Consultant - Network Security

Brak informacji o wynagrodzeniu
SeniorFull-time
#449491·Dodano 3 dni temu·1
Źródło: EPAM Systems
Aplikuj teraz

Tech Stack / Keywords

Check Point CloudGuardCloudFlareGitHub ActionsPalo Alto Cortex XSOARZscaler Internet AccessZscaler Private AccessTerraformAnsibleSIEMAWS Network Firewall

Firma i stanowisko

EPAM is global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, we empower our clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.

Wymagania

  • 5+ years of experience in network security architecture and operations focused on cross-border or multi-region connectivity
  • Expertise in Check Point Security Gateways, Palo Alto Networks firewalls, and Panorama management
  • Proficiency in Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) for zero-trust architecture
  • Skills in Cloudflare Magic Transit/Magic WAN, WAF management, and DDoS mitigation
  • Knowledge of cloud hybrid connectivity including Site-to-Site VPN, Cloud Interconnect, and BGP routing
  • Background in SD-WAN, MPLS, and SASE architectures with policy-based routing and strong encryption
  • Understanding of regulatory and compliance frameworks relevant to data residency, TLS inspection, and lawful intercept
  • Familiarity with SIEM platforms and telemetry normalization for cross-border security monitoring
  • Competency in Terraform, Ansible, and vendor APIs for policy-as-code and CI/CD integration
  • Capability to lead L3/L4 incident response and conduct root cause analysis with corrective action planning

Obowiązki

  • Define trust zones, routing boundaries, and inter-zone controls for regional and Global Network, including micro-segmentation and cross-border allow-lists
  • Produce HLD/LLD, threat models, and control mappings aligned to internal standards and regulations
  • Design and operate dual-vendor firewall perimeters with HA/cluster design, NAT domain strategy, SSL/TLS inspection governance, and tuned Threat Prevention/WildFire/URL filtering
  • Engineer ZIA for identity-aware egress controls, SSL inspection with jurisdiction-aware bypasses, inline CASB/DLP, and sanctioned SaaS governance
  • Implement ZPA for per-application zero-trust access with connector placement, posture checks, conditional access, and app segmentation replacing legacy VPN
  • Design and deliver Site-to-Site VPN (IPSec), Cloud Interconnect/Partner Interconnect, and BGP-based dual-tunnel HA for cloud hybrid connectivity
  • Deploy Cloudflare Magic Transit/Magic WAN, WAF Management, and rate limiting and integrate with on-prem perimeters
  • Engineer SD-WAN/MPLS/SASE paths with policy-based routing, strong encryption, and key custody/rotation by jurisdiction
  • Translate regulatory and internal controls into enforceable technical controls for logging, data residency, TLS inspection scope, and lawful intercept
  • Normalize telemetry from firewall, Zscaler, and Cloudflare into SIEM with regional data handling rules and detect cross-border anomalies
  • Lead L3/L4 incidents, coordinate containment, and drive root cause analysis with corrective actions
  • Manage firewall, Zscaler, and Cloudflare policy through Terraform, Ansible, and vendor APIs, implementing CI/CD with policy linting, tests, and path simulation

Benefity

  • Hybrid work mode designed with opportunity to work remotely within Poland
  • Chance to work abroad for up to 60 days annually
  • Business-driven relocation opportunities
  • Career development programs including mentoring, soft skills, and well-being
  • Certifications such as Anthropic, Gemini, GCP, Azure, AWS
  • English classes
  • Stable pay
  • Participation in Employee Stock Purchase Plan with 15% discount
  • Benefits package including health insurance, multisport, and shopping vouchers
  • Referral bonuses up to $2,000
  • Offices with entertainment and relaxation zones, table tennis, football, free snacks, and coffee
  • Corporate, social, and well-being events
Elastyczne godziny
Budżet konferencyjny
Dofinansowanie szkoleń
Spotkania integracyjne
Kursy językowe
Karta sportowa
Opieka zdrowotna
Ubezpieczenie
Napoje w biurze
Darmowe przekąski
Premie
Udziały pracownicze

Inne informacje

Benefits listed are available to employees only. Open to working with Contractors under individually agreed B2B cooperation agreements. Only selected candidates will be contacted.

EPAM Systems

EPAM Systems

1208 aktywnych ofert

Zobacz wszystkie oferty
Aplikuj teraz