Role Overview
As an experienced Network Security Engineer, you will play a key role in designing, implementing, securing, and optimising enterprise network security services across on-premises, cloud, and hybrid environments.
Your expertise will be utilised to strengthen the organisation’s cyber defence capabilities, drive network security innovation, automate security operations, and ensure resilient, secure, and scalable connectivity solutions.
You will work closely with architecture, engineering, operations, cloud, and business teams to deliver secure network services, respond to emerging threats, and support the adoption of modern network security technologies.
The role requires a strong focus on automation, continuous improvement, operational excellence, and adherence to security and regulatory requirements.
Primary Responsibilities:: Network Security Engineering & Delivery
- Lead the implementation, engineering and operational support of Island Enterprise Browser services across enterprise environments.
- Develop and maintain browser security policies to protect sensitive data, secure third-party access and support workforce mobility initiatives.
- Collaborate with Security Architecture, End User Computing, Identity & Access Management and Security Operations teams to deliver secure browser-based access solutions.
- Support browser modernisation initiatives that replace traditional VPN and endpoint-centric security controls with Zero Trust access models.
- Design, implement, and maintain secure enterprise network infrastructure and security controls aligned to organisational strategy and security standards.
- Drive network security enhancements and modernisation initiatives within agreed budgets, timelines, and risk appetites.
- Support the delivery of secure connectivity solutions across cloud, on-premises, and hybrid environments.
- Collaborate with architects and engineers to develop High Level Designs (HLDs) and Low Level Designs (LLDs) into operational solutions.
- Lead operational readiness and transition requirements from design/build phase to BAU
- Lead policy governance, including rule review, optimisation, recertification, and compliance management processes.
- Drive continuous improvement of network security operations through automation, policy simplification, and control standardisation.
- Identify opportunities to reduce operational risk through proactive firewall rule analysis, remediation, and optimisation activities.
- Partner with Infrastructure, Security Architecture, Engineering, and Cyber Defence teams to deliver secure network services and strategic security initiatives.
- Collaborate with leadership teams to align network security capabilities with broader technology, resilience, and cyber security strategies.
- Develop and implement automated solutions for network security administration, policy management, compliance validation, and operational processes.
- Drive the adoption of Infrastructure as Code (IaC), Security as Code, and automated governance controls across network security platforms.
- Contribute to enterprise-wide initiatives focused on network visibility, security posture improvement, and operational efficiency.
- Monitor and analyse browser security events, policy violations and suspicious user activity to support threat detection and incident response activities.
- Support investigations involving browser session activity, data protection events and secure application access controls.
- Monitor, analyse, and respond to network security incidents, vulnerabilities, and emerging threats.
- Support threat detection, containment, remediation, and post-incident reviews.
- Ensure network security controls remain effective, compliant, and aligned with evolving cyber threats.
- Conduct security assessments, rule reviews, and network segmentation activities.
- Ensure network architectures comply with security standards, secure-by-design principles, and software development lifecycle requirements.
- Support the implementation of Zero Trust, defence-in-depth, and least privilege security models.
- Maintain awareness of current industry threats, vulnerabilities, and security technologies.
- Strong understanding of SWG controls
- Island Enterprise Browser, extension and agent engineering
- Strong understanding of TLS interception
- Proxy & Secure Web Gateway Technologies
- Zero Trust Network Access (ZTNA)
- Strong understanding of authentication method at enterprise level
- Strong understanding of content controls (request and response mode)
- Network Security Automation (Python, PowerShell, APIs, Terraform)
- Cloud Security & Secure Connectivity
- Identity Integration (Entra ID, Conditional Access, MFA)
- Hands-on experience implementing, configuring and supporting Enterprise Browser solutions, including Island Browser or equivalent secure enterprise browser technologies.
- Design and implement browser-based security controls to support Zero Trust security principles, secure remote access, data protection and policy enforcement.
- Configure and manage browser security policies including:
- Data Loss Prevention (DLP)
- Clipboard controls
- File upload and download restrictions
- Browser isolation controls
- Session protection
- Watermarking
- Secure application access controls
- Downstream SWG
- Microsoft Entra ID
- Multi-Factor Authentication (MFA)
- Conditional Access
- Security Information and Event Management (SIEM) platforms
- Strong operational experience supporting enterprise network security environments.
- Experience managing security incidents, policy changes, exceptions, and operational support within regulated organisations.
- Understanding of compliance management, governance processes, audit requirements, and regulatory controls.
- Experience working within ITIL-aligned Incident, Problem, Change, and Service Management frameworks.
- Experience automating network security processes, including:
- Rule lifecycle management
- Policy validation
- Compliance reporting
- Security control enforcement
- Operational workflows
- Strong stakeholder management and relationship-building skills across technical and executive audiences.
- Ability to influence and drive security improvements across infrastructure, cloud, engineering, and operational teams.
- Strong analytical approach to risk identification, remediation, and operational optimisation.
- Excellent written and verbal communication skills with the ability to present complex technical issues in a clear and concise manner.
- Demonstrated ability to balance security, operational resilience, regulatory obligations, and business requirements.
- Experience implementing SWG within large-scale enterprise environments.
- Experience supporting enterprise browser adoption, policy governance and operational service management processes.
- Experience with Zero Trust Network Architecture (ZTNA), SASE, and Security Service Edge (SSE) technologies.
- Experience within large-scale financial services, banking, or other highly regulated environments.
- Knowledge of regulatory frameworks including PCI-DSS, ISO27001, NIST Cyber Security Framework, CIS Controls, and relevant financial industry regulations.
- Experience supporting network security transformation, cloud migration, and hybrid networking programmes.