Zero Trust & Network Security Engineer
Hybrid with 3 days a week in London
Inside ir35
- Partner with internal stakeholders and technology vendors to evaluate, select, and implement Zero Trust security solutions.
- Design and engineer scalable, resilient, and secure enterprise network and security architectures.
- Collaborate across Network Engineering, Security Engineering, IAM, Cloud, EUC, and Operations teams to deliver security transformation initiatives.
- Contribute to technical strategy, standards, reference architectures, and design patterns.
- Deliver solutions tailored to internal business requirements. Articulate design rationale, flexibly adapt solutions, and iterate designs when required.
- Develop High-Level Designs (HLD), Low-Level Designs (LLD), migration plans, operational procedures, and architecture documentation.
- Support vendor evaluations, Proof of Concepts (PoCs), pilot deployments, and production rollouts.
- Lead technical assessments, architecture reviews, root cause analysis, and engineering recommendations.
- Design, deploy, and operate Palo Alto, Fortinet or Cisco NGFW platforms and their respective (Cloud) Manager, (Strata Cloud, FortiManager, Cisco Security Cloud)
- Design and implement SASE/SSE solutions for enterprise-scale deployments.
- Implement centralized security management, policy governance, logging, monitoring, and reporting using the Vendors ecosystem or solutions like Tufin or Algosec.
Network Security & Segmentation
- Design and implement on-premises Zero Trust Enforcement Points (NGFW)
- Develop segmentation and micro-segmentation strategies across data centres, campuses, cloud, and branch environments.
- Define secure traffic flows and trust boundaries.
- Support migration from traditional network-centric security models to Zero Trust architectures.
Enterprise Networking
- Routers, switches, LAN/WAN design and engineering.
- VPN technologies, IPSec, TLS encryption, and NAC integration.
- Hands-on experience with:
- Cisco ASR/ISR/Catalyst 8k
- Cisco Catalyst and Nexus platforms
- Arista switching platforms
- Strong experience with:
- BGP
- OSPF
- EVPN
- VXLAN
- MPLS
- VRF-based segmentation
- Deep understanding of Layer 2 and Layer 3 network technologies.
Security & Integration: Experience integrating network security solutions with:
- Microsoft Entra ID
- Active Directory
- Cisco ISE/NAC platforms