Track Manager (Support & Operations)
Teknik, data och digitalt · IT-infrastruktur och säkerhet · Cybersäkerhet · Nätverksadministration · DevOps
I korthet
Network Security Engineer (L3) with 8-12+ years of experience sought for 24x7 support in Noida, India. Responsibilities include advanced firewall and VPN management, security architecture, major incident resolution, and RCA ownership. The role requires deep expertise in Palo Alto, Fortinet, Check Point, and Cisco ASA/FTD, along with SIEM/SOAR and ServiceNow tools.
Ansvarsområden
- Provide deep L3 expertise for complex firewall, VPN, NAT, segmentation, access control, inspection, HA, and security platform issues.
- Lead major incident restoration and RCA for business-impacting network security outages or security incidents.
- Improve firewall/VPN security posture through standards, governance, rule-base quality, monitoring accuracy, automation, and preventive controls.
- Own high-risk firewall/VPN changes, ensuring impact analysis, peer review, rollback, testing, and evidence.
- Mentor L1/L2 teams and improve shift-left through runbooks, known errors, training, and escalation quality reviews.
- Act as the L3 escalation point for complex firewall, VPN, NAT, routing, HA, inspection, threat prevention, segmentation, remote access, and application connectivity issues.
- Lead network security technical recovery during P1/P2 incidents, provide bridge direction, define workaround/restoration options, and coordinate with relevant teams.
- Review and optimize firewall architecture, zone strategy, policy hierarchy, NAT design, HA design, route integration, segmentation patterns, and platform scalability.
- Plan, peer-review, and execute high-risk changes such as firewall upgrades, HA failover tests, major policy migration, rule cleanup, VPN migration, certificate changes, and platform redesign support.
- Own complex IPSec, SSL VPN, GlobalProtect/remote access, ZTNA/ZINA, certificate, authentication, IKE/IPSec, split-tunnel, routing, and tunnel performance issues.
- Support advanced security controls including IPS/IDS, anti-malware, URL filtering, DNS security, WildFire/sandboxing, SSL decryption, data filtering, DoS protection, and content inspection.
- Perform detailed analysis using Panorama, FortiAnalyzer, SmartConsole, SIEM/SOAR, device logs, flow/session tables, and packet captures to determine root cause and remediation options.
- Define firewall/VPN governance standards, audit controls, evidence standards, rule lifecycle, access reviews, log retention, and change documentation expectations.
Krav
- 8-12+ years of experience in Network Security, specifically with Firewall and VPN management.
- Deep SME level knowledge in Network Security Engineering.
- Experience with Palo Alto, Fortinet/FortiGate, Check Point, Cisco ASA/FTD.
- Expertise in VPN, NAT, ZTNA/ZINA.
- Proficiency in core tools such as Panorama, FortiManager, FortiAnalyzer, SmartConsole, SIEM/SOAR, ServiceNow, and Wireshark.
- Experience in 24x7 managed network security operations.
- Certifications such as PCNSE, NSE4/5/7, CCNP/CCIE Security, CCSA/CCSE, ITIL are preferred.
Önskade kvalifikationer
- L3 / Network Security SME role level.
- Support Window: 24x7 escalation / on-call.
- Function: Network Security.
- Primary Technologies: Palo Alto, Fortinet/FortiGate, Check Point, Cisco ASA/FTD, VPN, NAT, ZTNA/ZINA.
- Primary Processes: Major Incident, Problem/RCA, Complex Change, Risk, Compliance.
- Delivery Context: Burlington 24x7 managed network security operations.
Förmåner
- Supercharge your potential at HCLTech.
- Find your career and spark at a place that puts people first.
#Network Security#Firewall#VPN#SME#L3 Support#Security Architecture#Incident Management#RCA#Change Management#Palo Alto#Fortinet#Check Point#Cisco ASA/FTD#ZTNA#ZINA#Panorama#FortiManager#FortiAnalyzer#SmartConsole#SIEM#SOAR#ServiceNow#Wireshark#ITIL#Threat Prevention#SSL Decryption