Jobs · Information Technology · North Carolina

Principal Security Engineer

Verizon · Cary, NC · Yesterday
Information Technology$121k–$231k/yrFull-time

About the role

The Verizon Network Security team is seeking a Principal Engineer to join the Net-Sec Defense Organization under the Broadband Access team. This role involves overseeing the network security posture, Security Lifecycle, and protection against threats across various network elements including Edge Routers, Broadband Access routers and switches, CPE equipment, and RAN transport infrastructure.

Responsibilities

  • Owning the Network security posture, Security Lifecycle, and protection against threats across the Broadband access network
  • Understanding complex network architectures utilizing various protocols, topologies, and vendor hardware
  • Leveraging automation platforms to develop scripts and tools to enhance security operations
  • Leading response to network security incidents and implementing proactive measures to safeguard critical assets
  • Continuously monitoring and proactively detecting threats to safeguard network functions and assets
  • Collaborating with internal organizations and vendors to improve security posture by implementing Network Security Policies
  • Planning, designing, and leading execution of Network Security policies across all owned assets
  • Driving continuous improvement of network visibility and telemetry collection to strengthen detection and response capabilities
  • Developing baseline operations for the team and implementing threat detections, automated alerts to proactively identify potential cyber threats
  • Executing root cause analysis for incidents, performing regular security control assessments, and leading strategic security solution implementation
  • Ensuring that the security controls planned for the Networks are operating effectively by performing audits
  • Leveraging network automation and scripting to make the process efficient
  • Leading the development and upkeep of network automation systems for ongoing security monitoring and early identification of security incidents
  • Offering technical guidance and expert feedback on the Vendor Plan of Record (POR), selection of security/monitoring tools, and vendor engagements
  • Developing essential technical documentation, including playbooks, Confluence pages, Network diagrams, and Method of Procedures (MOPs)
  • Preparing and delivering quarterly presentations to leadership detailing project status and updates
  • Mentoring Team members as well as Organizational partners and acting as the overall SME
  • Building healthy relationships across the Operations, Engineering, and Planning organizations to better understand the current and future landscape of the network

Requirements

  • Bachelor’s degree or four or more years of work experience
  • Six or more years of relevant experience required, demonstrated through one or a combination of work and/or military experience, or specialized training
  • Demonstrated leadership skills as a project and/or team lead for cross-functional project teams and vendor management
  • Expert understanding of Spine, Leaf, SDN, OTNGN, and Hub & Spoke network architectures
  • Expert-level understanding of routing and switching security, including BGP and IGP security, is mandatory, e.g., BGP hijacking, Route injection, and managing complex ACLs
  • Hands-on experience with internet-scale data sets such as Netflow, BGP, DNS, and IDS logs
  • Fluency in security frameworks, particularly the application of CIS Benchmarks (Level 1 & 2 hardening) and mitigating MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs) on network devices, along with a solid understanding of network security fundamentals
  • Expertise in using Python, API, Ansible, or Terraform-type tools to automate and develop custom security “health checks” on network devices
  • Understanding of network security fundamental policies and principles
  • Experience with utilizing SIEM tools like Splunk for performing analysis

Qualifications

  • Network Security certifications such as CISSP or other ISC2 certifications
  • Routing and Switching certifications like CCNP, CCIE, or equivalent vendor certs
  • Familiarity with Identity and Access Management (IAM) solutions and SIEM tools
  • Knowledge of technical products and systems development lifecycle within a large global enterprise environment
  • Effective written, interpersonal, and verbal communication skills
  • Ability to work with diverse stakeholders, including highly technical teams, business owners, and executives
  • Strong leadership and mentoring abilities, with experience guiding and developing teams

Skills

  • Python
  • API
  • Terraform
  • Ansible
  • Automation platforms
  • SIEM tools (Splunk)
  • Security frameworks (CIS Benchmarks, MITRE ATT&CK)
  • Routing and Switching security
  • Network security fundamentals

Benefits and Compensation

  • Health and wellness benefits including medical, dental, vision, short and long term disability, basic life insurance, supplemental life insurance, AD&D insurance, identity theft protection, pet insurance, and group home & auto insurance
  • Matched 401(k) savings plan
  • Up to 8 company paid holidays per year and up to 6 personal days per year
  • Paid parental leave
  • Adoption assistance
  • Tuition assistance
  • Other incentives

Pay

$120,500.00 - $231,000.00 annually based on a full-time schedule

Schedule

This role can be located out of any US based Verizon hub location. It is a hybrid role with a defined work location that includes working from home and a minimum of three days per week in the office, which will be set by your manager. Employees are responsible for maintaining compliance with hybrid work policies. Scheduled Weekly Hours 40

Similar jobs