Principal Security Engineer
Verizon · Basking Ridge, NJ · Yesterday
Information Technology$121k–$231k/yrFull-time
About the role
The Verizon Network Security team is seeking a Principal Engineer to join the Net-Sec Defense Organization under the Broadband Access team. This role involves hands-on work and demonstrates subject matter expertise with routers, switches, and other networking gear, as well as Security Information and Event Management (SIEM) tools, particularly Splunk and ISE.
Responsibilities
- Owning the Network security posture, Security Lifecycle and protection against threats across the Broadband access network that includes, but is not limited to Edge Routers, Broadband Access routers and switches, CPE equipment and RAN transport infrastructure.
- Understanding complex network architectures utilizing various protocols, topologies, and vendor hardware.
- Leveraging automation platforms to develop scripts and tools to enhance security operations and play a key role in monitoring, analyzing, and leading response to network security incidents while implementing proactive measures to safeguard critical assets.
- Continuously monitoring and proactively detecting threats to safeguard network functions and assets, with a focus on leveraging automation and AI.
- Driving continuous improvement of network visibility and telemetry collection to strengthen detection and response capabilities.
- Developing baseline operations for the team and implementing threat detections, automated alerts to proactively identify potential cyber threats, leveraging SIEM tools such as Splunk.
- Leading the development of incident response protocols to quickly identify, contain, and resolve network security incidents and threats.
- Executing root cause analysis for incidents, performing regular security control assessments, and leading strategic security solution implementation in a highly scalable environment.
- Ensuring that the security controls planned for the Networks are operating effectively by performing audits.
- Leveraging network automation and scripting to make the process efficient.
- Leading the development and upkeep of network automation systems for ongoing security monitoring and early identification of security incidents.
- Offering technical guidance and expert feedback on the Vendor Plan of Record (POR), selection of security/monitoring tools, and vendor engagements.
- Developing essential technical documentation, including playbooks, Confluence pages, Network diagrams, and Method of Procedures (MOPs).
- Preparing and delivering quarterly presentations to leadership detailing project status and updates.
- Mentoring Team members as well as Organizational partners and acting as the overall SME.
- Building healthy relationships across the Operations, Engineering, and Planning organizations to better understand the current and future landscape of the network.
Requirements
- Bachelor’s degree or four or more years of work experience.
- Six or more years of relevant experience required, demonstrated through one or a combination of work and/or military experience, or specialized training.
- Demonstrated leadership skills as a project and/or team lead for cross-functional project teams and vendor management.
- Expert understanding of Spine, Leaf, SDN, OTNGN, and Hub & Spoke network architectures.
- Expert-level understanding of routing and switching security, including BGP and IGP security, is mandatory, e.g., BGP hijacking, Route injection, and managing complex ACLs.
- Hands-on experience with internet-scale data sets such as Netflow, BGP, DNS, and IDS logs.
- Fluency in security frameworks, particularly the application of CIS Benchmarks (Level 1 & 2 hardening) and mitigating MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs) on network devices, along with a solid understanding of network security fundamentals.
- Expertise in using Python, API, Ansible, or Terraform-type tools to automate and develop custom security “health checks” on network devices.
- Understanding of network security fundamental policies and principles.
- Experience with utilizing SIEM tools like Splunk for performing analysis.
Qualifications
- Network Security certifications such as CISSP or other ISC2 certifications.
- Routing and Switching certifications like CCNP, CCIE, or equivalent vendor certs.
- Familiarity with Identity and Access Management (IAM) solutions and SIEM tools.
- Demonstrated organization and project management skills.
- Knowledge of technical products and systems development lifecycle within a large global enterprise environment.
- Effective written, interpersonal, and verbal communication skills.
- Ability to work with diverse stakeholders, including highly technical teams, business owners, and executives.
- Strong leadership and mentoring abilities, with experience guiding and developing teams.