Senior Network Security Engineer
TechHuman · Springfield, MO · 2 wk ago
HybridFull-time
About the role
We are seeking a Senior Network Security Engineer to support and modernize a large enterprise firewall environment across corporate, distribution-center, and retail operations. The engineer will administer and troubleshoot Palo Alto and Fortinet/FortiGate technologies, support dynamic routing with a strong emphasis on BGP, and maintain secure connectivity through VPN, IPsec, LAN, Ethernet, and Layer 3 firewall technologies. This role balances complex project work with day-to-day operational support, including a high-volume firewall ticket queue, rule hygiene, incident response, and audit evidence for PCI and other sensitive-data controls.
Responsibilities
- Administer and troubleshoot Palo Alto and Fortinet/FortiGate firewall technologies.
- Support dynamic routing, with a strong emphasis on BGP.
- Maintain secure connectivity through VPN, IPsec, LAN, Ethernet, and Layer 3 firewall technologies.
- Manage a high-volume firewall ticket queue and ensure rule hygiene.
- Respond to security incidents and provide audit evidence for PCI and other sensitive-data controls.
- Drive project work across Systems, Virtualization, and Infrastructure teams.
- Interpret network diagrams, understand ports and protocols, and analyze system-level interactions.
- Automate firewall and network tasks using Ansible and Python.
Requirements
- 6+ years of professional experience in Network Engineering.
- Technical depth with Palo Alto firewalls.
- Strong background in dynamic routing, Layer 2 networking, data center engineering, and firewall routing.
- Hands-on experience with Zero Trust security architectures.
- Proficiency with LAN, Ethernet, VPN, IPSec, and L3 firewalls.
- Strong rule-hygiene practices and experience managing high-volume firewall ticket queues.
- Proficiency with Ansible and Python for automation.
- Expertise in firewall protection of PCI, PII, and other sensitive data.
- Strong understanding of BGP and dynamic routing (hard requirement).
Nice to Haves
- Prior experience in retail environments with distributed physical locations.
- Zscaler experience or familiarity working alongside Zscaler implementations.
- Experience with retail, datacenter, and/or multi-site/distributed networks.
- Experience supporting both data-center networking and firewall/security environments.
- Firewall automation experience using Ansible/AAP, scripting, or platforms such as Tufin, FireMon, or AlgoSec.
- Palo Alto, Fortinet, Security+, or other relevant network-security certifications.
- GCP or broader cloud-networking exposure.
- Experience supporting PCI audits and producing firewall-related compliance evidence.
- Deeper expertise in firewall rule hygiene, policy cleanup, and governance.
- Team mentorship, leadership, or project ownership.
- Palo Alto or Fortinet certifications.