Sr Checkpoint Firewall Engineer, Progression
Shift: 8-hour days, 5 days per week
About the Role
The Network & Systems Security Analyst is responsible for planning, designing, implementing, and supporting new and existing network, server, and storage infrastructure. This role ensures all network security controls—such as firewalls, web application firewalls (WAF), proxies, network segmentation, NAC, ACLs, and more—are implemented and managed according to corporate information security standards. The position also involves assessing enterprise and critical assets for secure configurations and maintaining compliance with regulations like NERC Critical Infrastructure Protection (CIP), Sarbanes-Oxley (SOX), and Payment Card Industry (PCI).
This role oversees the design, planning, operation, maintenance, and support of TECO and NMGC network infrastructure, including route/switch, on-premise LAN/WAN, IPAM, Wi-Fi, ISP management, site-to-site VPNs, proxies, perimeter firewall management, DNS, Azure cloud environments, automation, NAC/user access, hyperconverged infrastructure, and overall network security. The position partners with Telecommunication teams on circuit upgrades and is responsible for NERC Cyber Infrastructure Protection and disaster recovery plans.
Key technologies include VoIP, SIP, DHCP, DNS, TCP/IP routing (OSPF, BGP), binary mathematics, NAT, PAT, IPsec and SSL VPN, GRE tunneling, route redistribution, traffic shaping, port-level filtering, SD-WAN, MPLS, DNP over IP, SCADA communications, and Smart GRID communication hardware.
Focus Areas
- Check Point experience in production (R82)
- Hands-on experience with Check Point Maestro (deployment, Security Group management, orchestration, scaling, and troubleshooting)
- Deep Layer 2 / Layer 3 networking and TCP/IP troubleshooting skills
- GAIA and Security Management Server experience
- Proven experience designing and supporting VPN solutions
- Experience in high-availability or large-scale enterprise environments
Responsibilities
- Design, install, configure, and maintain WAN and LAN connectivity, including core and campus switches, routers, firewalls, wireless access points, WAN scalers, and load balancer technologies.
- Configure and maintain DNP over IP and serial SCADA communications between primary/backup control centers, power plants, solar sites, and substations.
- Configure and maintain Smart GRID communication hardware switches and routers.
- Monitor, troubleshoot, and resolve server, network, and security control issues.
- Install and configure hardware/software to meet security standards.
- Lead small projects, provide consulting, and mentor peers.
- Develop, test, and document disaster recovery plans.
- Provide third-level technical support for security systems and authentication mechanisms.
- Ensure compliance with NERC CIP, SOX, PCI, and other regulatory standards.
Qualifications
Education:
- Required: High School Diploma or GED
- Preferred: Bachelor’s degree in Computer Science, Engineering, Math, or equivalent IT discipline (e.g., MIS)
Certifications:
- Level 1 Required: At least one related certification (e.g., MCSA, VCP, CCNA, CEH, GIAC, CISSP)
- Level 2 Required: At least two related certifications (e.g., MCSA, MCSE, VCP, CCNA, CCNP, CEH, GNFA, CISSP)
- Level 3 Required: At least three certifications (or two with a commitment to obtain a third within one year of hire)
- Preferred: ITIL v3, CCNA, CCNP, MCSA, MCSE, VCP, Security+, CISSP, GNFA
Experience:
- Level 1: Minimum 4 years of hands-on experience in Windows, VMware, firewall support, DDoS protection, proxies, WAFs, NetScaler load balancers, or Cisco Networking. In lieu of experience, 3 years with an Associate’s Degree or 2 years with a Bachelor’s Degree in a relevant field.
- Level 2: Minimum 6 years of related experience. In lieu of experience, 4 years with an Associate’s Degree or 3 years with a Bachelor’s Degree in a relevant field.
- Level 3: Extensive experience with progressive responsibility in network and security infrastructure.
Skills
- Working knowledge of network, server, and security controls infrastructure
- Proficiency in switching, routing, DNS/DHCP, Windows Active Directory, VMware, VoIP, Storage Area Networking, firewall support, DDoS protection, proxies, WAFs, NetScaler load balancing, network segmentation, NAC, IDS/IPS, antivirus, and cybersecurity best practices
- Packet analysis and denial-of-service protection
- Strong critical thinking, analytical, problem-solving, and risk assessment skills
- Excellent communication (oral and written) and interpersonal skills
- Ability to present complex technical topics to non-technical audiences
- Knowledge of regulatory compliance (NERC CIP, SOX, PCI)
Working Conditions
- Normal office and operational (Power Plant, Solar, Control Center) environments
- Occasional extended hours during the week and weekends
- Must be able to lift 50-pound boxes and ascend/descend ladders to service network access points