W2 Role || Senior Network Security Engineer (Microsegmentation)
Noblesoft Technologies · Houston, TX · Yesterday
On-siteInformation TechnologyContract
Key Responsibilities
- Translate high-level business strategic objectives and goals into Enterprise IT requirements and conceptual designs.
- Develop and support comprehensive solutions that meet requirements and align with Client's global network security and microsegmentation strategy.
- Develop and maintain a multi-year strategic network and security architecture roadmap, incorporating Zero Trust and segmentation-driven security models.
- Lead end-to-end network and security architecture across global platforms ensuring secure, high-performing, fault-tolerant, and resilient environments.
- Microsegmentation & Zero Trust Responsibilities:
- Architect and implement microsegmentation strategies across data center, campus, and cloud environments to limit lateral movement and enforce least-privilege access.
- Design and operationalize Zero Trust Architecture (ZTA) principles, integrating identity, application, and network-based policy enforcement.
- Collaborate with application owners to discover, validate, and map application dependencies to enable policy-driven segmentation.
- Define and enforce granular security policies using label/tag-based segmentation approaches across hybrid environments.
- Integrate microsegmentation with firewalls, SIEM, IAM, EDR/XDR, and cloud-native controls for unified policy enforcement.
- Lead adoption of microsegmentation platforms (e.g, Guardicore/Akamai Segmentation).
- Develop segmentation governance models, policy lifecycle management, and compliance alignment (CIS/NIST/Zero Trust frameworks).
Core Network Security Responsibilities
- Participate in network security design reviews and ensure all implementations meet enterprise security standards.
- Analyze business requirements to design and implement security across data centers, campus networks, and hybrid environments.
- Provide ongoing risk metrics, control effectiveness tracking, and security posture reporting.
- Conduct and support internal and external security audits and compliance assessments.
- Develop and manage policies, processes, and procedures ensuring reliability, availability, and security of network systems.
- Maintain awareness of emerging threats and update policies accordingly.
- Manage and optimize Security Information and Event Management (SIEM) systems.
- Collaborate with Cyber Security, infrastructure, and application teams toward compliance and operational excellence.
Technical Qualifications
- 10+ years of experience in enterprise network security architecture, engineering, and operations.
- Microsegmentation & Advanced Security: Strong hands-on experience in designing and implementing microsegmentation solutions in complex enterprise environments.
- Proven capability to build application-aware segmentation policies based on traffic flow analysis.
- Experience with policy simulation, enforcement, monitoring, and optimization in segmentation platforms.
- Familiarity with Zero Trust Network Access (ZTNA) and identity-driven access models.
- Network Security & Infrastructure: Strong experience managing LAN/WAN security technologies, including firewalls, IDS/IPS, SIEM, VPN, and NAC.
- Expertise in firewall architecture and design with hands-on experience in: Fortinet (Fortigate), Palo Alto, Juniper.
- Policy design, NAT, routing, application control, and threat prevention profiles.
- Experience securing public and private cloud (AWS, Azure, GCP) environments.
- Design and implementation of Web Application and API Protection (WAAP) solutions.
- Strong experience in proxy (forward/reverse), load balancing, and application security integration.
- Experience with SDN and SD-WAN architectures, including segmentation use cases.
- Networking & Protocol Expertise: Strong knowledge of: Routing protocols: BGP, OSPF, RIP, MPLS, Network services: DNS, DHCP, NTPIpv4/IPv6 architecture and traffic management.
- Experience in QoS, NetFlow, ACLs, NAT, multicast, and wireless technologies (802.11 variants).
- Experience with F5 GTM/LTM, VPN technologies, and Internet proxy solutions.
- Data Center & Infrastructure Experience: Managing enterprise data center environments with technologies including: Aruba, Arista, Juniper switching, Firewalls, WAN optimization, IDS/IPS, DLP, Strong understanding of structured cabling and network facilities.
Operations & Lifecycle Management
- Plan, implement, and document infrastructure changes, including upgrades and migrations.
- Work within ITIL frameworks for incident, change, and problem management.
Education & Certifications
- Bachelor's Degree in Computer Science, Network Engineering, or related field (or equivalent experience).
- Prefered certifications: CCNP / CCIE, JNCIE, Security certifications (CISSP, CISM, or equivalent) are a plus.