Education Qualification :
Engineer - B.E / B.Tech / MCA
Role type: Senior individual contributor / hands-on subject-matter expert (with mentoring)
Experience: ~10–15 years in enterprise network security, with deep and current hands-on depth on Cisco Secure Firewall and at least one major proxy/SSE platform. Hands-on is non-negotiable, this is not a review-only role.
About the role
Deep technical authority for our firewall, proxy, and generic secure-access estate. You are the person who is hands-on in the consoles, scripts, and vendor APIs every week; the final escalation point when something hard breaks; and the one who keeps the estate audit-ready between incidents. You work in a patient-safety-first engineering culture: direct, plain-spoken, evidence over slideware. Profile mix: 55% Security Operations | 25% Hands-on Technical (incl. automation & AIOps) | 20% Governance, Risk & Compliance.
What you'll own:
- Firewall estate — Cisco Secure Firewall (FTD / FMC / ASA / Firepower): rule lifecycle and hygiene, HA, FMC upgrades and migrations, perimeter, and internal segmentation.
- Proxy & web security — PAC file management at global scale (including China and other high-latency / restricted regions), proxy policy, SSL/TLS inspection.
- Secure Service Edge / SASE — Zscaler (ZIA / ZPA) and Cisco Umbrella as the primary platforms. Exposure to Palo-Alto, Netskope or Cloudflare One is a plus.
- Remote & site connectivity — IPSec / SSL VPN, AnyConnect / Secure Client, site-to-site (S2S), out-of-band management (OOBM), and partner access (S2S / VDI).
- Identity & access — Cisco ISE / AAA.
- Certificates & PKI — certificate lifecycle and expiry management, TLS, and closed-loop certificate automation.
- Vulnerability & advisory response — PSIRT cadence, patching, and upgrade lifecycle across the estate.
Hands-on Technical:
- Deep, current hands-on across the estate: Cisco FTD/FMC/ASA/Firepower, ISE, Cisco SSE/Umbrella, Zscaler ZIA/ZPA, PAC files, PKI/TLS, rule design, SSL inspection, FMC HA and migrations, ISE policy, VPN (IPSec/SSL/S2S) troubleshooting.
- Holds L3/L4 escalation authority with Cisco TAC, Zscaler and managed-service partners, ie: the break-glass engineer when P1/MI hits: firewall HA failures, FMC migrations, PSIRT response.
- Writes and maintains automation in Python, Ansible and Terraform, working directly against vendor REST APIs: Cisco FMC, Zscaler, ISE, and IPAM/DNS (e.g. Efficient IP): safe bulk rule changes, PAC at scale.
- Maintains lab/sandbox to test changes and upgrades before production.
- Cloud network security — Liaises with Cloud Infrastructure, Security, DNS, IPAM and Active Directory teams to secure and enable network connectivity and integration across AWS, Azure, GCP and China cloud — Security groups, NACLs, NVA / cloud firewalls, Cloud On-Ramp, ExpressRoute/DX, TGW/VNet peering, SSE PoP integration and CSPM signal handoff.
Operations & governance:
- Drives the firewall/proxy/SSE domain from reactive firefighting to a predictable run model: ITSM discipline, RCA, change governance, and SLA/KPI ownership for the domain.
- Senior ServiceNow change approver for firewall, proxy, VPN and other security-touching changes; technical reviewer on the change/technical review board.
- Keeps the estate audit-ready — NIS2, ISO 27001, healthcare-grade — with defensible evidence and change-to-change-record traceability.
- Maintains the domain security risk register and supports DR / security tabletop drills.
- Holds managed-service and OEM partners (Cisco, Zscaler and the relevant MSPs) technically accountable on delivery quality, feeding the commercial and escalation process owned by the Lead.
- Stakeholder, Communication & Escalation Management — Runs structured stakeholder engagement, leadership/vendor/audit communications, and escalation as a discipline (thresholds, pathways, ownership) feeding the Lead's commercial authority.
- Service (Operations, Delivery, Commercial & Contractual) Management — Owns partner (MSPs, OEMs) service delivery (quality, milestones, acceptance, security), RFPs (evaluation, scoring, selection inputs), and commercial/contractual oversight (business case, sizing, ROI, lifecycle, services, support, licenses, purchases, Invoices, renewals, exit clauses) feeding the Lead's final decisioning.
Note: contract management, RFP ownership, business-case approval, and formal vendor-commercial escalation sit with the Lead, Digital Networks, this role provides the technical substance behind them.
Mentoring & collaboration:
- Works alongside engineers, not just reviewing them, ie: sets the hands-on bar for the team.
- Mentors’ junior engineers and interns.
- Partners with the Security Architect and the Lead; represents the domain in relevant technical forums (change and architecture review boards).
Skills & Certifications:
Must-have certifications:
This role is certification-backed. We expect current and active credentials, not lapsed ones.
- CCNP Security (350-701 SCOR core plus a relevant concentration exam). The concentrations that map directly to this role:
- 300-710 SNCF — Securing Networks with Cisco Firewalls (Secure Firewall / FMC) (highly preferred or willingness to get)
- 300-730 SVPN — Secure VPNs (IPSec / SSL)
- 300-715 SISE — Identity Services Engine (ISE)
- At least one current SSE vendor credential; Zscaler is preferred.
Must-have skills:
- Hands-on: Cisco FTD / FMC / ASA / Firepower; ISE; Zscaler ZIA / ZPA; Cisco Umbrella; PAC files; PKI / TLS.
- VPN: IPSec / SSL / AnyConnect / site-to-site / OOBM solutions.
- Automation: Python, Ansible, Terraform, REST APIs.
- AIOps / observability: Splunk or equivalent.
- ITIL v4 ways of working; strong RCA discipline.
- Audit literacy: NIS2, ISO 27001 (healthcare / regulated-industry experience a plus).
- Clear, direct, plain-English communication.
Nice-to-haves:
- ITIL Expert / Managing Professional
- CISSP / CISM / CCSP
- AWS Security Specialty / Azure Security Engineer
- Palo-Alto, Netskope or Cloudflare One exposure