Looking for something else?
Find a vacancy that works for you. Send us your CV to receive a personalized offer.
Find me a jobWe are seeking a Consultant – Network Security to design, implement, and operate secure, compliant network segmentation between regional environments and Global networks. This role leverages a standardized control stack including Check Point Security Gateways, Palo Alto Networks next-generation firewalls, Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA), and Cloudflare for DDoS mitigation, WAF, and application protection. The position blends architecture, hands-on engineering, automation, and L3/L4 operational leadership to deliver policy-driven connectivity under strict regulatory and operational requirements.
Responsibilities
- Define trust zones, routing boundaries, and inter-zone controls for regional and Global Network, covering north-south and east-west paths, micro-segmentation for sensitive tiers, and explicit cross-border allow-lists
- Produce HLD/LLD, threat models, and control mappings aligned to internal standards and regional regulation to enable secure communication between regional and Global customer sites
- Design and operate dual-vendor firewall perimeters with clear control allocation, HA/cluster design, deterministic failover, NAT domain strategy, SSL/TLS inspection governance, and Threat Prevention/WildFire/URL filtering tuned for jurisdiction
- Engineer ZIA for identity-aware egress controls, SSL inspection with jurisdiction-aware bypasses, inline CASB/DLP, and sanctioned SaaS governance
- Implement ZPA for per-application zero-trust access, with connector placement, posture checks, conditional access, and app segmentation replacing legacy VPN where feasible
- Design and deliver Site-to-Site VPN (IPSec), Cloud Interconnect/Partner Interconnect equivalents, and BGP-based dual-tunnel HA per site for cloud hybrid connectivity
- Deploy Cloudflare Magic Transit/Magic WAN, WAF Management, and rate limiting for internet-facing services, and integrate with on-prem perimeters for layered defence
- Engineer SD-WAN/MPLS/SASE paths with policy-based routing, strong encryption, and defined key custody/rotation by jurisdiction
- Translate regulatory and internal control requirements into enforceable technical controls for logging, data residency, TLS inspection scope, and lawful intercept considerations
- Normalise telemetry from firewall, Zscaler, and Cloudflare platforms into SIEM with regional data handling rules, and build detections for cross-border anomalies and policy drift
- Lead L3/L4 incidents, coordinate issue containment, and drive RCAs with corrective actions codified
- Manage firewall, Zscaler, and Cloudflare policy through Terraform/Ansible and vendor APIs, and implement CI/CD with policy linting, unit tests, and path simulation
Requirements
- 5+ years of experience in network security architecture and operations, with a focus on cross-border or multi-region connectivity
- Expertise in Check Point Security Gateways, Palo Alto Networks next-generation firewalls, and Panorama management
- Proficiency in Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) for zero-trust architecture
- Skills in Cloudflare Magic Transit/Magic WAN, WAF Management, and DDoS mitigation strategies
- Knowledge of cloud hybrid connectivity, including Site-to-Site VPN, Cloud Interconnect, and BGP routing
- Background in SD-WAN, MPLS, and SASE architectures with policy-based routing and strong encryption protocols
- Understanding of regulatory and compliance frameworks relevant to data residency, TLS inspection, and lawful intercept
- Familiarity with SIEM platforms and telemetry normalisation for cross-border security monitoring
- Competency in Terraform, Ansible, and vendor APIs for policy-as-code and CI/CD pipeline integration
- Capability to lead L3/L4 incident response and conduct root cause analysis with corrective action planning
