- Company Name
- TPI Global Solutions
- Job Title
- Network Security Engineer
- Job Description
-
**Job Title:** Senior Network Security Engineer
**Role Summary:**
Design, implement, and maintain an enterprise security architecture comprising firewalls, SD‑WAN, and cloud security solutions. Drive migration from legacy Checkpoint to Fortinet, optimize routing, NAT and firewall policies, and ensure resilience against DDoS, threats, and performance issues.
**Expectations:**
- 6‑12 month W2 contract (possible extension).
- Deliver architectural design, policy conversion, and performance improvements within project timeframe.
- Provide expertise in multi‑vendor environments and zero‑trust principles.
**Key Responsibilities:**
- Lead migration of firewall policies from Checkpoint to Fortinet, including rule optimization and traffic validation.
- Design and deploy Cisco ASA, Palo Alto, Fortinet, and Checkpoint firewalls across corporate, cloud, and remote sites.
- Architect and manage SD‑WAN (Fortinet, Cisco, Prisma Access) to optimize global connectivity, traffic steering, and fail‑over.
- Configure, troubleshoot, and optimize EIGRP, BGP, OSPF routing protocols.
- Develop NAT policies and analyze routing tables for performance and security.
- Manage Zscaler ZIA/ZPA cloud‑security, Radware DDoS protection, and IPS/IDS solutions.
- Perform risk assessments, firewall audits, and compliance validation.
- Troubleshoot SD‑WAN performance, routing conflicts, and connectivity issues.
- Ensure seamless integration among SD‑WAN, firewalls, cloud security, and on‑prem networks.
**Required Skills:**
- 5‑8 years network‑security engineering experience.
- Proficiency with Cisco ASA, Checkpoint, Fortinet FortiGate, Palo Alto firewalls.
- Strong knowledge of SD‑WAN (Fortinet SD‑WAN, Cisco SD‑WAN, Prisma Access).
- Configuring and troubleshooting EIGRP, BGP, OSPF.
- Hands‑on VPN (IPSec, SSL, GRE, DMVPN, L2TP) security.
- NAT, firewall rule optimization, routing table analysis.
- Radware DDoS protection, IPS/IDS, threat mitigation.
- Zero‑trust security architecture and secure SD‑WAN concepts.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Technology, or related field (or equivalent experience).
- Certifications: CISSP, CCNP Security, Fortinet NSE 5/6, Checkpoint CCSA, or Palo Alto PA‑CP. (Additional certifications welcome.)