- Company Name
- Charles Schwab
- Job Title
- Network Security Engineer - Hybrid
- Job Description
-
**Job title:** Network Security Engineer – Hybrid
**Role Summary:** Design, implement, and maintain secure network infrastructure in a regulated, cloud‑enabled finance environment, ensuring high availability, compliance, and threat resilience. Works cross‑functionally with IAM, DevOps, and operations teams to embed security controls across virtualized, containerized, and public cloud platforms.
**Expectations:** Deliver secure, scalable architecture with minimal operational overhead; communicate complex security concepts clearly; demonstrate strong analytical, troubleshooting, and continuous learning aptitude; collaborate effectively in a fast‑paced, multi‑time‑zone setting.
**Key Responsibilities:**
- Develop and refine firewall, routing, and segmentation policies using Palo Alto, Check Point, Fortinet, AWS, Azure, GCP, and VMWare NSX‑T.
- Automate security deployments with IaC (Terraform, Ansible, Salt) and integrate into existing CI/CD pipelines (Git, Jenkins, Bamboo).
- Configure and manage routing protocols (OSPF, EIGRP, BGP, IP Multicast) and ACLs on distributed and cloud networks.
- Conduct threat modeling, vulnerability assessments, and remediate findings to meet audit and regulatory requirements.
- Collaborate with DevOps and platform teams to embed security into container orchestration (K8s, PCF) and application lifecycle.
- Provide documentation, runbooks, and training materials for peer teams; support incident response and forensics.
- Participate in agile ceremonies, sprint planning, and backlog refinement for security features.
**Required Skills:**
- 2+ years of network security design in large virtualized or containerized environments.
- Expertise in firewall technologies (Palo Alto, Check Point, Fortinet), SD‑Firewall, and cloud security controls.
- Strong TCP/IP, DNS, VLAN, QoS, ACL, OSPF, EIGRP, BGP knowledge.
- Automation proficiency (Terraform, Ansible, Salt) and IaC best practices.
- Experience with SCM/DevOps toolchains (Git, Jenkins, Concourse).
- Familiarity with Agile/Scrum and continuous integration/delivery concepts.
- Excellent analytical, problem‑solving, and communication skills; ability to influence cross‑functional teams.
**Required Education & Certifications:**
- Bachelor’s degree in Cyber Security, Computer Science, Information Technology, or related field (or equivalent practical experience).
- Relevant certifications such as CCNA Security, CCNP, Palo Alto PAN‑OS, Check Point CCSE, or equivalent are preferred.