Network Security Engineer
⚲ Warszawa, Gdańsk, Wrocław, Kraków, Poznań
Do uzgodnienia
Wymagania
- NGFW
- Palo Alto
- Fortinet
- DDoS mitigation
- Zero Trust
- SASE frameworks (e.g., Zscaler, Prisma Access)
- cloud networking components
- protocols (BGP, OSPF, DNS, TLS/SSL)
Opis stanowiska
Your responsibilities:
Edge Architecture & Engineering
• Perimeter Defense Mastery: Lead the end-to-end deployment, configuration, and maintenance of Next-Generation Firewalls (Palo Alto, Fortinet), ensuring high availability (Active/Active & Active/Passive) and optimal inspection performance across global entry points.
Zero Trust Transition: Architect and implement ZTNA solutions to move beyond legacy VPNs, focusing on granular, application-level access and identity-aware security policies.
• Multi-Cloud Network Security: Engineer and manage cloud-native security controls within AWS, Azure, and GCP, ensuring consistent security posture across hybrid and multi-cloud environments.
• DDoS & Threat Mitigation: Design and refine DDoS protection strategies and automated threat prevention policies (SSL decryption, IPS/IDS) to shield critical infrastructure from sophisticated external attacks.
Product Lifecycle & Evolution
• Lifecycle Governance: Oversee the delivery of Edge solutions from initial design through build, global rollout, and continuous optimization, ensuring that all security controls are reliable, scalable, and documented.
• Edge Innovation: Proactively identify emerging trends in Edge computing and SASE (Secure Access Service Edge) to inform the product roadmap and maintain a competitive advantage in network defense.
Operational Excellence & Visibility
• Technical Subject Matter Expertise: Serve as the lead engineer for complex network security escalations, performing deep-packet analysis and root-cause investigations to implement long-term architectural fixes.
• Security Observability: Develop advanced monitoring dashboards and telemetry to provide real-time visibility into edge traffic patterns, attack surfaces, and the health of the security stack.
• Automation & Orchestration: Manage security policies as code while continuously improving automation workflows and cross-platform orchestration to eliminate manual friction, reduce operational overhead, and ensure consistent, high-speed security enforcement.
• Self-Service & Enablement: Build and maintain automate
We are looking for you, if you have:
Education / Experience
• Educational Background: Bachelor’s degree in Computer Science, Software Engineering, Information Security, or a related technical field.
• Perimeter Security Mastery: 5+ years of hands-on experience in designing and managing enterprise-grade Firewall environments (specifically Palo Alto and/or Fortinet).
• Cloud Security Expertise: Proven track record of implementing network security controls in at least two major cloud providers (AWS, Azure, or GCP).
• Perimeter & Inspection Expertise: Proven track record in configuring and maintaining Palo Alto Next-Generation Firewalls (NGFW), including TLS inspection, User identification, WildFire, Threat Prevention, URL Filtering and GlobalProtect.
• Automation Engineering: Proven experience using Ansible, Terraform, or Python to manage network security infrastructure at scale.
• Large-Scale Infrastructure: Experience managing security controls in complex, global environments involving thousands of diverse device profiles (IoT, Medical, Corporate).
• Regulated Industry: Experience working in highly regulated environments (e.g., Pharmaceuticals, Healthcare, or Finance) is a significant plus.
Technical Skills
• NGFW Expert: Expert-level knowledge of Palo Alto and/or Fortinet platforms, including advanced threat prevention, SSL decryption, and high-availability design.
• DDoS Mitigation: Experience managing specialized DDoS protection services (e.g., Akamai, Cloudflare, or F5).
• ZTNA & Remote Access: Proficiency in modern Zero Trust architectures and SASE frameworks (e.g., Zscaler, Prisma Access).
• Multi-Cloud Networking: Strong understanding of cloud networking components (VPCs, VNETs, Transit Gateways, Cloud Firewalls).
• Network Foundations: Deep understanding of core protocols (BGP, OSPF, DNS, TLS/SSL) and how they intersect with security enforcement.
Skills below will be considered a plus:
• Vendor certifications: Fortinet NSE or Palo Alto Networks PCNSA PCNSE or Cisco CCNP Security
• Cybersecurity certification: CISSP
• Infrastructure as Code (IaC): Proficiency in Terraform and GitHub to maintain version-controlled, reproducible security configurations.
• Scripting & Integration: Strong skills in Python or Go to build custom API integrations between security platforms and internal orchestration tools.
• DDoS Mitigation: Experience managing specialized DDoS protection services (e.g., Akamai, Cloudflare, or F5).
• Governance Frameworks: Familiarity with NIST, ISO 27001, and FAIR data principles.
Leadership Skills
• Communication: Strong ability to build trust with network and infrastructure experts and explain complex security policy concepts to non-technical stakeholders.
• Innovation & Curiosity: A relentless passion for staying ahead of threat actors by researching emerging network security trends and automated enforcement techniques.
• Thriving in Ambiguity: Ability to navigate global complexity and drive clarity when translating high-level security requirements into functional network policies.
• Self-Starter: Proven ability to manage technical workstreams from concept to production with minimal supervision, taking full ownership of the Edge Defense product lifecycle.
Additional Qualifications
• Demonstrated ability to mentor colleagues with less experience and provide guidance on cybersecurity best practices and analysis techniques
• Strong facilitation, communication, and conflict resolution skills to ensure alignment across multiple product squads and complex stakeholder networks
• Demonstrated interpersonal, collaborative and commitment to operational excellence skills.
We offer:
• Participation in interesting and demanding projects.
• Flexible working hours.
• A great, non-corporate atmosphere.
• Possibility to work remote or hybrid (2 days per week from the office).
• Opportunities for development and promotion.
• Attractive package of benefits.
We reserve the right to contact the selected candidates.
Edge Architecture & Engineering
• Perimeter Defense Mastery: Lead the end-to-end deployment, configuration, and maintenance of Next-Generation Firewalls (Palo Alto, Fortinet), ensuring high availability (Active/Active & Active/Passive) and optimal inspection performance across global entry points.
Zero Trust Transition: Architect and implement ZTNA solutions to move beyond legacy VPNs, focusing on granular, application-level access and identity-aware security policies.
• Multi-Cloud Network Security: Engineer and manage cloud-native security controls within AWS, Azure, and GCP, ensuring consistent security posture across hybrid and multi-cloud environments.
• DDoS & Threat Mitigation: Design and refine DDoS protection strategies and automated threat prevention policies (SSL decryption, IPS/IDS) to shield critical infrastructure from sophisticated external attacks.
Product Lifecycle & Evolution
• Lifecycle Governance: Oversee the delivery of Edge solutions from initial design through build, global rollout, and continuous optimization, ensuring that all security controls are reliable, scalable, and documented.
• Edge Innovation: Proactively identify emerging trends in Edge computing and SASE (Secure Access Service Edge) to inform the product roadmap and maintain a competitive advantage in network defense.
Operational Excellence & Visibility
• Technical Subject Matter Expertise: Serve as the lead engineer for complex network security escalations, performing deep-packet analysis and root-cause investigations to implement long-term architectural fixes.
• Security Observability: Develop advanced monitoring dashboards and telemetry to provide real-time visibility into edge traffic patterns, attack surfaces, and the health of the security stack.
• Automation & Orchestration: Manage security policies as code while continuously improving automation workflows and cross-platform orchestration to eliminate manual friction, reduce operational overhead, and ensure consistent, high-speed security enforcement.
• Self-Service & Enablement: Build and maintain automate
We are looking for you, if you have:
Education / Experience
• Educational Background: Bachelor’s degree in Computer Science, Software Engineering, Information Security, or a related technical field.
• Perimeter Security Mastery: 5+ years of hands-on experience in designing and managing enterprise-grade Firewall environments (specifically Palo Alto and/or Fortinet).
• Cloud Security Expertise: Proven track record of implementing network security controls in at least two major cloud providers (AWS, Azure, or GCP).
• Perimeter & Inspection Expertise: Proven track record in configuring and maintaining Palo Alto Next-Generation Firewalls (NGFW), including TLS inspection, User identification, WildFire, Threat Prevention, URL Filtering and GlobalProtect.
• Automation Engineering: Proven experience using Ansible, Terraform, or Python to manage network security infrastructure at scale.
• Large-Scale Infrastructure: Experience managing security controls in complex, global environments involving thousands of diverse device profiles (IoT, Medical, Corporate).
• Regulated Industry: Experience working in highly regulated environments (e.g., Pharmaceuticals, Healthcare, or Finance) is a significant plus.
Technical Skills
• NGFW Expert: Expert-level knowledge of Palo Alto and/or Fortinet platforms, including advanced threat prevention, SSL decryption, and high-availability design.
• DDoS Mitigation: Experience managing specialized DDoS protection services (e.g., Akamai, Cloudflare, or F5).
• ZTNA & Remote Access: Proficiency in modern Zero Trust architectures and SASE frameworks (e.g., Zscaler, Prisma Access).
• Multi-Cloud Networking: Strong understanding of cloud networking components (VPCs, VNETs, Transit Gateways, Cloud Firewalls).
• Network Foundations: Deep understanding of core protocols (BGP, OSPF, DNS, TLS/SSL) and how they intersect with security enforcement.
Skills below will be considered a plus:
• Vendor certifications: Fortinet NSE or Palo Alto Networks PCNSA PCNSE or Cisco CCNP Security
• Cybersecurity certification: CISSP
• Infrastructure as Code (IaC): Proficiency in Terraform and GitHub to maintain version-controlled, reproducible security configurations.
• Scripting & Integration: Strong skills in Python or Go to build custom API integrations between security platforms and internal orchestration tools.
• DDoS Mitigation: Experience managing specialized DDoS protection services (e.g., Akamai, Cloudflare, or F5).
• Governance Frameworks: Familiarity with NIST, ISO 27001, and FAIR data principles.
Leadership Skills
• Communication: Strong ability to build trust with network and infrastructure experts and explain complex security policy concepts to non-technical stakeholders.
• Innovation & Curiosity: A relentless passion for staying ahead of threat actors by researching emerging network security trends and automated enforcement techniques.
• Thriving in Ambiguity: Ability to navigate global complexity and drive clarity when translating high-level security requirements into functional network policies.
• Self-Starter: Proven ability to manage technical workstreams from concept to production with minimal supervision, taking full ownership of the Edge Defense product lifecycle.
Additional Qualifications
• Demonstrated ability to mentor colleagues with less experience and provide guidance on cybersecurity best practices and analysis techniques
• Strong facilitation, communication, and conflict resolution skills to ensure alignment across multiple product squads and complex stakeholder networks
• Demonstrated interpersonal, collaborative and commitment to operational excellence skills.
We offer:
• Participation in interesting and demanding projects.
• Flexible working hours.
• A great, non-corporate atmosphere.
• Possibility to work remote or hybrid (2 days per week from the office).
• Opportunities for development and promotion.
• Attractive package of benefits.
We reserve the right to contact the selected candidates.
🔍 Dekoder Ogłoszenia
🔴
Perimeter Defense Mastery
Oczekuje się od Ciebie pełnej kontroli nad istniejącymi rozwiązaniami ochrony obwodowej, a niekoniecznie budowania ich od zera.
🔴
Zero Trust Transition
Może oznaczać, że projekt jest w początkowej fazie lub wymaga znaczącej pracy nad migracją istniejących systemów.
🟡
Multi-Cloud Network Security
Może oznaczać zarządzanie bezpieczeństwem w wielu chmurach, ale także konieczność radzenia sobie z różnicami i integracją między nimi.
🟡
DDoS & Threat Mitigation
Oprócz projektowania, prawdopodobnie będziesz odpowiedzialny za bieżące reagowanie na incydenty i analizę zagrożeń.
🔴
Edge Innovation
Może oznaczać śledzenie trendów, ale także konieczność wdrażania nowości w ograniczonych zasobach lub przy braku jasnej wizji strategicznej.