Network Security Engineer (New Delhi)

Network Security Engineer (New Delhi)

03 Aug
|
Tata Consultancy Services
|
New Delhi

03 Aug

Tata Consultancy Services

New Delhi

Network Security

L2/L3 Network Security Engineer

Summary:
Own complex incident response, advanced configuration, and optimization across security controls. Mentor L1 and drive stability.

Key Responsibilities

- Lead L2/L3 incidents (e.g., application breakage from WAF/IPS signatures, complex NAT/policy collisions, certificate chain issues, DNS failures).
- Design and implement non-standard changes: app-based firewalling, user-ID integrations, URL filtering strategies, DLP integration on proxy.
- Tune policies/rules for performance and security (rule clean-up, logging strategy, SSL decryption policy tuning).
- Manage PKI/KMS lifecycle end-to-end: CSR generation, CA workflows, cert pinning impacts, renewals at scale; operations on HSMs (key backup/restore, partition roles).
- DDI engineering: DNS forwarders/conditional forwarding, split DNS for hybrid, DHCP failover, IPAM role-based controls.
- NAC: 802.1X/EAP, device profiling, posture policies, remediation flows; integrate with AD/IdP and MDM/UEM.
- Troubleshoot with packet capture (SPAN/PCAP), decryption where authorized.
- Develop and maintain runbooks, SOPs, and automation scripts (e.g., via APIs).
- Support audits, implement security baselines and compliance controls.

Core Technologies & L2/L3 Scope

- Firewalls: App-ID/user-ID,



threat profiles, SSL decryption policies, HA failovers.
- WAF: Custom signatures, positive security model, bot mitigation tuning, API protection basics.
- IPS/IDS: Inline vs TAP, policy layers, exception management, performance tuning.
- PKI/HSM/KMS: Key lifecycle, HSM partitioning, KMS key rotation policies, envelope encryption concepts.
- DDI: DNSSEC/TSIG basics, split-horizon DNS, DHCP high availability, IPAM workflows.
- Web Proxy: Explicit/transparent modes, SSL inspection categories/exceptions, auth schemes (Kerberos/NTLM/SAML).
- NAC: Policy design, guest/BYOD flows, remediation VLANs, CoA (Change of Authorization).

Must-Have Skills

- Strong TCP/IP & security protocols; HTTP internals, TLS handshakes, certificate chains.
- Positive grasp of routing (OSPF/BGP) interactions with firewalls.
- Hands-on with at least two major vendors (e.g., Palo Alto / Fortinet / Cisco / Check Point; F5 / Imperva; Zscaler / Blue Coat / SWG; Infoblox/BlueCat; Cisco ISE / Aruba ClearPass).

Experience: 5+ years

Certifications: CCNP Security / PCNSE / NSE 5–7 / Check Point CCSA/CCSE / F5 201/301 / Zscaler ZIA/ZPA Professional / Infoblox NIOS / Cisco ISE Specialist.

📌 Network Security Engineer (New Delhi)
🏢 Tata Consultancy Services
📍 New Delhi

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: network security engineer (new delhi) / new delhi

Subscribe to this job alert:

Get the latest job offers by email for: network security engineer (new delhi) / new delhi