06 Aug
|
Mphasis
|
Bengaluru
Job Title: Senior Network Security Engineer (Microsegmentation)Designation: Technical Architect Location: Bangalore Job Summary: We are seeking a highly skilled Senior Network Security Engineer with a strong focus on microsegmentation and Zero Trust principles. The ideal candidate will be responsible for translating high-level business objectives into comprehensive network security solutions, ensuring the security and resilience of our global IT infrastructure. This role requires a deep understanding of network security architecture, microsegmentation strategies, and cross-team collaboration to enhance our security posture.
Responsibilities - Translate high-level business strategic objectives into Enterprise IT requirements and conceptual designs.
- Develop and support comprehensive solutions that align with Clients's global network security and microsegmentation strategy.
- Maintain a multi-year strategic network and security architecture roadmap, incorporating Zero Trust and segmentation-driven security models.
- Lead end-to-end network and security architecture across global platforms, ensuring secure, high-performing, fault-tolerant, and resilient environments.
- Architect and implement microsegmentation strategies across data center, campus, and cloud environments to limit lateral movement and enforce least-privilege access.
- Design and operationalize Zero Trust Architecture (ZTA) principles, integrating identity, application, and network-based policy enforcement.
- Collaborate with application owners to discover, validate, and map application dependencies for policy-driven segmentation.
- Define and enforce granular security policies using label/tag-based segmentation approaches across hybrid environments.
- Integrate microsegmentation with firewalls, SIEM, IAM, EDR/XDR, and cloud-native controls for unified policy enforcement.
- Lead the adoption of microsegmentation platforms (e.g., Guardicore/Akamai Segmentation).
- Develop segmentation governance models, policy lifecycle management, and compliance alignment (CIS/NIST/Zero Trust frameworks).
- Participate in network security design reviews to ensure all implementations meet enterprise security standards.
- Analyze business requirements to design and implement security across data centers, campus networks, and hybrid environments.
- Provide ongoing risk metrics, control effectiveness tracking, and security posture reporting.
- Conduct and support internal and external security audits and compliance assessments.
- Maintain awareness of emerging threats and update policies accordingly.
- Develop and manage policies, processes, and procedures ensuring reliability, availability, and security of network systems.
- Manage and optimize Security Information and Event Management (SIEM) systems.
- Collaborate with Cyber Security, infrastructure,
and application teams toward compliance and operational excellence.
Mandatory
Skills - Strong hands-on experience in designing and implementing microsegmentation solutions in complex enterprise environments.
- Proven capability to build application-aware segmentation policies based on traffic flow analysis.
- Experience with policy simulation, enforcement, monitoring, and optimization in segmentation platforms.
- Understanding of east-west traffic inspection, workload protection, and software-defined segmentation.
- Familiarity with Zero Trust Network Access (ZTNA) and identity-driven access models.
- Robust experience managing LAN/WAN security technologies, including firewalls, IDS/IPS, SIEM, VPN, and NAC.
- Expertise in firewall architecture and design with hands-on experience in Fortinet, Palo Alto, and Juniper.
- Experience securing public and private cloud environments (AWS, Azure, GCP).
- Strong knowledge of routing protocols, network services, and IPv4/IPv6 architecture.
Preferred Skills - Experience with Web Application and API Protection (WAAP) solutions.
- Experience with SDN and SD-WAN architectures, including segmentation use cases.
- Experience managing enterprise data center environments with technologies including Aruba, Arista, and Juniper switching.
Qualifications - Bachelor's Degree in Computer Science, Network Engineering, or related field (or equivalent experience).
- Preferred certifications: CCNP / CCIE, JNCIE Security certifications (CISSP, CISM, or equivalent).
📌 Technical Architect (Bengaluru)
🏢 Mphasis
📍 Bengaluru