07 Aug
|
Philips
|
Bengaluru
Job Description
Senior Security Operations / SME / Governance u2014 Digital Networks
Role type: Senior individual contributor / hands-on subject-matter expert (with mentoring)
Experience: 10u201315 years in enterprise network security, with deep and hands-on depth on Cisco Secure Firewall and at least one major proxy/SSE platform. Hands-on is non-negotiable, this is not a review-only role.
About the role
Deep technical authority for our firewall, proxy, and generic secure-access estate. You are the person who is hands-on in the consoles, scripts, and vendor APIs every week the final escalation point when something hard breaks and the one who keeps the estate audit-ready between incidents. You work in a patient-safety-first engineering culture: direct, plain-spoken, evidence over slideware. Profile mix: 55% Security Operations | 25% Hands-on Technical (incl. automation & AIOps) | 20% Governance, Risk & Compliance.
What you'll own:
- Firewall estate u2014 Cisco Secure Firewall (FTD / FMC / ASA / Firepower): rule lifecycle and hygiene, HA, FMC upgrades and migrations, perimeter, and internal segmentation.
- Proxy & web security u2014 PAC file management at global scale (including China and other high-latency / restricted regions), proxy policy, SSL/TLS inspection.
- Secure Service Edge / SASE u2014 Zscaler (ZIA / ZPA) and Cisco Umbrella as the primary platforms. Exposure to Palo-Alto, Netskope or Cloudflare One is a plus.
- Remote & site connectivity u2014 IPSec / SSL VPN, AnyConnect / Secure Client, site-to-site (S2S), out-of-band management (OOBM), and partner access (S2S / VDI).
- Identity & access u2014 Cisco ISE / AAA.
- Certificates & PKI u2014 certificate lifecycle and expiry management, TLS, and closed-loop certificate automation.
- Vulnerability & advisory response u2014 PSIRT cadence, patching, and upgrade lifecycle across the estate.
Hands-on Technical:
- Deep, current hands-on across the estate: Cisco FTD/FMC/ASA/Firepower, ISE, Cisco SSE/Umbrella, Zscaler ZIA/ZPA, PAC files, PKI/TLS, rule design, SSL inspection, FMC HA and migrations, ISE policy, VPN (IPSec/SSL/S2S) troubleshooting.
- Holds L3/L4 escalation authority with Cisco TAC, Zscaler and managed-service partners, ie: the break-glass engineer when P1/MI hits: firewall HA failures, FMC migrations, PSIRT response.
- Writes and maintains automation in Python, Ansible and Terraform, working directly against vendor REST APIs: Cisco FMC, Zscaler, ISE, and IPAM/DNS (e.g. Efficient IP): safe bulk rule changes, PAC at scale.
- Maintains lab/sandbox to test changes and upgrades before production.
- Cloud network security u2014 Liaises with Cloud Infrastructure, Security, DNS, IPAM and Active Directory teams to secure and enable network connectivity and integration across AWS, Azure, GCP and China cloud u2014 Security groups, NACLs, NVA / cloud firewalls, Cloud On-Ramp, ExpressRoute/DX, TGW/VNet peering, SSE PoP integration and CSPM signal handoff.
Operations & governance:
- Drives the firewall/proxy/SSE domain from reactive firefighting to a predictable run model: ITSM discipline, RCA, change governance, and SLA/KPI ownership for the domain.
- Senior ServiceNow change approver for firewall, proxy, VPN and other security-touching changes technical reviewer on the change/technical review board.
- Keeps the estate audit-ready u2014 NIS2, ISO 27001, healthcare-grade u2014 with defensible evidence and change-to-change-record traceability.
- Maintains the domain security risk register and supports DR / security tabletop drills.
- Holds managed-service and OEM partners (Cisco, Zscaler and the relevant MSPs) technically accountable on delivery quality, feeding the commercial and escalation process owned by the Lead.
- Stakeholder, Communication & Escalation Management u2014 Runs structured stakeholder engagement, leadership/vendor/audit communications, and escalation as a discipline (thresholds, pathways, ownership) feeding the Lead's commercial authority.
- Service (Operations, Delivery, Commercial & Contractual) Management u2014 Owns partner (MSPs, OEMs) service delivery (quality, milestones, acceptance, security), RFPs (evaluation, scoring, selection inputs), and commercial/contractual oversight (business case, sizing, ROI, lifecycle, services, support, licenses, purchases, Invoices, renewals, exit clauses) feeding the Lead's final decisioning.
Note: contract management, RFP ownership, business-case approval, and formal vendor-commercial escalation sit with the Lead, Digital Networks, this role provides the technical substance behind them.
Mentoring & collaboration:
- Works alongside engineers, not just reviewing them, ie:
sets the hands-on bar for the team.
- Mentorsu2019 junior engineers and interns.
- Partners with the Security Architect and the Lead represents the domain in relevant technical forums (change and architecture review boards).
Skills & Certifications:
Must-have certifications:
This role is certification-backed. We expect current and active credentials, not lapsed ones.
- CCNP Security (350-701 SCOR core plus a relevant concentration exam). The concentrations that map directly to this role:
- 300-710 SNCF u2014 Securing Networks with Cisco Firewalls (Secure Firewall / FMC) (highly preferred or willingness to get)
- 300-730 SVPN u2014 Secure VPNs (IPSec / SSL)
- 300-715 SISE u2014 Identity Services Engine (ISE)
- At least one current SSE vendor credential Zscaler is preferred.
Must-have skills:
- Hands-on: Cisco FTD / FMC / ASA / Firepower ISE Zscaler ZIA / ZPA Cisco Umbrella PAC files PKI / TLS.
- VPN: IPSec / SSL / AnyConnect / site-to-site / OOBM solutions.
- Automation: Python, Ansible, Terraform, REST APIs.
- AIOps / observability: Splunk or equivalent.
- ITIL v4 ways of working strong RCA discipline.
- Audit literacy: NIS2, ISO 27001 (healthcare / regulated-industry experience a plus).
- Explicit, direct, plain-English communication.
Nice-to-haves:
- ITIL Expert / Managing Skilled
- CISSP / CISM / CCSP
- AWS Security Specialty / Azure Security Engineer
- Palo-Alto, Netskope or Cloudflare One exposure
How we work together
We believe that we are better together than apart. For our office-based teams, this means working in-person at least 3 days per week.
Onsite roles require full-time presence in the companyu2019s facilities.
Field roles are most effectively done outside of the companyu2019s main facilities, generally at the customersu2019 or suppliersu2019 locations.
Indicate if this role is an office/field/onsite role.
About Philips
We are a health technology company. We built our entire company around the belief that every human matters, and we won't stop until everybody everywhere has access to the quality healthcare that we all deserve. Do the work of your life to help the lives of others.
u2022 Learn more about .
u2022 Discover .
u2022 Learn more about .
If youu2019re interested in this role and have many, but not all, of the experiences needed, we encourage you to apply. You may still be the right candidate for this or other opportunities at Philips. Learn more about our culture of impact with care .
📌 Senior Security Operations Lead u2014 Digital Networks (Bengaluru)
🏢 Philips
📍 Bengaluru