05 Sep
|
HIRESTAR JOB BANK
|
Kochi
05 Sep
HIRESTAR JOB BANK
Kochi
Position: Lead Network & Cyber Security Engineer (L3) – Team Lead Department: Projects Delivery & Professional Services Employment Type: Full-Time Reporting To: Department Head 1. Company Overview Hilal Technology is a leading Systems Integrator (SI) specializing in delivering turnkey IT infrastructure, network, and cybersecurity solutions to enterprise clients. We bridge the gap between complex vendor technologies (networking, security, and unified communications) and business operational needs. We are seeking a highly skilled L3 Team Lead to lead our combined network and security implementation pod, ensuring that our clients receive robust, scalable, and seamlessly integrated infrastructure and security architectures. 2. Role Summary This is a client-facing, hands-on technical leadership role. As the L3 Team Lead, you will be the highest technical authority for Network Architecture, Routing & Switching, Network Security, Cyber Security, and Unified Communications deployments for Hilal Technology's client base. Your primary mandate is to design, implement, migrate, and troubleshoot network and security solutions, leading a team of deployment engineers and working closely with the Project Manager and Technical Manager to ensure that what is sold is delivered to the highest standard. Important Note: This is a Project Delivery & Engineering role. The engineer must be available to resolve and support the team upon request & urgency. 3. Key Responsibilities A. Network Engineering (Routing & Switching) · Core Infrastructure: Design, configure, and troubleshoot complex enterprise LAN/WAN environments across Cisco (Catalyst/Nexus), Aruba (CX/Switches), Dell (PowerSwitch, DS Series), and Huawei (Cloud Engine/S-series) switches. · Advanced Routing: Implement and optimize dynamic routing protocols (OSPF, BGP, EIGRP, IS-IS) across multi-vendor routers and firewalls. · Wireless: Oversee deployment of enterprise wireless networks, specifically Cisco Meraki, Aruba Wireless (Controllers, Access Points, Central/ArubaOS) and Huawei WLAN solutions. · Network Automation & Management: Deploy and manage Cisco DNA Centre (Catalyst Centre) and Huawei iMaster NCE to automate provisioning, monitor network health, and enforce policy-based networking. B. Network & Cyber Security Engineering (Hands-On L3) · Multi-Vendor Firewall Expertise: Act as the L3 Subject Matter Expert / technical authority for deployment, migration, and tuning of Next-Gen Firewalls across Palo Alto, Check Point, Cisco (FTD/ASA), Fortinet (FortiGate), Juniper (SRX), and Huawei (USG/Firepower). · Execute complex firewall/security migrations (e.g., Check Point to Palo Alto, Cisco to Fortinet, Legacy Cisco to Palo Alto, Juniper to Fortinet)
with minimal downtime using automation tools. · Configure advanced features including BGP/OSPF routing, SSL Decryption, App-ID, User-ID, Threat Prevention, and Site-to-Site/Remote Access VPNs (Route-based, Hub-and-Spoke, and SD-WAN integrations). · Network Access Control (NAC): Design and implement 802.1X and MAB solutions (e.g., Cisco ISE, FortiNAC, Aruba ClearPass) to secure wired, wireless, and VPN access, integrated with enterprise wireless and switching infrastructure. · Identity & Access Management (MFA): Design and integrate Multi-Factor Authentication solutions, specifically Cisco Duo and FortiAuthenticator, for remote VPN and admin access. · Privileged Access Management (PAM): Deploy PAM solutions (e.g., CyberArk, Wallix, BeyondTrust) including vaulting, session isolation, and integration with client Active Directories. · Endpoint Security (EDR/XDR): Lead large-scale agent deployment projects (CrowdStrike, SentinelOne, Cortex XDR, Defender) across client environments, ensuring policy tuning and false-positive resolution before handover. · Web Application Firewall (WAF): Deploy and tune WAF policies (e.g., F5, Imperva, FortiWeb, Cloudflare) in front of client web applications, balancing strict OWASP security with application availability without disrupting business logic. · Remote Access & SASE: Design and maintain enterprise VPN solutions (GlobalProtect, AnyConnect, FortiClient) and integrate with Zero Trust Network Access (ZTNA) principles. C. Unified Communications & Collaboration (Voice) · IP Telephony & Video: Lead the deployment, migration, and troubleshooting of enterprise voice environments, including: · Cisco Collaboration: CUCM (Call Manager), Unity Connection, Expressway, and WebEx Calling integration. · Avaya Collaboration: Aura Communication Manager, Session Manager, and IP Office. · Session Border Controllers (SBC): Configure and manage Ribbon SBC & AudioCodes for SIP trunking, VoIP security, and interoperability between carrier networks and enterprise voice. D. Team Leadership & Project Management · Team Supervision: Lead, mentor, and assign daily tasks to a team of L1/L2 Network and Security implementation engineers. Review technical changes, conduct performance reviews, and drive internal cross-training and mentoring for career growth. · Project Delivery:
Own the "Technical Implementation Plan." Work with the PMO to ensure deployments are completed on time, within scope, and within budget. · Client Handover: Create "As-Built" documentation (LLDs) and conduct training sessions for clients before transitioning them to Hilal Technology's Managed Services or SOC teams. · Escalation Point: Serve as the final P1/P2 technical escalation point during project hyper-care, resolving complex multi-vendor (Network/Security/Voice) routing, stability, integration, or connectivity issues. 4. Required Skills & Qualifications Experience · Minimum 8-10 years in Network & Cyber Security Engineering, with at least 3 years in a Systems Integrator (SI) or Qualified Services environment. · Proven track record of managing simultaneous projects and team workloads for multiple clients. Vendor & Technology Expertise (Mandatory) · Networking: Hands-on command of Cisco IOS/IOS-XE, Aruba CX/OS, Huawei VRP, and Dell OS10/OS9 (Enterprise SONiC OS is a plus). · Firewalls: Strong hands-on expertise in at least three of the following: Palo Alto Strata, Check Point Quantum, Cisco Firepower, Fortinet FortiGate, Juniper SRX, Huawei. · Deep Domain Knowledge: NAC (Cisco ISE / Aruba ClearPass / FortiNAC), EDR/XDR, WAF, and PAM. · Collaboration: Deep understanding of SIP protocol, dial plans, and troubleshooting tools (Translations, Trace routes, Wireshark). Must have deployed either Cisco or Avaya IPT solutions. · SBC: Working knowledge of Ribbon SBC configurations for SIP trunks. · Authentication: Hands-on experience with Cisco Duo and FortiAuthenticator. Networking Knowledge · CCNP/CCIE level understanding of Routing & Switching (BGP, OSPF, EIGRP, IS-IS, VLANs, Spanning Tree, VRF, VXLAN, TCP/IP, DNS, DHCP). · Ability to use Wireshark/tcpdump to read packet captures and prove network issues are not the firewall's fault, resolving connectivity, voice quality (VoIP), latency, or network bottleneck issues. Soft Skills · Communication: Excellent written and verbal communication in English. Ability to explain complex technical issues and present solutions to client stakeholders and C-level executives. · Leadership: Proven ability to motivate a technical team and enforce engineering standards. · Documentation: High proficiency in creating High-Level Designs (HLDs), Low-Level Designs (LLDs), Migration Runbooks, and Network Diagrams (Visio, PowerPoint, Draw.io & other tools). Certifications (Preferred) · Networking: CCNP Enterprise, CCIE (R&S;/Enterprise/Security), Aruba ACSP/ACMP, or Huawei HCIP/HCIE. · Security: PCNSE (Palo Alto), NSE 7/8 (Fortinet), CCSE (Check Point), JNCIE-SEC, or CISSP.
📌 Lead Network & Cyber Security Engineer- (Kochi)
🏢 HIRESTAR JOB BANK
📍 Kochi