Principal Security EngineerCheckpoint & PaloAlto (Pune)

Principal Security EngineerCheckpoint & PaloAlto (Pune)

19 Sep
|
TEKWISSEN
|
Pune

19 Sep

TEKWISSEN

Pune

Overview:

TekWissen is a global workforce management provider throughout India and many other countries in the world. The below job opportunity is one of our clients which has been a one-stop solution for qualified digital services.

Position: Principal Security Engineer (L3) - Checkpoint & PaloAlto

Location: Pune

Job Type: Full Time

Work Type: Remote

Job Summary

- The Principal Security Engineer is the bank's most senior technical authority for network-security and firewall architecture, setting the target-state design, standards and engineering direction for the Check Point and Palo Alto estate across production, DMZ, DR and cloud.
- Operating as a hands-on design leader rather than a people manager, the role owns architecture decisions, complex programme delivery (migrations, refreshes, segmentation), threat-prevention strategy, automation, and the highest level of incident and problem escalation driving resilience, security posture and regulatory assurance for business-critical and customer-facing banking services.
- The role influences across teams and vendors and mentors senior and L3 engineers.

Key Responsibilities

- Architecture & Technical Strategy
- Own the target-state architecture and technical roadmap for the firewall and network-security estate (Check Point and Palo Alto), aligned to Enterprise Architecture and Information Security strategy.
- Define and enforce security design standards, reference architectures, hardening baselines and rule-lifecycle governance across the bank.
- Lead network segmentation and Zero-Trust / micro-segmentation strategy, DMZ and east-west security design, and secure connectivity for cloud and hybrid environments.
- Provide design authority and technical sign-off on high-impact changes, new solutions and HLD/LLD across the security estate

- Deep Platform Engineering Check Point & Palo Alto

- Act as the deepest technical escalation and design authority on Check Point (Gaia, MDS/Provider-1, ClusterXL, VSX, Maestro hyperscale) and Palo Alto (PAN-OS, Panorama, App-ID/User-ID/Content-ID, Threat Prevention, WildFire, GlobalProtect).
- Design and validate high-scale, highly-available firewall deployments, including capacity,



throughput and interface/uplink planning to eliminate single points of failure and chokepoints.
- Set threat-prevention, IPS and SSL-decryption strategy and tuning standards for a banking threat profile.
- Lead complex platform migrations, refreshes and major version upgrades end-to-end, with robust rollback and minimal business impact.

- Automation & Engineering Excellence

- Drive automation of policy, configuration and change (Check Point Management API, Palo Alto AS3/XML API, Ansible/Python) to improve consistency, speed and auditability.
- Establish infrastructure-as-code and configuration-standardisation practices for the security estate.
- Champion observability, config backup/compliance (SolarWinds NCM) and continuous posture monitoring.

- Governance, Risk & Assurance

- Serve as senior technical lead for audits and regulatory engagements (SAMA / CBUAE, PCI-DSS); own remediation strategy and evidence for network-security findings.
- Partner with Information Security (ISG), Risk and Enterprise Architecture on security posture, standards and technology selection.
- Lead root-cause analysis and problem management for major (P1) security incidents and define preventive controls.

- Technical Leadership & Mentoring

- Mentor and uplift senior, L3 and L2 engineers; set engineering standards and review complex designs and changes.
- Represent the bank in senior technical engagements with OEMs/vendors (Check Point, Palo Alto, F5) and influence product roadmaps and support outcomes.

- Required Skills & Experience

- Expert-level, current hands-on mastery of Check Point (incl. MDS, VSX, Maestro) and Palo Alto (incl. Panorama, advanced Threat Prevention).
- Strong architecture capability — segmentation, Zero Trust, DMZ, hybrid/cloud security connectivity, and HA/DR design.




- Advanced networking — routing/switching, NAT, VPN (IPsec/SSL), BGP/OSPF, and high-throughput/interface design.
- Automation and IaC — Check Point/Palo Alto APIs, Ansible, Python; CI/CD for network security desirable.
- Adjacent controls — IPS/IDS, WAF/F5, proxy/SASE/SSE, and SIEM integration.
- Strong grasp of security frameworks and regulatory requirements relevant to banking.

- Certifications (Preferred)

- Check Point CCSM (Master) — CCSE required as a minimum.
- Palo Alto PCNSE (and PCSAE/ architecture credentials desirable).
- CISSP and/or security architecture certification (e.g. SABSA, TOGAF) strongly preferred.
- Cloud security certification (Azure / AWS) an advantage.

- Experience & Qualifications

- Bachelor's or Master's degree in Computer Science, Engineering, Information Security or related field.
- 12+ years in network/security engineering, including significant time as a senior/lead or architect owning firewall and network-security design at enterprise scale.
- Demonstrable track record leading large migrations, segmentation programmes and multi-vendor security architecture.
- Banking or large regulated-enterprise experience with business-critical, customer-facing environments strongly preferred.

- Behavioral / Leadership Skills

- Recognised technical authority — sets direction and makes high-stakes design decisions with confidence and sound judgement.
- Excellent communication — able to influence leadership, articulate risk, and align stakeholders and vendors.
- Strong ownership, and a disciplined approach to change, documentation, risk and assurance.
- Collaborative technical leader who elevates the capability of the wider engineering team.

- Preferred Industry Experience

- Banking
- Financial Services
- Insurance (BFSI)
- Large Enterprise Security Operations Environment

- Work Model

- Full-time Remote/ customer onsite deployment at customer location
- Willingness to support after-hours activities during critical incidents or planned maintenance
- Participation in on-call support rotation if required

TekWissen® Group is an equal opportunity employer supporting workforce diversity.

📌 Principal Security EngineerCheckpoint & PaloAlto (Pune)
🏢 TEKWISSEN
📍 Pune

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: principal security engineercheckpoint & paloalto (pune) / pune

Subscribe to this job alert:

Get the latest job offers by email for: principal security engineercheckpoint & paloalto (pune) / pune