Network Security Engineer-Banking
Network Security Engineer-Banking
dicetek llcEarly Applicant
- Posted 10 days ago
- Be among the first 10 applicants
Job Description
Key Responsibilities *
F5: 301a/b (BIG-IP LTM), 302 (ASM/Advanced WAF) or equivalent practical mastery.
- Own firewall and WAF rule life-cycle: design, change review, implementation, optimization, and periodic recertification.
- Manage SSL/TLS certificates, ciphers, and HSTS for internet-facing services; enforce secure crypto standards.
- Build and maintain site-to-site VPNs, SD-WAN, and secure remote access solutions across hybrid networks.
- Integrate network security controls with SIEM/SOAR and network telemetry; develop actionable runbooks.
- Implement Azure/AWS network security (VNet/VPC design, NSGs/NACLs, PrivateLink, Transit Gateway/Virtual WAN, Firewall/IDS/IPS).
- Deploy and govern cloud WAF and application gateways; integrate with native services where applicable.
- Embed guardrails (IaC policy, tagging, security blueprints) and support DevSecOps workflows.
- Required Skills *
- Expert hands-on with:
- F5 BIG-IP (ASM/Advanced WAF): policy tuning, attack signatures, bot and DDoS mitigation, iRules basics.
- Palo Alto Networks: security policy design, App-ID/URL filtering, Threat Prevention/WildFire, Panorama.
- Fortinet FortiGate/FortiManager/FortiAnalyzer: NGFW policies, IPS/AV/web filter, automation, logging.
- Citrix ADC (NetScaler): L7 load balancing, SSL/TLS, content switching, AppFW exposure.
- Strong Azure and AWS networking & security: VNet/VPC, peering, routing, NSG/NACL, Azure Firewall/AWS Network Firewall, Application Gateway/ALB/WAF, PrivateLink, Transit Gateway/Virtual WAN.
- Protocol depth: TCP/IP, BGP/OSPF, NAT, DNS, TLS, HTTP/S, IPsec/SSL VPN.
- Proven experience designing for high availability, performance, and security compliance.
- Security first mindset with pragmatic delivery.
- Ownership, attention to detail, and strong troubleshooting under pressure.
- Collaboration across infra, app, SOC, and risk teams; mentoring capability.
F5: 301a/b (BIG-IP LTM), 302 (ASM/Advanced WAF) or equivalent practical mastery.
- Palo Alto: PCNSE.
- Fortinet: NSE 4–7 (NSE 7 highly desirable).
- Citrix: CCA-N/CCP-N (ADC).
- Cloud: Azure Security Engineer (AZ-500), AWS Security – Specialty (or Architect certs with strong security exposure).
