Search Jobs

Search by job, company or skills

Principal Security Engineer - Checkpoint & PaloAlto

Principal Security Engineer - Checkpoint & PaloAlto

tekwissen india
12-14 Years
  • Posted 5 days ago
  • Be among the first 10 applicants

Job Description

Overview

TekWissen is a global workforce management provider throughout India and many other countries in the world. The below job opportunity is one of our clients which has been a one-stop solution for professional digital services.

Position:Principal Security Engineer (L3) - Checkpoint & PaloAlto

Location: Pune

Job Type: Full Time

Work Type: Remote

Job Summary

  • The Principal Security Engineer is the bank's most senior technical authority for network-security and firewall architecture, setting the target-state design, standards and engineering direction for the Check Point and Palo Alto estate across production, DMZ, DR and cloud.
  • Operating as a hands-on design leader rather than a people manager, the role owns architecture decisions, complex programme delivery (migrations, refreshes, segmentation), threat-prevention strategy, automation, and the highest level of incident and problem escalation — driving resilience, security posture and regulatory assurance for business-critical and customer-facing banking services.
  • The role influences across teams and vendors and mentors senior and L3 engineers.

Key Responsibilities

  • Architecture & Technical Strategy
    • Own the target-state architecture and technical roadmap for the firewall and network-security estate (Check Point and Palo Alto), aligned to Enterprise Architecture and Information Security strategy.
    • Define and enforce security design standards, reference architectures, hardening baselines and rule-lifecycle governance across the bank.
    • Lead network segmentation and Zero-Trust / micro-segmentation strategy, DMZ and east-west security design, and secure connectivity for cloud and hybrid environments.
    • Provide design authority and technical sign-off on high-impact changes, new solutions and HLD/LLD across the security estate
  • Deep Platform Engineering — Check Point & Palo Alto
    • Act as the deepest technical escalation and design authority on Check Point (Gaia, MDS/Provider-1, ClusterXL, VSX, Maestro hyperscale) and Palo Alto (PAN-OS, Panorama, App-ID/User-ID/Content-ID, Threat Prevention, WildFire, GlobalProtect).
    • Design and validate high-scale, highly-available firewall deployments, including capacity, throughput and interface/uplink planning to eliminate single points of failure and chokepoints.
    • Set threat-prevention, IPS and SSL-decryption strategy and tuning standards for a banking threat profile.
    • Lead complex platform migrations, refreshes and major version upgrades end-to-end, with robust rollback and minimal business impact.
  • Automation & Engineering Excellence
    • Drive automation of policy, configuration and change (Check Point Management API, Palo Alto AS3/XML API, Ansible/Python) to improve consistency, speed and auditability.
    • Establish infrastructure-as-code and configuration-standardisation practices for the security estate.
    • Champion observability, config backup/compliance (SolarWinds NCM) and continuous posture monitoring.
  • Governance, Risk & Assurance
    • Serve as senior technical lead for audits and regulatory engagements (SAMA / CBUAE, PCI-DSS); own remediation strategy and evidence for network-security findings.
    • Partner with Information Security (ISG), Risk and Enterprise Architecture on security posture, standards and technology selection.
    • Lead root-cause analysis and problem management for major (P1) security incidents and define preventive controls.
  • Technical Leadership & Mentoring
    • Mentor and uplift senior, L3 and L2 engineers; set engineering standards and review complex designs and changes.
    • Represent the bank in senior technical engagements with OEMs/vendors (Check Point, Palo Alto, F5) and influence product roadmaps and support outcomes.
  • Required Skills & Experience
    • Expert-level, current hands-on mastery of Check Point (incl. MDS, VSX, Maestro) and Palo Alto (incl. Panorama, advanced Threat Prevention).
    • Strong architecture capability — segmentation, Zero Trust, DMZ, hybrid/cloud security connectivity, and HA/DR design.
    • Advanced networking — routing/switching, NAT, VPN (IPsec/SSL), BGP/OSPF, and high-throughput/interface design.
    • Automation and IaC — Check Point/Palo Alto APIs, Ansible, Python; CI/CD for network security desirable.
    • Adjacent controls — IPS/IDS, WAF/F5, proxy/SASE/SSE, and SIEM integration.
    • Strong grasp of security frameworks and regulatory requirements relevant to banking.
  • Certifications (Preferred)
    • Check Point CCSM (Master) — CCSE required as a minimum.
    • Palo Alto PCNSE (and PCSAE/ architecture credentials desirable).
    • CISSP and/or security architecture certification (e.g. SABSA, TOGAF) strongly preferred.
    • Cloud security certification (Azure / AWS) an advantage.
  • Experience & Qualifications
    • Bachelor's or Master's degree in Computer Science, Engineering, Information Security or related field.
    • 12+ years in network/security engineering, including significant time as a senior/lead or architect owning firewall and network-security design at enterprise scale.
    • Demonstrable track record leading large migrations, segmentation programmes and multi-vendor security architecture.
    • Banking or large regulated-enterprise experience with business-critical, customer-facing environments strongly preferred.
  • Behavioral / Leadership Skills
    • Recognised technical authority — sets direction and makes high-stakes design decisions with confidence and sound judgement.
    • Excellent communication — able to influence leadership, articulate risk, and align stakeholders and vendors.
    • Strong ownership, and a disciplined approach to change, documentation, risk and assurance.
    • Collaborative technical leader who elevates the capability of the wider engineering team.
  • Preferred Industry Experience
    • Banking
    • Financial Services
    • Insurance (BFSI)
    • Large Enterprise Security Operations Environment
  • Work Model
    • Full-time Remote/ customer onsite deployment at customer location
    • Willingness to support after-hours activities during critical incidents or planned maintenance
    • Participation in on-call support rotation if required
TekWissen® Group is an equal opportunity employer supporting workforce diversity.

More Info

Job Type:
Industry:
Function:
Employment Type:

Key Skills

Threat Prevention

SASE

F5 proxy

PAN-OS

SolarWinds NCM

Check Point Management API

Palo Alto AS3

MDS

VSX

Palo Alto

About Company