Senior Network Security Engineer
DXC Technology- Posted 10 hours ago
- Be among the first 10 applicants
Job Description
Job Purpose:
The Senior Network Security Engineer is a senior technical expert responsible for designing, implementing, and troubleshooting complex network security solutions across the organization. This role requires in-depth knowledge of enterprise security technologies, proactive threat mitigation, and seamless integration of security controls into the network infrastructure to meet the regulatory demands of a financial institution.
Key Responsibilities & Duties:
· Design & Architecture: Develop and maintain security architecture for network infrastructure, including firewalls, VPNs, proxies, and intrusion prevention systems. Ensure alignment with security frameworks such as SAMA, ISO 27001, and NIST.
· Advanced Troubleshooting: Lead in-depth analysis and resolution of complex security-related incidents and performance issues. Coordinate with cross-functional teams during security investigations and post-incident reviews.
· Security Operations & Monitoring: Implement and maintain security monitoring tools (e.g., SIEM, IDS/IPS). Analyze security logs and traffic patterns to identify and mitigate potential threats.
· Firewall & Perimeter Management: Manage and optimize enterprise firewalls (e.g., Fortinet, Palo Alto, Cisco ASA). Oversee access control policies, NAT, site-to-site VPNs, and internet gateways.
· Compliance & Risk Management: Enforce security policies and ensure audit readiness for internal and external compliance. Assist in risk assessments, vulnerability management, and remediation planning.
· Project Support & Integration: Participate in the design and deployment of new applications and services, ensuring secure-by-design principles are followed. Evaluate emerging technologies and recommend security enhancements.
· Documentation & Standards: Maintain detailed documentation of configurations, policies, and procedures. Contribute to the continuous improvement of network security standards and practices.
Skills & Qualifications:
· Typically, 6+ years of relevant work experience in industry, with a minimum of 2+ years in a similar role
· Deep understanding of enterprise-grade firewalls, VPNs, NAC, and threat detection tools.
· Strong troubleshooting skills across Layer 2–7, with a focus on perimeter and endpoint protection.
· Familiarity with Zero Trust architecture, segmentation, and defense-in-depth strategies.
· Hands-on experience with Fortinet, Palo Alto, Cisco ASA/FTD, and relevant security tools.
· Excellent communication skills and experience working with cross-functional teams.
Education & Certifications:
· Bachelor's Degree in Computer Science, Information Security, or related field.
· Preferred certifications:
· - Fortinet NSE 4–7
· - Palo Alto PCNSE
· - Cisco CCNP Security / CCIE Security
· - CISSP or CISM (a plus)
Working Conditions:
· May require occasional on-site support during major incidents or projects.
· Flexibility to work off-hours for emergency changes or incidents.
· Regular collaboration with infrastructure, SOC, and compliance teams.
Platform Proficiency (Required)
· Palo Alto NGFW — primary enterprise firewall platform (design, policy management, threat prevention, GlobalProtect VPN)
· Cisco ASA/FTD — secondary firewall platform
· Cisco ISE — Network Access Control (posture assessment, guest access, BYOD workflows, subject to Cybersecurity team approvals)
· SolarWinds NPM/NTA — network security monitoring and traffic analysis
· Dynatrace — full-stack observability for security event correlation
· ServiceNow — change control, incident management for all security changes (CAB process, maintenance windows, evidence attachment, rollback plans)
Compliance & Regulatory (Maaden-Specific)
· NCA (National Cybersecurity Authority) — Saudi national cybersecurity framework (replaces SAMA, which applies to banking sector only)
· NDMO (National Data Management Office) — Saudi data governance mandates
· ISO 27001, NIST, CIS hardening baselines
· Support for NCA/CIS-aligned server and network device hardening with drift correction
Operational Context
· Coordinate with SOC team for remediation/evidence (SOC operations themselves are out of DXC scope — owned by Maaden Cybersecurity)
· Participate in Unified Endpoint Security (UES) consolidation initiative (current state: multiple EDR/AV agents causing policy conflicts)
· Support Zero Trust architecture implementation aligned with network segmentation strategy across all 23+ sites
Preferred Certifications (Reordered for Maaden)
· Palo Alto PCNSE (primary)
· Cisco CCNP Security / CCIE Security
· CISSP or CISM (a plus)
· Fortinet NSE certifications (desirable but not primary)
Language
Bilingual Arabic and English proficiency required

