Network Security Engineer
About the role
We are seeking an Network Security Engineer with strong expertise in Palo Alto Networks to design, secure, and maintain cloud and hybrid network infrastructure. In this role, you will be responsible for building resilient AWS VPC environments, managing hybrid cloud connectivity, and enforcing enterprise-grade network security using Palo Alto Firewalls and AWS-native security tools.
Key responsibilities
Deploy, configure, and administer Palo Alto Next-Generation Firewalls (NGFW), VM-Series in AWS, and VPN infrastructure. Manage security policies, threat prevention, traffic filtering, and Zero Trust network controls.
Design, implement, and maintain AWS VPCs, subnets, Transit Gateways, Route 53 (DNS), PrivateLink, and Load Balancers (ALB/NLB/ELB).
Establish and manage secure connectivity between on-premises data centers and AWS using AWS Direct Connect, Site-to-Site VPN, and Transit Gateway routing.
Automate network deployments and firewall configurations using Terraform, AWS CloudFormation, or Ansible.
Lead incident resolution for network and firewall issues. Monitor network traffic and security events using AWS CloudWatch, VPC Flow Logs, Palo Alto Panorama, and CloudTrail.
Work closely with Cybersecurity, Cloud Architecture, and DevOps teams to ensure network topologies comply with internal security guidelines and regulatory standards.
About you
Bachelor's degree in Computer Science, Information Technology, Electrical Engineering, or a related field.
2+ years of experience in network engineering with a strong focus on AWS Cloud and Palo Alto Firewalls.
Hands-on experience configuring and managing Palo Alto Next-Generation Firewalls (NGFW), security policies, NAT rules, and IPS/Threat Prevention features.
Strong proficiency in AWS networking constructs (VPC, Transit Gateway, Direct Connect, PrivateLink, Route 53, WAF).
Deep understanding of core networking protocols: TCP/IP, BGP routing, DNS, DHCP, IPsec VPNs, and Load Balancing.
Practical experience writing IaC scripts using Terraform, CloudFormation, or Ansible.
Preferred: Palo Alto: PCNSA (Palo Alto Networks Certified Network Security Administrator) or PCNSE (Palo Alto Networks Certified Network Security Engineer).
Preferred: AWS: AWS Certified Advanced Networking – Specialty or AWS Certified Solutions Architect.
Preferred: Experience managing Palo Alto Panorama for centralized firewall management.
Preferred: Experience working in government, banking, or compliance-heavy environments.
Important Note:
Please share your resume in word format with richa@helius-tech.com
If this requirement is not a match for you, please refer to your friends.
Interested professionals can reach out to me for Confidential Discussion @ +65- 6950 5535.
