Security Engineer and Network Engineer
You will design and implement a highly secure enterprise network using hardware and software. The role covers scalable VPN deployment, protocol evaluation, firewall and IDS/IPS integration, authentication and encryption, access control, risk assessment, compliance, monitoring, performance optimization, patching, incident response, documentation, and IT staff training.
Responsibilities
- Design scalable, high-performance VPN architectures for hybrid cloud and on-premises environments
- Evaluate and select VPN protocols and encryption methodologies
- Integrate VPNs with firewalls, routers, and IDS/IPS
- Implement multi-factor authentication and certificate-based access
- Apply advanced encryption standards and key exchange protocols
- Develop and enforce access control and user permission policies
- Conduct network analysis to minimize latency and maximize uptime
- Implement load balancing and failover mechanisms for high availability
- Optimize bandwidth utilization and troubleshoot connectivity issues
- Perform risk assessments and implement vulnerability mitigations
- Ensure VPN and network compliance with applicable regulations
- Deploy monitoring tools to detect anomalies and unauthorized access
- Maintain firmware, software, and security patches for network components
- Develop incident response plans for VPN and network security events
- Document architectures, configurations, and standard operating procedures
- Provide training and guidance to IT staff on VPN and network best practices
Requirements
- 5+ years of experience in network engineering and cybersecurity
- Deep understanding of routing, switching, DNS, and BGP
- Expertise with OpenVPN, IPsec, SSL/TLS, and WireGuard
- Proficiency with firewalls, IDS/IPS, and SIEM solutions
- Hands-on experience with AWS, Azure, and Google Cloud in hybrid environments
- Experience implementing MFA and certificate-based authentication
- Experience with AES-256 and key exchange protocols including Diffie-Hellman and IKEv2
- Familiarity with GDPR, HIPAA, and ISO 27001
- Familiarity with Python, Bash, automation, and CI/CD deployment methods
- Preferred certifications include CISSP, CCNP Security, or CEH
- Preferred knowledge of zero-trust architectures and Software-Defined Perimeter frameworks