Senior Network Security Engineer
Senior Network Security Engineer
Department: Infrastructure Security
Experience: 8+years
| Position Title | Senior Network Security Engineer / Consultant — Check Point Firewall |
| Function | Network Security Delivery / Professional Services |
| Reports To | Project Manager / Practice Lead — Network Security |
| Location | Work location : Dubai, UAE – Travel to other region as project required. |
| Engagement Type | Full Time |
| Experience Required | 8+ years in network security, with a minimum of 5 years hands-on Check Point delivery |
| Positions Open | 2 |
1. Role Overview
We are seeking an accomplished Check Point firewall specialist to join the delivery team for a large-scale, multi-vendor security transformation programme. The engagement involves migrating an existing mixed firewall estatecomprising Juniper, Huawei and Cisco platforms onto a new Check Point Quantum Force high-end appliance estate across different locations, deployed as high-availability clusters and managed through a Multi-Domain Smart-1 architecture.
The successful candidate will take a lead technical role across the full delivery lifecycle: source estate discovery and policy audit, target architecture and low-level design, policy conversion and rationalization, staging and commissioning, migration cutover under strict change control, and post-implementation support. This is a hands-on senior position requiring both design authority and the operational discipline to execute cutovers on a live carrier network where the tolerance for service impact is effectively zero.
2. Key Responsibilities
Design & Architecture
- Produce high-level and low-level designs for Check Point gateway clusters, covering ClusterXL high-availability design, interface and bonding architecture, VLAN and addressing plans, and routing integration with the carrier core.
- Design the multi-domain management and logging architecture, including domain structure, global policy layers, administrator models, log retention and event correlation.
- Define the target security policy architecture ordered and inline policy layers, object standards, NAT design and VPN topologies and establish the standards that operational teams will work to thereafter.
- Design Threat Prevention and sandboxing profiles, including IPS, Anti-Virus and Anti-Bot baselines and a staged detect-to-prevent rollout strategy appropriate to high-throughput carrier traffic.
- Develop migration architecture: parallel installation approach, traffic-swing methodology, soak criteria and technically credible rollback design.
Implementation & Migration
- Lead policy conversion from Juniper, Huawei and Cisco source platforms using Check Point SmartMove and scripted or manual conversion methodologies, followed by manual review, rule rationalization and object normalization.
- Build and commission high-end Check Point appliances: OS installation and hardening, cluster formation, interface and bonding configuration, SIC establishment and onboarding to the correct management domain.
- Configure and validate high-speed interfaces in line cards, including optics validation and link aggregation at scale.
- Build the Smart-1 management and logging infrastructure, including Multi-Domain Server deployment, SmartEvent configuration and SIEM log forwarding.
- Author detailed cutover method statements and execute migrations within approved change windows, including on-site presence, live traffic verification and rollback execution where triggers are met.
Testing, Support & Handover
- Develop and execute acceptance test plans covering high-availability failover, routing convergence, policy parity against the legacy estate, throughput validation and Threat Prevention behaviour.
- Provide post-migration hypercare support: incident diagnosis, policy and Threat Prevention tuning, performance optimisation and vendor TAC escalation management.
- Perform advanced troubleshooting using packet-level and kernel-level diagnostics, cluster state analysis and acceleration path investigation.
- Produce as-built documentation and operational runbooks, and deliver structured knowledge transfer to customer network operations and security operations teams.
Programme & Stakeholder Engagement
- Represent the delivery organisation in customer design reviews, technical workshops, change advisory boards and acceptance sign-off sessions.
- Work within a phased, wave-based rollout model, meeting entry and exit gate criteria per wave and maintaining delivery quality across parallel site activity.
- Mentor junior engineers and contribute to the internal Check Point practice through reusable design patterns, conversion tooling and lessons learned.
3. Essential Skills & Experience
- Minimum 5 years of hands-on experience designing, implementing and supporting Check Point security gateways, including at least two enterprise or carrier-scale deployments or migrations.
- Deep expertise across the Check Point portfolio: Gaia OS, SmartConsole, Security Management and Multi-Domain Management (MDS/MLM), ClusterXL, Management API, SecureXL and CoreXL acceleration.
- Demonstrable experience with high-end Check Point appliances and high-throughput deploymentsmulti-hundred-gigabit or terabit-class environments, high-density line cards and performance tuning under sustained load.
- Proven policy migration experience from third-party firewall vendors like Cisco, Juniper or ScreenOS, Huawei, Fortinet including practical use of SmartMove and post-conversion validation.
- Strong command of Threat Prevention blades and sandboxing: IPS, Anti-Virus, Anti-Bot, Threat Emulation and Threat Extraction, including profile design and false-positive management.
- Solid networking foundation: TCP/IP, routing protocols (OSPF, BGP), VLANs and trunking, link aggregation, NAT, IPSec VPN and high-availability design principles.
- Advanced troubleshooting capability using fw monitor, tcpdump, kernel debug, cpview, cphaprob and related diagnostic tooling.
- Experience executing changes on production networks under formal change management, including method statement authorship, risk assessment and rollback planning.
- Strong documentation and communication skills, with the ability to present and defend technical designs to senior customer stakeholders.
4. Certification Requirements
A valid, current certification is mandatory for this role. Candidates without an active certification at the required level will not be considered.
Mandatory
- Check Point Certified Security Expert (CCSE) must be valid and current on a supported software release.
Highly Desirable
- Check Point Certified Security Master (CCSM) or CCSM Elite.
- Check Point Certified Multi-Domain Security Management Specialist.
- Check Point Certified Troubleshooting Expert (CCTE) or Automation Specialist (CCAS).
- Complementary networking or security certification: CCNP/CCIE Security, JNCIP/JNCIE-SEC, HCIP/HCIE-Security
5. Preferred — Telecommunications Domain Experience
Candidates with service provider or telecommunications experience will be given clear preference. The following are considered significant advantages:
- Prior delivery experience with a telecom operator, mobile network operator or internet service provider, particularly in a mobile packet core, MPBN or carrier backbone environment.
- Understanding of telecom network architecture and the security demarcation between the transport layer and the security layer — including Gi/SGi firewall, roaming and peering security concepts.
- Familiarity with modern carrier transport technologies: EVPN, Segment Routing (SR-MPLS) and SRv6, and how firewall clusters attach to and interoperate with such fabrics.
- Experience operating within carrier-grade service level commitments, restricted maintenance windows and formal telecom change governance.
- Exposure to carrier-scale traffic profiles and the performance engineering considerations that accompany them, including asymmetric routing and high session-rate environments.
- Experience with regulatory, lawful intercept or telecom-specific compliance requirements as they affect security infrastructure design.
6. Personal Attributes
- Composure and sound judgement when executing high-risk changes on live production networks during constrained maintenance windows.
- Methodical and evidence-driven approach to diagnosis, with the discipline to document decisions and follow agreed process.
- Ability to work independently on customer sites while maintaining alignment with programme governance and reporting.
- Willingness to travel to customer locations as required and to work extended or night-time maintenance windows during cutover phases.
- Collaborative approach with customer teams, with the credibility to advise and, where necessary, respectfully challenge on technical risk.