Senior Network Security Engineer
Specialist Check Point
Job Description Summary
As a Senior Network Security Engineer, you will be a key technical owner of the organization’s Check Point firewall infrastructure, responsible for the design, operation, optimization, and continuous improvement of enterprise network security services.
This position has a strong and mandatory focus on Check Point firewall technologies. The successful candidate must have extensive hands-on experience managing Check Point environments, including firewall policy administration, rule optimization, VPNs, troubleshooting, upgrades, monitoring, and high-availability configurations.
As part of the Global Network Operations team, you will serve as the regional technical lead for Network Security Operations across the North America / US region, ensuring the security, availability, performance, and scalability of critical network security services.
The role combines deep technical expertise in Check Point Security Gateways and management platforms with strong enterprise networking knowledge. You will work closely with Global Security Operations, infrastructure teams, application owners, cybersecurity, and external service providers to maintain a secure and resilient global network environment.
You will be expected to demonstrate a strong ownership mindset, taking responsibility for both proactive improvements and reactive troubleshooting of critical network security services.
Key Responsibilities
Check Point Firewall Ownership
■ Own the day-to-day operation and technical lifecycle of the Check Point firewall environment, ensuring security, stability, performance, and availability.
■ Design, implement, maintain, and optimize Check Point firewall policies, security rules, NAT, objects, services, and access controls according to global security standards.
■ Perform advanced Check Point troubleshooting, including connectivity issues, policy behavior, routing interactions, VPN problems, performance degradation, and complex production incidents.
■ Manage Check Point VPN technologies, including site-to-site VPNs and remote access solutions, ensuring secure and reliable connectivity.
■ Support and maintain Check Point High Availability / ClusterXL environments, including failover, synchronization, and operational troubleshooting.
■ Execute and coordinate Check Point upgrades, migrations, patches, and lifecycle activities, minimizing operational risk and business disruption.
■ Monitor Check Point infrastructure and proactively identify security, capacity, performance, and availability risks.
■ Continuously review and optimize firewall rule bases, identifying unnecessary, redundant, outdated, or overly permissive rules.
■ Serve as the primary technical escalation point for complex Check Point firewall incidents and security-related network issues.
Network Security Operations
■ Act as the regional Network Security lead for the North America / US region, coordinating operational activities and ensuring appropriate business-hours coverage.
■ Design, implement, and operate secure and scalable network security architectures integrated with the organization's global network infrastructure.
■ Manage firewall segmentation, VPN connectivity, routing dependencies, and security controls in alignment with enterprise cybersecurity standards.
■ Ensure the reliable operation and availability of network security services supporting critical business processes.
■ Collaborate closely with Global Security Operations (SOC) on security incidents, threat mitigation, investigations, and implementation of security requirements.
■ Provide network security expertise for major IT and business projects, including architecture reviews, firewall design, migrations, and infrastructure changes.
■ Act as a senior technical escalation point for complex network, firewall, VPN, and connectivity incidents.
■ Develop and maintain high-quality technical documentation, firewall standards, operating procedures, and troubleshooting guides.
■ Identify opportunities to improve operational efficiency through automation, standardization, and continuous improvement.
■ Participate in an on-call rotation supporting critical network security services.
Required Qualifications
Mandatory Check Point Experience
■ Extensive hands-on experience with Check Point firewalls in enterprise environments – mandatory.
■ Strong practical knowledge of Check Point Security Gateways and Security Management architecture.
■ Proven experience with Check Point firewall policy administration, rule-base management, NAT, objects, services, and access control.
■ Advanced troubleshooting experience with Check Point firewalls in complex production environments.
■ Hands-on experience with Check Point VPN technologies, including site-to-site VPNs.
■ Experience with Check Point High Availability / ClusterXL environments.
■ Proven experience performing Check Point upgrades, migrations, patches, and lifecycle management.
■ Ability to analyze and troubleshoot firewall-related issues involving routing, TCP/IP, NAT, VPNs, DNS, and network segmentation.
■ Check Point certification such as CCSE is highly desirable and will be considered a strong advantage.
Enterprise Network & Security Experience
■ Extensive experience in Network and Network Security Operations within complex enterprise environments.
■ Strong networking knowledge, including TCP/IP, routing, switching, WAN/LAN, VLANs, VPNs, DNS, and network segmentation.
■ Solid understanding of enterprise security principles, including defense-in-depth, least privilege, network segmentation, and Zero Trust concepts.
■ Experience operating network security services tightly integrated with enterprise infrastructure.
■ Understanding of network security monitoring, incident response, and security operations processes.
■ Experience with network automation concepts and tools is a plus.
■ Experience working within globally distributed teams and supporting critical infrastructure across multiple time zones.
■ Strong analytical, troubleshooting, and problem-solving skills with a high degree of technical ownership.
■ Ability to work effectively with cybersecurity teams, network teams, infrastructure teams, application owners, and external service providers.
■ Fluent English communication skills, both written and spoken.
■ Relevant certifications are a plus, including Check Point CCSE/CCSA, Palo Alto PCNSE, Fortinet certifications, Cisco CCNA/CCNP, or equivalent.
■ Bachelor’s degree in Computer Science, Information Technology, Telecommunications, Cybersecurity, or a related field, or equivalent practical experience.
Sueldo: $80,000.00 - $100,000.00 la hora
Horas previstas: 40.0 por semana
Lugar de trabajo: Empleo presencial