Nebius
Nebius

Network Security Engineer

engineeringfull-timeRemote - Europe
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
ai
Apply for this position
✦ AutoApply Sick of applying? We apply to roles like this for you, up to 20 a month.
Learn more

About the role

Role Summary

We are looking for a

Network Security Engineer

to join our Network team. This role combines deep expertise in network engineering and cybersecurity. You will help

implement

end-to-end network security architectures for enterprise and data center backbone/fabric environments,

work with network architects and the management team to guide these designs through review and approval with the Security team, and operate and maintain the implemented solutions day-to-day.

You are expected to be hands-on with leading firewall platforms (Palo Alto, Check Point, etc.), understand complex routing and switching designs,

and be comfortable implementing and troubleshooting these networks.
Responsibilities
  • Implement and maintain Zero Trust-aligned security architectures for both enterprise and data center networks.
  • Configure Layer 3/4 & Multi-VRF Segmentation, Security Policies, Secure Remote access.
  • Implement and test large hyper scale DC Security solutions : IPS/NDR solutions , AntiDDOS solutions.
  • Integrate NGFW platforms with modern identity providers such as Microsoft Entra ID and Okta, maintain NGFW management, automation, and logging capabilities required by the Security team.
  • Implement and maintain Security Capabilities, including Layer 7 application inspection, IPS, user identification, ZTNA, and SASE integrations.
  • Integrate and operate monitoring tools such as Zabbix, Grafana, and Akvorado.
  • Regularly perform security hardening, vulnerability management, and patching and upgrades on network and infrastructure devices, and verify the effectiveness of these procedures.
Required Qualifications
  • Experience in networking and security protocols (TCP/IP, HTTP(S), DNS, TLS, IPsec, Routing protocols)
  • Experience and Knowledge of Backbone & Datacenter technologies (EVPN, L3VPN MPLS, MPBGP, L2VPN..)
  • Hands-on experience with next-generation firewalls (Palo Alto Networks, Check Point, or similar).
  • Experience with automation using Python, Go, or equivalent.
  • Proficiency in Unix/Linux and experience with major network vendors (Cisco, Juniper, Aruba, etc.).
  • Experience configuring and troubleshooting NGFW capabilities and integrations, including IPS, User-ID, Microsoft Entra ID, and ZTNA.
Preferred Qualifications
  • Good knowledge of IPv6.
  • Experience with automation tools (Ansible, Terraform, NetBox, SaltStack, etc.).
  • Experience with large-scale, highly available distributed systems.
  • Knowledge of Zero Trust principles and micro-segmentation approaches.
  • Relevant certifications (CCNP/CCIE, PCNSE, NSE 4/7) and professional working proficiency in English.
  • Familiarity with commercial or open-source monitoring, logging, and security analytics solutions such as Splunk; EDR/XDR platforms such as CrowdStrike; and centralized NGFW management platforms such as Panorama, Strata Cloud Manager, and FortiManager.
  • Bonus: Exposure to DevSecOps practices (SAST/DAST), CSPM/CWPP platforms such as Wiz, EDR, offensive security (OSCP/CPTS, red teaming), or security frameworks, standards, and regulations such as ISO/IEC 27001, NIST CSF, and GDPR.
✦ Sick of applying to 40 jobs a month?
I rewrite your resume for ATS by hand first. Once you sign off on it, AutoApply applies to up to 20 roles like this a month, cover letter in your own voice each time. From $14.99/mo, cancel anytime.
Get AutoApply
Apply now
Network Security Engineer at Nebius — Remote