Nebius
Network Security Engineer
engineeringfull-timeRemote - Europe
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
ai
✦ AutoApply Sick of applying? We apply to roles like this for you, up to 20 a month.
Learn more
About the role
Role Summary
Responsibilities
We are looking for a
Network Security Engineerto join our Network team. This role combines deep expertise in network engineering and cybersecurity. You will help
implementend-to-end network security architectures for enterprise and data center backbone/fabric environments,
work with network architects and the management team to guide these designs through review and approval with the Security team, and operate and maintain the implemented solutions day-to-day.You are expected to be hands-on with leading firewall platforms (Palo Alto, Check Point, etc.), understand complex routing and switching designs,
and be comfortable implementing and troubleshooting these networks.Responsibilities
- Implement and maintain Zero Trust-aligned security architectures for both enterprise and data center networks.
- Configure Layer 3/4 & Multi-VRF Segmentation, Security Policies, Secure Remote access.
- Implement and test large hyper scale DC Security solutions : IPS/NDR solutions , AntiDDOS solutions.
- Integrate NGFW platforms with modern identity providers such as Microsoft Entra ID and Okta, maintain NGFW management, automation, and logging capabilities required by the Security team.
- Implement and maintain Security Capabilities, including Layer 7 application inspection, IPS, user identification, ZTNA, and SASE integrations.
- Integrate and operate monitoring tools such as Zabbix, Grafana, and Akvorado.
- Regularly perform security hardening, vulnerability management, and patching and upgrades on network and infrastructure devices, and verify the effectiveness of these procedures.
- Experience in networking and security protocols (TCP/IP, HTTP(S), DNS, TLS, IPsec, Routing protocols)
- Experience and Knowledge of Backbone & Datacenter technologies (EVPN, L3VPN MPLS, MPBGP, L2VPN..)
- Hands-on experience with next-generation firewalls (Palo Alto Networks, Check Point, or similar).
- Experience with automation using Python, Go, or equivalent.
- Proficiency in Unix/Linux and experience with major network vendors (Cisco, Juniper, Aruba, etc.).
- Experience configuring and troubleshooting NGFW capabilities and integrations, including IPS, User-ID, Microsoft Entra ID, and ZTNA.
- Good knowledge of IPv6.
- Experience with automation tools (Ansible, Terraform, NetBox, SaltStack, etc.).
- Experience with large-scale, highly available distributed systems.
- Knowledge of Zero Trust principles and micro-segmentation approaches.
- Relevant certifications (CCNP/CCIE, PCNSE, NSE 4/7) and professional working proficiency in English.
- Familiarity with commercial or open-source monitoring, logging, and security analytics solutions such as Splunk; EDR/XDR platforms such as CrowdStrike; and centralized NGFW management platforms such as Panorama, Strata Cloud Manager, and FortiManager.
- Bonus: Exposure to DevSecOps practices (SAST/DAST), CSPM/CWPP platforms such as Wiz, EDR, offensive security (OSCP/CPTS, red teaming), or security frameworks, standards, and regulations such as ISO/IEC 27001, NIST CSF, and GDPR.
✦ Sick of applying to 40 jobs a month?
I rewrite your resume for ATS by hand first. Once you sign off on it, AutoApply applies to up to 20 roles like this a month, cover letter in your own voice each time. From $14.99/mo, cancel anytime.
Get AutoApply