This page was automatically translated and may contain errors. View in English.
malomatia

Perimeter Edge Security Engineer

malomatia

Qatar · 全职

抢先申请

经验
5年以上
薪水
职位空缺
1
发布
11 小时前
工作模式
在办公室
学历
学士学位
恢复
需要申请

你的工作地点

职位描述

Job Overview

This role involves taking full ownership of the design, management, and lifecycle of the organization's network perimeter and cloud edge security infrastructure. The environment includes Palo Alto VM-Series firewalls, FortiGate HA clusters distributed across on-premises and multi-cloud setups, alongside Cloudflare services such as CDN, DDoS protection, edge WAF, and DNS.

Key Responsibilities

  • Architect and maintain zone-based security designs, establish inter-zone policies, and implement DMZ segmentation utilizing Palo Alto and FortiGate platforms.
  • Configure and oversee policies related to App-ID, User-ID, Content-ID, SSL/TLS decryption, NAT actions (including DNAT, SNAT, U-turn), and unified threat management functions such as IPS, antivirus, web filtering, and application control.
  • Construct and manage Site-to-Site IPSec VPNs using IKEv2 with dynamic BGP routing, route- or policy-based VPNs, and apply SD-WAN for traffic steering where necessary.
  • Operate centralized policy management tools like Panorama and Strata Cloud Manager for Palo Alto, and FortiManager with FortiAnalyzer for Fortinet, to enforce policies, aggregate logs, and generate reports.
  • Design and deploy high-availability clusters configured as Active-Passive or Active-Active; conduct quarterly failover tests and create root cause analysis documentation.
  • Lead the deployment and migration of network virtual appliances (NVAs), including migrations between cloud providers such as Azure to OCI, manage firmware and patch lifecycle, execute hotfixes, and implement HA-aware patching with rollback plans.
  • Integrate firewalls and NVAs with load balancers at Layer 4 and Layer 7 to ensure comprehensive traffic inspection.
  • Administer Cloudflare services including CDN with cache rules and Workers/Pages, manage network and application layer DDoS protection, edge WAF with managed and custom rule sets, rate limiting, and bot management.
  • Handle Cloudflare load balancing, public DNS, URL management, and continuously analyze and optimize traffic at the network edge.
  • Own full vulnerability remediation cycles including patching schedules and upgrade planning for all firewall, NVA, and edge security assets.
  • Monitor Next-Generation Firewall (NGFW) and Unified Threat Management (UTM) threat logs alongside Cloudflare traffic and attack analytics; manage signature updates and lead incident triage and response activities related to perimeter and edge security events.

Required Qualifications

  • Bachelor's degree in Computer Science, Information Security, or a related discipline.
  • More than 5 years of hands-on experience managing enterprise-grade NGFW platforms like Palo Alto and/or Fortinet within production environments.
  • Proven expertise in multi-cloud network virtual appliance deployments, including platforms such as Azure, Google Cloud Platform, or Oracle Cloud Infrastructure, plus experience with cloud edge and CDN security solutions like Cloudflare or equivalents.
  • Professional certifications such as PCNSE (Palo Alto), NSE 4/NSE 7 (Fortinet), or Cloudflare Certified Administrator are highly desirable.
  • Strong knowledge of advanced routing protocols like BGP, VPN technologies, DNS architecture, DDoS mitigation tactics, and network segmentation principles.
  • Excellent skills in incident response, thorough documentation, and coordination across multiple teams.

Work styles they’re looking for

问题解决 注重细节 弹力 Cross-team collaboration

如果您希望收到回复,请留下您的信息——我们不会将您的信息用于其他用途。

点击浏览拖放,或 粘贴 截图

PNG、JPG、GIF、MP4、WebM、MOV 格式 · 每个文件最大 20MB · 最多 5 个文件

🤖
在线·即时人工智能帮助