- Company Name
- SOFTNICE UK LIMITED
- Job Title
- Network Engineer
- Job Description
-
**Job Title:** Network Security Engineer
**Role Summary:**
Senior L4 Network Security Engineer tasked with designing, deploying, and maintaining enterprise security solutions across multi‑site and data‑center environments. Responsible for configuration, upgrade, migration, and decommission of Cisco ISE, ASA/FTD, Check Point, and F5 APM platforms, ensuring security compliance and operational excellence.
**Expectations:**
Deliver robust, scalable security architectures, lead implementation projects, and act as the primary escalation point for complex network‑security incidents. Mentor junior staff, document processes, and enforce industry security standards.
**Key Responsibilities:**
1. **Security Infrastructure Operations** – Configure and troubleshoot Cisco ISE (TACACS+, RADIUS, Dot1X, CoA, profiling), ASA/FTD firewalls (ACLs, NAT, VPN, clustering, upgrades), Check Point R80.x (policy, clustering, VPN, logging), F5 APM (remote VPN, SSO, auth policies), and DC‑level routing/security (segmentation, VRF).
2. **Implementation & Decommissioning** – Install, configure, and deploy security devices; lead hardware refresh, firewall replacement, and migration projects; perform clean decommission including config removal, rack removal, and documentation.
3. **Architecture & Project Support** – Design secure network topologies, draft HLD/LLD documents, network diagrams, migration plans, SOPs, and coordinate change activities with cross‑functional teams.
4. **Security Operations & Troubleshooting** – Act as L4 SME for escalated incidents; root‑cause analysis and remediation of authentication failures, VPN issues, firewall packet drops, routing conflicts; monitor logs, alerts, and system health across platforms.
5. **Governance & Compliance** – Ensure adherence to ISO 27001, NIST, PCI‑DSS, CIS benchmarks; conduct policy optimization, audits, firmware/software updates, and provide training to L1/L2 teams.
**Required Skills:**
- **Technical**: Expert Cisco ISE; Cisco ASA/FTD (VPN, NAT, ACL, clustering, FMC); Check Point R80.x (SmartConsole, IPS, HA); F5 APM (access policies, SAML/OAuth); Nexus switching/routing (VLAN, VPC, OSPF/BGP basics); packet capture (Wireshark, tcpdump); basic cloud networking (AWS/Azure).
- **Automation**: Python, Ansible (preferred).
- **Soft**: Strong written/verbal communication, analytical problem‑solving, independent change ownership, global collaboration, mentoring.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Technology, or related field.
- Professional certifications: CCNP/CCNP Security, CISM or CISSP (preferred), Check Point Certified Architect (CCSA) or equivalent, F5 Certified Technical Associate (F5-CTA) or higher.
- Minimum 6–10 years of enterprise network‑security experience in high‑availability, distributed environments.
Guildford, United kingdom
On site
Mid level
16-02-2026