About this role
Firewall Administration & Architecture
- Deployment & Config: Install, configure, and maintain Palo Alto (PA-Series) and Fortinet (FortiGate) firewalls.
- Policy Management: Design and audit firewall rule bases, security profiles, and NAT policies.
- Centralised Management: Manage large-scale environments using Palo Alto Panorama and Fortinet FortiManager / FortiAnalyzer .
- VPN Management: Establish and secure Site-to-Site IPsec VPNs and Remote Access VPNs (GlobalProtect, FortiClient).
2. Network Security Operations
- Threat Mitigation: Configure advanced security features including IPS/IDS, URL filtering, Anti-
- Upgrade & Patching: Perform routine firmware upgrades, hotfixes, and vulnerability patching.
- Monitoring: Analyze security logs to detect anomalies, unauthorized access, or potential network breaches.
- High Availability: Maintain redundant firewall clusters (HA Active/Passive and Active/Active topologies).
Traffic Management & Core Network Services (DDI)
- Application Delivery: Configure F5 BIG-IP LTM (Local Traffic Manager), including VIPs, Pools, Monitors, SSL offloading, and advanced iRules .
- IPAM & DDI: Manage Infoblox Grid Manager to run high-availability DNS, DHCP, and IP Address Management (IPAM) .
- Network Automation: Maintain network health by automating IP allocations and DNS entries.
Edge Architecture & WAN Edge
- SD-WAN Fabric: Design, deploy, and optimize SD-WAN solutions (Fortinet Secure SD-WAN or Palo Alto Prisma SD-WAN) to replace traditional MPLS.
- Traffic Steering: Define application-aware routing paths to guarantee performance for critical SaaS and cloud workloads.
- Hybrid Connectivity: Maintain secure Site-to-Site IPsec VPN overlays across the SD-WAN fabric.
Troubleshooting & Support
- Incident Response: Act as a Tier 2/3 escalation point for complex network security issues and outages.
- Packet Analysis: Use tools like Wireshark and built-in CLI packet captures to diagnose complex routing or traffic drops.
- Performance Tuning: Monitor firewall CPU, memory, and session counts to optimize throughput
Troubleshooting & Architecture
- Tier 3 Escalation: Diagnose complex outages involving multi-vendor paths (e.g., F5 VIP to Firewall to SD-WAN edge).
- Packet Diagnostics: Master packet capture tools (Wireshark, tcpdump) to resolve deep-layer routing, translation, or load-balancing issues.
Firewall Administration & Architecture
- Deployment & Config: Install, configure, and maintain Palo Alto (PA-Series) and Fortinet (FortiGate) firewalls.
- Policy Management: Design and audit firewall rule bases, security profiles, and NAT policies.
- Centralised Management: Manage large-scale environments using Palo Alto Panorama and Fortinet FortiManager / FortiAnalyzer .
- VPN Management: Establish and secure Site-to-Site IPsec VPNs and Remote Access VPNs (GlobalProtect, FortiClient).
2. Network Security Operations
- Threat Mitigation: Configure advanced security features including IPS/IDS, URL filtering, Anti-
- Upgrade & Patching: Perform routine firmware upgrades, hotfixes, and vulnerability patching.
- Monitoring: Analyze security logs to detect anomalies, unauthorized access, or potential network breaches.
- High Availability: Maintain redundant firewall clusters (HA Active/Passive and Active/Active topologies).
Traffic Management & Core Network Services (DDI)
- Application Delivery: Configure F5 BIG-IP LTM (Local Traffic Manager), including VIPs, Pools, Monitors, SSL offloading, and advanced iRules .
- IPAM & DDI: Manage Infoblox Grid Manager to run high-availability DNS, DHCP, and IP Address Management (IPAM) .
- Network Automation: Maintain network health by automating IP allocations and DNS entries.
Edge Architecture & WAN Edge
- SD-WAN Fabric: Design, deploy, and optimize SD-WAN solutions (Fortinet Secure SD-WAN or Palo Alto Prisma SD-WAN) to replace traditional MPLS.
- Traffic Steering: Define application-aware routing paths to guarantee performance for critical SaaS and cloud workloads.
- Hybrid Connectivity: Maintain secure Site-to-Site IPsec VPN overlays across the SD-WAN fabric.
Troubleshooting & Support
- Incident Response: Act as a Tier 2/3 escalation point for complex network security issues and outages.
- Packet Analysis: Use tools like Wireshark and built-in CLI packet captures to diagnose complex routing or traffic drops.
- Performance Tuning: Monitor firewall CPU, memory, and session counts to optimize throughput
Troubleshooting & Architecture
- Tier 3 Escalation: Diagnose complex outages involving multi-vendor paths (e.g., F5 VIP to Firewall to SD-WAN edge).
- Packet Diagnostics: Master packet capture tools (Wireshark, tcpdump) to resolve deep-layer routing, translation, or load-balancing issues.