Network Security Engineer / Senior Network Security Engineer

Crypto.comSan Francisco, CaliforniaOn-siteFull-timeSenior, 5–8 yearsListed 7 hours ago

Apply now

About this role

Responsibilities:

- Handle Incident Escalation: Serve as the primary Level 3 escalation point for resolving complex network infrastructure, routing, and security configuration issues across both on-premise Data Centers and AWS environments.

- Execute Live Cloud Cutovers: Drive and execute live Data Center to AWS cloud migration cutovers under tight execution windows, ensuring seamless transitions across AWS DirectConnect, hybrid routing, security perimeters, load balancing, and DNS services.

- Maintain Multi-Vendor Security & Perimeter Solutions: Responsible for the overall design, configuration, and optimization of FortiGate Firewalls (On-Prem & AWS), Cisco ASA Firewalls, and Akamai WAF / Anti-DDoS solutions protecting core endpoints.

- Manage Core Network & Infrastructure Services: Identify and resolve network issues, bottlenecks, and vulnerabilities across Arista core/access switches, Cisco routers, F5 Load Balancers (LTM/GTM), and Infoblox (DNS/DHCP).

- Develop & Maintain Architecture Documentation: Develop and maintain comprehensive documentation on network topology, hybrid cloud designs, system security configurations, and operational SOPs.

- Bridge Infrastructure and DevOps (IaC): Bridge the gap between development and operations by embracing "Infrastructure as Code" (IaC) in close collaboration with DevOps teams to automate network deployments and security workflows.

- Integrate AI & Network Task Automation: Research and leverage automation/AI tools (e.g., Tines, N8N, Dify) for Security Orchestration or network task automation to improve operational efficiency.

- Provide Support During Non-Office Hours: Provide non-office hour escalation support whenever needed during major live cutovers or critical network emergencies.

Requirements:

- Education: Diploma holder or above in Computer Science, Information Systems, or related technical disciplines.

- Industry Certifications: CCNP or higher certification (CCIE, AWS Certified Advanced Networking – Specialty, and/or CISSP highly valued).

- Cloud Migration Experience: Proven track record of executing complex, live Data Center to AWS migration cutovers under strict timeframes with minimal operational risk.

- Core Technical Stack Proficiency: In-depth technical knowledge and hands-on experience across:
- Security & Edge: FortiGate Firewalls (On-Prem & AWS VPCs), Cisco ASA Firewalls, Akamai WAF / Anti-DDoS.

- Routing & Switching: Arista Core & Access Switches, Cisco Routers, AWS DirectConnect, AWS VPC Networking, and deep understanding of protocols (BGP, OSPF, IPsec, HSRP, QoS).

- Traffic & Core Services: F5 Load Balancers (LTM/GTM) and Infoblox (DNS/DHCP).

- Automation & Orchestration: Experience leveraging IaC and automation/AI tools (e.g., N8N, Dify, Tines) for Security Orchestration or network task automation is a strong advantage.

- Personal Attributes & Communication: Strong time management, willing to learn, able to work independently.