About this role
Key Accountabilities:
- Deploy and configure VMware Cloud Director (VCD) networking, including organisation VDC networks, edge gateways, routed and isolated networks, and integration with NSX-T backed provider gateways.
- Deploy and configure NSX Advanced Load Balancer (AVI Networks), including virtual services, pool configuration, health monitors, SSL termination, WAF policies, and integration with NSX-T and VCD environments.
- Implement Layer 2 extension across sites using NSX L2 Bridging, VMware HCX Layer 2 extension, or equivalent technologies to support workload mobility and phased migration strategies.
- Deploy and configure enterprise network security solutions, including next-generation firewalls (NGFW), intrusion prevention systems (IPS), and advanced threat protection tools, from staging through to production.
- Deploy and configure VMware NSX-T environments, including overlay networking (Geneve), Tier-0/Tier-1 gateways, distributed routing, Distributed Firewall (DFW), Gateway Firewall, and micro-segmentation policies.
- Execute end-to-end migration projects, transitioning legacy network security infrastructure to modern platforms with minimal business disruption.
- Deploy and manage Palo Alto Networks (PAN-OS, Panorama) and Fortinet (FortiGate, FortiManager, FortiAnalyzer) NGFW platforms, including rule-base migration, URL filtering, application control, SSL inspection, VPN configuration, and threat prevention profile tuning.
- Configure OCI network security controls including Security Lists, Network Firewall, Fast Connect, and OCI IAM policies in support of hybrid and private cloud environments.
- Deploy and configure F5 BIG-IP (LTM, GTM, ASM/AWAF) solutions, including virtual server configuration, iRules, WAF policy deployment, SSL offloading, and health monitoring. Execute ADC migration and cutover activities.
- Configure and deploy secure web proxy and URL filtering solutions to enforce acceptable use and data loss prevention policies.
- Carry out security assessments of existing infrastructure to support migration planning and identify remediation requirements prior to cutover.
- Ensure all implemented solutions meet relevant security compliance standards and regulatory requirements.
- Contribute to High-Level Design (HLD) and Low-Level Design (LLD) documentation in support of implementation activities; prior design experience across NSX, VCD, NGFW, or F5 environments is a valued advantage
Qualifications, Experience and Skills:
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Network Engineering, or a related discipline or equivalent experience.
- 4+ years of hands-on experience in network security implementation, deployment, and migration roles.
- Hands-on experience deploying VMware NSX-T/NSX-4 (overlay networking, DFW, Gateway Firewall, micro-segmentation), VMware Cloud Director (VCD) networking, NSX Advanced Load Balancer (AVI), and Layer 2 extension technologies (NSX L2 Bridge, HCX L2 extension) in production environments.
- Preferred certifications include VMware Certified Professional – Network Virtualisation (VCP-NV)
- VMware NSX VCIX-NV or VMware Certified Implementation Expert
- CCNP Security or equivalent Cisco security certification
- Palo Alto Networks Certified Network Security Engineer (PCNSE)
- Fortinet NSE 7 or higher
- F5 Certified Solution Expert (CSE)
- OCI Network Associate.
- Proven track record delivering complex security migrations and cutovers in live enterprise environments.
- Deep technical expertise in Fortinet and Palo Alto firewall platforms, including policy migration, VPN setup, and threat prevention configuration.
- Familiarity with OCI network security services (Security Lists, Network Firewall, Fast Connect, OCI IAM) in support of private and hybrid cloud deployments.
- Demonstrated hands-on experience deploying and integrating F5 BIG-IP (LTM, GTM, ASM/AWAF) in production environments, including virtual server build, WAF policy tuning, and SSL profile configuration.
- Experience configuring and deploying secure web proxy and URL filtering platforms.
- Solid understanding of security compliance frameworks (ISO 27001, PCI DSS, NIST, SOC 2) as they apply to implementation and delivery.
- Experience with vulnerability management tools and security monitoring platforms.
- VMware NSX-T/NSX-4 full-stack deployment: Transport Zones, Segments, Tier-0/Tier-1 gateways, BGP/static routing, Distributed Firewall (DFW), Gateway Firewall, micro-segmentation, and NSX Manager cluster configuration.
- VMware Cloud Director (VCD) networking: organisation VDC network creation, edge gateway configuration, routed/isolated/direct network types, VCD integration with NSX-T provider gateways, and multi-tenant network provisioning.
- Layer 2 extension implementation using NSX L2 Bridging and VMware HCX L2 extension, supporting workload mobility, phased migrations, and stretched network scenarios.
- Network and Security platform migration planning, runbook development, and cutover execution.
- Infrastructure as Code (IaC) for security deployment automation (Terraform, Ansible).
- Fortinet (FortiGate, FortiManager, FortiAnalyzer) and Palo Alto Networks (Panorama, PAN-OS) platform deployment, policy migration, and threat prevention tuning.
- Next-generation firewall (NGFW) rule base implementation, zone-based segmentation, and SSL inspection configuration.
- VPN implementation: IPsec, SSL/TLS, and SD-WAN overlay connectivity.
- OCI network security: Security Lists, OCI Network Firewall, Fast Connect, Load Balancer, and OCI IAM policies in support of private cloud and hybrid connectivity.
- Private cloud and hybrid network security controls deployment, with a focus on VMware-based environments.
- OCI Landing Zone security configuration and brownfield security uplift for on-premises to cloud migrations.
- F5 BIG-IP (LTM, GTM, ASM/AWAF) deployment: virtual servers, iRules, WAF policy configuration, SSL offloading, and health monitoring.
- NSX Advanced Load Balancer (AVI Networks): virtual service deployment, pool configuration, health monitors, SSL termination, and WAF policy implementation within NSX-T and VCD environments.
- IAM and PAM solution deployment and directory services integration (Active Directory, LDAP, OCI IAM policy, RBAC).
- Secure web proxy and URL filtering deployment.
- Security compliance frameworks: ISO 27001, PCI DSS, NIST CSF, SOC 2.
- Methodical and detail-oriented approach to implementation, testing, and cutover activities.
- Strong communication skills, with the ability to coordinate across technical teams and stakeholders during live migrations.
- Ability to produce clear implementation runbooks, test plans, and post-migration reports.
- Effective under pressure, with experience managing risks and issues during time-sensitive deployment windows.
- Collaborative team player with experience working alongside architects, project managers, and operations teams.