Visionpool Business Servies is hiring a REMOTE Network Security Consultant Resource who will serve as a senior subject matter expert responsible for the governance, architecture, and oversight of enterprise network security controls across on-premises and hybrid cloud environments. The Consultant will provide security guidance on network and application designs, with a focus on Cisco-based security platforms, ensuring alignment with enterprise standards, zoning and segmentation models, and zero trust principles.
Responsibilities:
Design, implement, and manage enterprise network security controls across Cisco security platforms including Cisco Firepower Threat Defense (FTD) firewalls (LINA and SNORT engines), Cisco FMC (Firepower Management Center), Cisco Umbrella DNS / OpenDNS, Cisco Web Security Appliances (WSA), Cisco Secure Malware Analytics (Sandboxing).
Provide governance oversight and security expertise for remote access solutions, including VPN services on Cisco FTD platforms, ensuring configurations align with enterprise security standards, access control policies, and zero trust principles.
Act as a subject matter expert for troubleshooting and triaging network security incidents, alerts, and anomalies related to firewall, IPS, DNS, and web security technologies.
Perform continuous review and tuning of Intrusion Prevention System (IPS) / Intrusion Detection System (IDS) signatures, firewall rules, and traffic inspection policies to improve detection capabilities and reduce false positives.
Provide expertise in Azure networking and security controls, including Virtual networks (VNets), subnets, and network security groups (NSGs), Azure Firewall and application gateways, Identity and Access Management (IAM), Privileged Access Management (PAM),Conditional Access, and Role-Based Access Control (RBAC)
Evaluate and integrate emerging network security technologies, including automation, orchestration, and Artificial Intelligence (AI) / Machine Learning (ML) - based threat detection capabilities.
Lead or support incident response activities related to network security breaches, including containment, root cause analysis, and remediation.
Strong understanding of load balancing technologies, particularly F5 load balancers, with the ability to review and assess traffic flow configurations, including traffic distribution and redirection to backend servers, ensuring alignment with enterprise security controls and design standards.
Qualifications:
Strong expertise in network security architecture, design, and governance, including segmentation, zoning, and zero trust principles.
Demonstrated hands-on experience with enterprise network security technologies, including Cisco Firepower Threat Defense (FTD), FMC, IPS/IDS, DNS and web security controls (Cisco Umbrella/OpenDNS, Web Security Appliances)
Deep understanding of network security controls including firewalls, IPS/IDS, VPNs, encryption, Uniform Resource Locator (URL) / Domain Name System (DNS) filtering, and network segmentation.
Familiarity with Security Information and Event Management SIEM), Security Orchestration, Automation, and Response (SOAR), Network Detection and Response (NDR), Endpoint Detection and Response (EDR), and vulnerability management platforms.
Proven ability to work with cross-functional teams, including infrastructure, cloud, and architecture teams.