Network Security Engineer

Vailexa Technology

NULL, ID

JOB DETAILS
SKILLS
Amazon Web Services (AWS), Analysis Skills, Ansible, Application Programming Interface (API), CCNP - Cisco Certified Network Professional, CISSP - Certified Information Systems Security Professional, Change Control, Cisco ASA (Adaptive Security Appliance), Cisco Network Systems, Cloud Computing, CompTIA Security+, Computer Firmware, Configuration Management, DNS (Domain Name System), Denial of Service (DoS), Documentation, Email Security, Firewall Administration, Firewalls, GCP (Good Clinical Practices), Hunting, IP (Internet Protocol) Routing, IPsec (IP Security), Identify Issues, Incident Response, Internet Application, Intrusion Detection Systems, Intrusion Prevention Systems, Load Balancing, Machine Tool, Microsoft Windows Azure, NAT (Network Address Translation), Network Architecture/Engineering, Network Routing, Network Security, Network Support, Network Switching, Network Traffic Analysis, Presentation/Verbal Skills, Python Programming/Scripting Language, REST (Representational State Transfer), Risk Management, Root Cause Analysis, SSL-TLS (Secure Socket Layer - Transport Layer Security), Scripting (Scripting Languages), Security Attacks, Security Information and Event Management (SIEM), Software Administration, Software Upgrades, TCP/IP (Transmission Control Protocol/Internet Protocol), VPN (Virtual Private Network)
LOCATION
NULL, ID
POSTED
1 day ago

Position: Network Security Engineer

Location: Boise, ID

Experience: 6+ Years

Duration: 12+ Months

Key Responsibilities:

  • Firewall operations - Configure, manage, and tune next-generation firewall policies, NAT rules, VPNs, and security profiles across Palo Alto and Cisco platforms.
  • Web proxy & secure access - Administer secure web gateway/proxy services (e.g., Zscaler), including URL filtering, SSL inspection, traffic forwarding, and policy enforcement for users and locations.
  • DDoS protection - Deploy, monitor, and tune DDoS mitigation controls; respond to volumetric and application-layer attacks and refine protection thresholds.
  • Network detection & response - Operate network detection and response (NDR) tooling to baseline traffic, investigate anomalies, and support threat hunting and incident response.
  • Incident support - Investigate security events and alerts, perform root-cause analysis, and coordinate remediation with SOC and network teams.
  • Documentation & change control - Maintain accurate configuration standards, runbooks, network diagrams, and change records; participate in the change-management process.
  • Hardening & lifecycle - Support firmware/software upgrades, rule-based cleanup, and recurring policy and access reviews to reduce risk and technical debt.
  • Collaboration - Collaborate with internal stakeholders and vendors to troubleshoot connectivity and security issues and to onboard new sites, services, and controls.

Required Qualifications:

  • Approximately 6+ years of hands-on experience in network security or network engineering with a security focus.
  • Demonstrated hands-on experience administering next-generation firewalls, with practical expertise in Palo Alto and/or Cisco (ASA, Firepower) platforms.
  • Working experience with secure web proxy / SWG solutions - Zscaler (ZIA/ZPA) strongly preferred - including SSL inspection and policy configuration.
  • Practical knowledge of DDoS mitigation concepts and tooling, and experience responding to attack scenarios.
  • Experience with NDR or network traffic analysis platforms for detection, investigation, and threat hunting.
  • Solid grasp of TCP/IP, routing and switching, VPNs (IPsec/SSL), DNS, and network segmentation.
  • Familiarity with SIEM/log analysis and a structured approach to incident investigation.
  • Strong troubleshooting skills and the ability to work independently in a fast-paced, delivery-oriented contract environment.
  • Clear written and verbal communication, with disciplined documentation habits.

Preferred Qualifications:

  • Industry certifications such as PCNSE (Palo Alto), CCNP Security, Zscaler Certified, CISSP, or Security+.
  • Exposure to cloud network security (AWS, Azure, or GCP) and SASE/Zero Trust architectures.
  • Experience with automation/scripting (Python, Ansible, or REST APIs) for policy and configuration management.
  • Familiarity with load balancers, IDS/IPS, web application firewalls (WAF), and email security gateways.
  • Experience operating in regulated or enterprise-scale environments with formal change control.

Technology Environment:

Candidates should be comfortable working across the following technology areas. Direct experience with the named platforms is preferred; equivalent experience with comparable enterprise tools will be considered.

  • Firewalls - Palo Alto Networks NGFW; Cisco ASA / Firepower.
  • Proxy / SWG - Zscaler (ZIA / ZPA) and comparable secure web gateways.
  • DDoS - Cloud-based and on-premises DDoS mitigation services.
  • NDR - Network detection and response and traffic analysis platforms.
  • Supporting - SIEM, IDS/IPS, VPN concentrators, and segmentation controls.

About the Company

V

Vailexa Technology