2 окт

network security consultant

ориентир по рынку
вакансия зп не указана
в среднем 328 556 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовься к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузи резюме

Рекламный баннер: ОБЩЕСТВО С ОГРАНИЧЕННОЙ ОТВЕТСТВЕННОСТЬЮ "ЦЕНТР НАЦИОНАЛЬНЫХ ИНТЕЛЛЕКТУАЛЬНЫХ СИСТЕМ"
О рекламодателе
ОБЩЕСТВО С ОГРАНИЧЕННОЙ ОТВЕТСТВЕННОСТЬЮ "ЦЕНТР НАЦИОНАЛЬНЫХ ИНТЕЛЛЕКТУАЛЬНЫХ СИСТЕМ"
ИНН: 9704271170

описание

Описания нет

задачи

  • Design, implement, and operate secure, compliant network segmentation between regional environments and Global networks
  • Define trust zones, routing boundaries, and inter-zone controls for regional and Global Network, including north-south and east-west paths, micro-segmentation for sensitive tiers, and explicit cross-border allow-lists
  • Produce HLD/LLD, threat models, and control mappings aligned with internal standards and regional regulation to enable secure communication between regional and Global customer sites
  • Design and operate dual-vendor firewall perimeters, including control allocation, HA/cluster design, deterministic failover, NAT domain strategy, SSL/TLS inspection governance, and jurisdiction-tuned Threat Prevention/WildFire/URL filtering
  • Engineer ZIA identity-aware egress controls, SSL inspection with jurisdiction-aware bypasses, inline CASB/DLP, and sanctioned SaaS governance
  • Implement ZPA per-application zero-trust access, including connector placement, posture checks, conditional access, and app segmentation to replace legacy VPN where feasible
  • Design and deliver Site-to-Site VPN (IPSec), Cloud Interconnect/Partner Interconnect equivalents, and BGP-based dual-tunnel HA per site for cloud hybrid connectivity
  • Deploy Cloudflare Magic Transit/Magic WAN, WAF Management, and rate limiting for internet-facing services, and integrate them with on-prem perimeters for layered defence
  • Engineer SD-WAN/MPLS/SASE paths with policy-based routing, strong encryption, and defined key custody/rotation by jurisdiction
  • Translate regulatory and internal control requirements into enforceable technical controls for logging, data residency, TLS inspection scope, and lawful intercept considerations
  • Normalise telemetry from firewall, Zscaler, and Cloudflare platforms into SIEM under regional data handling rules, and build detections for cross-border anomalies and policy drift
  • Lead L3/L4 incidents, coordinate issue containment, and drive RCAs with corrective actions codified
  • Manage firewall, Zscaler, and Cloudflare policies through Terraform/Ansible and vendor APIs, and implement CI/CD with policy linting, unit tests, and path simulation

требования

  • 5+ Years of experience in network security architecture and operations, focused on cross-border or multi-region connectivity
  • Expertise in Check Point Security Gateways, Palo Alto Networks next-generation firewalls, and Panorama management
  • Proficiency in Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) for zero-trust architecture
  • Skills in Cloudflare Magic Transit/Magic WAN, WAF Management, and DDoS mitigation strategies
  • Knowledge of cloud hybrid connectivity, including Site-to-Site VPN, Cloud Interconnect, and BGP routing
  • Background in SD-WAN, MPLS, and SASE architectures with policy-based routing and strong encryption protocols
  • Understanding of regulatory and compliance frameworks relevant to data residency, TLS inspection, and lawful intercept
  • Familiarity with SIEM platforms and telemetry normalisation for cross-border security monitoring
  • Competency in Terraform, Ansible, and vendor APIs for policy-as-code and CI/CD pipeline integration
  • Capability to lead L3/L4 incident response and conduct root cause analysis with corrective action planning

условия

  • Условий в вакансии нет

Глобальная компания в сфере digital engineering, product development и технологического консалтинга.

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайся: это мошенничество.

Про зарплаты

Анонимные данные по зарплатам и грейдам.
Можно сверить вилку с рынком.

Посмотреть зарплаты

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайся: это мошенничество.