Principal Network Engineer – Network & Security Patching (Banking Domain)
TAT IT Technolgies · Abu Dhabi, Abu Dhabi Emirate, United Arab Emirates
Apply & track with Apply EdgeHi,We have an urgent requirement for Principal Network Engineer – Network & Security Patching (Banking Domain) is required for our banking clients in Abu Dhabi ,UAEPrincipal Network Engineer to manage patching and lifecycle maintenance of network and network security infrastructure within a regulated banking--MustStrong Experience Firewalls (Fortinet, Palo Alto, F5, Cisco, Check Point)WAF / IPS / DDoS protection technologies, Routing & switching (BGP, OSPF, VLANs)--MustExpertise in patch management and upgrade lifecycle for network/security devices.---MustStrong understanding of vulnerability management and security hardening.---MustProvide L2/L3 support for network and security operations, including: Incident troubleshooting and resolution Critical outage handling and escalation Root Cause Analysis (RCA) participation--MustCertificate :CCNP,CCIE,CISSP --Any one must -NSE PCNSE ITIL—preffered Strong Banking Domain --MustRole SummaryWe are seeking an experienced Principal Network Engineer to manage patching and lifecycle maintenance of network and network security infrastructure within a regulated banking environment.The primary responsibility is to ensure timely remediation of vulnerabilities through controlled patching processes, while maintaining high availability, security posture, and regulatory complianceThe role requires strong expertise in risk assessment, impact analysis, and stakeholder communication, ensuring all changes are executed with minimal disruption and in full alignment with governance processes.In addition, the engineer will provide secondary support to Network & Security Operations (L2/L3) for incident handling and operational stability.Note: This role involves planned after-hours and weekend work aligned with approved maintenance windows for production systems.Key Responsibilities1. Network & Security Patch Management (Primary Role)Own end-to-end patch management lifecycle for network and security appliances (firewalls, WAF, IPS, routers, switches, VPN, etc.).Perform scheduled upgrades, patches, hotfixes, and firmware updates in line with vendor advisories and internal policies.Ensure all devices are compliant with security baselines, vulnerability remediation timelines, and audit requirements.Maintain up-to-date inventory and patch status of all in-scope infrastructure. Risk, Impact & Compliance ManagementPerform pre-change impact analysis and risk assessment, including dependency mapping and business impact evaluation.Ensure all activities follow formal Change Management (CAB) processes with proper approvals and documentation.Conduct patch testing in non-production environments and validate stability prior to production rollout.Define and maintain rollback/contingency plans for all changes.Ensure adherence to:Central Bank and internal regulatory requirementsPCI-DSS / security compliance standardsAudit and risk governance frameworks Stakeholder Communication & ReportingCommunicate patch schedules, risks, and expected service impact to technical teams, business stakeholders, and management.Provide real-time updates during maintenance windows and post-implementation reports.Ability to translate technical risk and impact into business-friendly communication.Coordinate with application owners, infrastructure teams, security teams, and vendors for seamless execution. Operational Support (Secondary Role)Provide L2/L3 support for network and security operations, including:Incident troubleshooting and resolutionCritical outage handling and escalationRoot Cause Analysis (RCA) participationSupport BAU operations for firewalls, WAF, IPS, VPN, and routing/switching environments.Work closely with SOC/NOC and operational teams to maintain service availability. Governance, Documentation & Continuous ImprovementMaintain audit-ready documentation for all patching activities, approvals, and implementation outcomes.Support internal/external audits by providing evidence of patch compliance and change controls.Identify opportunities to improve:Patch automationDeployment cyclesRisk mitigation processesContribute to standard operating procedures (SOPs) and best practices. After-Hours / Weekend ActivityExecute majority of patching during approved maintenance windows (after-hours/weekends) to minimize business impact.Provide on-call support during critical patching or incident scenarios.Required Skills & ExperienceTechnical Skills4–7 years of experience in network/security engineering within enterprise environments (banking preferred).Proven experience in:Firewalls (Fortinet, Palo Alto, F5, Cisco, Check Point)WAF / IPS / DDoS protection technologiesRouting & switching (BGP, OSPF, VLANs)Hands-on expertise in patch management and upgrade lifecycle for network/security devices.Strong understanding of vulnerability management and security hardening.Soft SkillsStrong communication and stakeholder management skills.Ability to assess risk and articulate impact clearly to business and leadership.Excellent analytical, problem-solving, and troubleshooting skills.Ability to work under pressure during critical maintenance or incidents.QualificationsBachelor’s degree in Computer Science / IT / related discipline.certifications:CCNP / CCIENSE / PCNSECISSP / ITILWorking ConditionsRole requires regular after-hours and weekend work aligned with banking change windows.Operates in a highly regulated, audit-driven environment with strict adherence to governance controls.Skills: patching,security,network