Senior Associate – Network & Security Engineer
Emirates Investment Bank pjsc · Dubai, United Arab Emirates
Apply & track with Apply EdgeJob Purpose:Lead the operation, security, and continuous improvement of enterprise network and hybrid-cloud connectivity. The role covers Cisco routing, switching and firewall infrastructure, network access control and AAA, LAN/WAN, network security platforms, Microsoft Azure networking, application and API protection, Zero Trust remote access, high availability, disaster recovery, monitoring, incident response, vendor governance, and regulatory compliance within a banking environment.Key ResponsibilitiesEnterprise Network & Security OperationsAdminister, maintain, and secure enterprise LAN/WAN infrastructure including Cisco routers, switches, firewall platforms, VPN services, and related network platforms.Operate network security platforms including Cisco firewalls, FortiGate, Palo Alto Networks firewalls, FortiWeb WAF, FortiAnalyzer, and associated monitoring and management services.Perform firmware and software upgrades, hotfixes, hardening, high-availability maintenance, policy changes, and lifecycle activities for managed network and security devices.Manage firewall policy, routing, NAT, VPN, segmentation, and access-control changes using least-privilege principles and regular rule reviews.Monitor availability, capacity, performance, and resilience of network and security services and identify required improvements before service impact.Cisco Network Access Control & Device AdministrationAdminister Cisco routing and switching environments, including Layer 2/Layer 3 switching, VLANs, trunking, routing, ACLs, redundancy, and secure device management.Administer Cisco Identity Services Engine (ISE) for Network Access Control (NAC) and AAA, including 802.1X authentication and RADIUS-based network access enforcement.Manage TACACS+ authentication, authorization, and accounting for administrative access to routers, switches, firewalls, and other network devices using centralized role-based access.Troubleshoot 802.1X, RADIUS, TACACS+, endpoint authentication, authorization-policy, and Cisco ISE integration issues across network infrastructure.Azure Cloud Networking & Hybrid ConnectivityDesign and operate Azure hub-and-spoke and landing-zone network architectures using VNets, subnets, peering, NSGs, UDRs, security zones, and controlled east-west and north-south traffic flows.Design, implement, and maintain hybrid connectivity using ExpressRoute and site-to-site VPN, including routing, redundancy, failover, and disaster-recovery requirements.Implement and troubleshoot Azure network services including Private Link and Private Endpoints, Azure Load Balancer, Application Gateway/WAF, VPN Gateway, and API Management network connectivity.Design traffic steering through network virtual appliances and troubleshoot stateful-flow issues including asymmetric routing, SNAT/DNAT, return-path control, and private-endpoint connectivity.Participate in cloud architecture and solution reviews to validate segmentation, resiliency, scalability, high availability, and secure connectivity before production deployment.Network Security, WAF & Application ProtectionImplement and maintain firewall, IPS/IDS, WAF, reverse-proxy, and application-publishing controls for internet-facing and internal applications.Translate vulnerability-assessment and penetration-test findings into network and WAF controls such as rate limiting, URL restrictions, access policies, TLS improvements, and security headers.Configure and troubleshoot secure application and API traffic flows, path-based routing, TLS certificates and certificate chains, and backend connectivity across FortiWeb and Azure security services.Review network exposure and security policies, remove unnecessary access, and validate changes with application and Information Security teams.Zero Trust, Remote Access & Identity IntegrationOperate secure remote-access and Zero Trust services using FortiSASE and FortiClient, including SPA/ZTNA access policies and endpoint connectivity.Integrate remote-access services with Microsoft Entra ID using SAML and MFA and support identity-based access-control requirements.Support controlled third-party and vendor access through segmented access paths and privileged-access-management solutions.Plan and support remote-access client upgrades and technology migrations, including transition from legacy VPN methods to supported secure protocols.Performance, Troubleshooting & Incident ResponseProvide Level-2/3 troubleshooting for complex network, security, cloud, and application-connectivity incidents across on-premises and Azure environments.Perform packet captures, session and flow analysis, TCP/TLS troubleshooting, route and path validation, latency analysis, and firewall counter investigation to isolate root cause.Troubleshoot connectivity across load balancers, private endpoints, load balancers, web application firewalls, and network virtual appliances.Perform root cause analysis for major incidents and recurring faults and implement corrective actions to improve availability and performance.Coordinate technical incident response with internal teams, managed service providers, cloud partners, and vendor TAC teams until service restoration and closure.Governance, Compliance & Change ManagementWork within formal change-management and CAB processes, assess technical risk, validate implementation and rollback plans, and ensure approved changes are executed and documented.Define and enforce network and cloud governance standards covering IP addressing, segmentation, security zoning, routing, firewall access, and secure connectivity.Support audits and regulatory reviews by providing configuration evidence, network diagrams, security-control evidence, and remediation status for applicable banking and security requirements.Coordinate internal and external vulnerability assessments and penetration testing and track network/security remediation actions through closure.Maintain network architecture diagrams, firewall and WAF rule documentation, IP address records, standard operating procedures, and operational runbooks.Technical Leadership & Vendor ManagementAct as a technical focal point for network, cloud, security, SOC/NOC, and managed-service partners and validate proposed configurations before production deployment.Lead technical discussions for new solutions, migrations, architecture changes, and incident resolution with Infrastructure, Cloud, Application, Information Security, and business stakeholders.Review service performance, SLA/KPI results, recurring incidents, and operational risks and escalate material gaps to IT management.Provide technical direction, knowledge transfer, and troubleshooting support to engineers and operations teams and review technical documentation produced by vendors.Support onboarding of new technologies and service providers, including design validation, implementation planning, handover, and operational readiness.Qualifications Essential: Bachelor's degree in Computer Science, Information Technology, Network Engineering, Cybersecurity, or a related discipline.Desirable:Strong enterprise networking knowledge covering TCP/IP, VLANs, routing, switching, high availability, LAN/WAN, IPsec/SSL VPN, DNS, and network segmentation.Hands-on experience with Cisco enterprise routing and switching, Cisco firewall platforms, Cisco ISE, Network Access Control (NAC), 802.1X, RADIUS, TACACS+, and AAA.Hands-on experience with next-generation firewalls, WAF, IPS/IDS, SASE/ZTNA, remote access, and security monitoring platforms, preferably across Fortinet and Palo Alto Networks technologies.Hands-on experience with Microsoft Azure networking, hybrid cloud connectivity, network virtual appliances, Private Link/Private Endpoints, load balancing, WAF, and cloud network governance.Strong understanding of HTTP/HTTPS, TLS, certificates, NAT, stateful firewall behaviour, application publishing, and packet-level troubleshooting.Experience working in regulated environments with formal change management, audit evidence, vulnerability remediation, disaster recovery, and security compliance requirements.Relevant professional certifications such as Cisco CCNA/CCNP, Fortinet, Palo Alto Networks, or Microsoft Azure certifications are preferred.Strong written and verbal communication skills with the ability to explain technical risk, coordinate vendors, document solutions, and support critical incidents.Experience:10 years of hands-on experience in enterprise network and network-security environments, preferably within banking, financial services, or another regulated industry. Experience should include routing and switching, firewall operations, network access control and AAA, hybrid-cloud networking, security operations, major incident troubleshooting, vendor coordination, and delivery of network/security projects.