Senior Associate – Network & Security Engineer
Emirates Investment Bank pjsc · Dubai, United Arab Emirates
قدّم وتابع مع أبلاي إيدجAbout Emirates Investment Bank:Emirates Investment Bank PJSC (EIBank) is an independent onshore private bank based in Dubai, United Arab Emirates, offering a wide range of banking and investment services to a select group of clients, supporting them through every stage of their wealth journey.Established in 1976 by prominent UAE business families, EIBank offers bespoke solutions across the full range of wealth management services, from asset management and access to global markets to advisory services. EIBank is a relationship driven bank, focused on building long-term partnerships. Our flexible and consultative approach enables us to offer customized products and solutions through innovative advice and services.Job Purpose:Lead the operation, security, and continuous improvement of enterprise network and hybrid-cloud connectivity. The role covers Cisco routing, switching and firewall infrastructure, network access control and AAA, LAN/WAN, network security platforms, Microsoft Azure networking, application and API protection, Zero Trust remote access, high availability, disaster recovery, monitoring, incident response, vendor governance, and regulatory compliance within a banking environment.Key ResponsibilitiesEnterprise Network & Security OperationsAdminister, maintain, and secure enterprise LAN/WAN infrastructure including routers, switches, firewalls, VPN services, and related network platforms.Operate network and security platforms including next-generation firewalls (NGFW), web application firewalls (WAF), security analytics, centralized logging, monitoring, and management solutions.Perform firmware and software upgrades, hotfixes, hardening, high-availability maintenance, policy changes, and lifecycle activities for managed network and security devices.Manage firewall policies, routing, NAT, VPN, network segmentation, and access control changes using least-privilege principles and regular rule reviews.Monitor availability, capacity, performance, and resilience of network and security services, identifying and implementing improvements to prevent service disruption.Network Access Control & Device AdministrationAdminister enterprise routing and switching environments, including Layer 2/Layer 3 switching, VLANs, trunking, routing, ACLs, redundancy, and secure device administration.Administer Network Access Control (NAC) and Authentication, Authorization, and Accounting (AAA) platforms, including 802.1X authentication and RADIUS-based access enforcement.Manage centralized administrative authentication, authorization, and accounting services for routers, switches, firewalls, and network devices using role-based access controls.Troubleshoot endpoint authentication, authorization policies, identity integration, NAC, RADIUS, and device administration issues across network infrastructure.Cloud Networking & Hybrid ConnectivityDesign and operate cloud network architectures, including hub-and-spoke and landing-zone models using virtual networks, subnets, network segmentation, security controls, user-defined routing, and controlled traffic flows.Design, implement, and maintain hybrid connectivity between on-premises and cloud environments, including dedicated private connectivity and site-to-site VPN solutions, with appropriate redundancy and disaster recovery capabilities.Implement and troubleshoot cloud networking services, including private connectivity, load balancing, web application security, gateway services, and API connectivity.Design traffic steering through virtual network security appliances and troubleshoot stateful traffic-flow issues, including asymmetric routing, source/destination translation, return-path control, and private connectivity challenges.Participate in architecture and solution reviews to validate segmentation, resiliency, scalability, high availability, and secure connectivity before production deployment.Network Security, WAF & Application ProtectionImplement and maintain firewall, IDS/IPS, web application firewall (WAF), reverse proxy, and application publishing controls for internet-facing and internal applications.Translate vulnerability assessment and penetration testing findings into network and application security controls such as rate limiting, URL filtering, access policies, TLS enhancements, and security header implementation.Configure and troubleshoot secure application and API traffic flows, path-based routing, digital certificates, certificate chains, and backend service connectivity across network and cloud security platforms.Review network exposure and security policies, remove unnecessary access, and validate changes with application and information security teams.Zero Trust, Remote Access & Identity IntegrationOperate secure remote-access and Zero Trust Network Access (ZTNA) solutions, including access-policy management and endpoint connectivity services.Integrate remote-access platforms with enterprise identity providers using federated authentication, single sign-on (SSO), and multi-factor authentication (MFA).Support controlled third-party access through segmented network paths and privileged access management solutions.Plan and support remote-access client upgrades and technology migrations, including transitioning from legacy connectivity methods to modern secure access protocols.Performance, Troubleshooting & Incident ResponseProvide Level 2/Level 3 support for complex network, security, cloud, and application connectivity incidents across on-premises and cloud environments.Perform packet captures, traffic-flow analysis, TCP/TLS troubleshooting, route validation, latency analysis, and security device investigations to isolate root causes.Troubleshoot connectivity across load balancers, private connectivity services, web application firewalls, gateways, and virtual network appliances.Conduct root cause analysis for major incidents and recurring faults, implementing corrective actions to improve service availability and performance.Coordinate technical incident response with internal teams, managed service providers, cloud service providers, and vendor support teams through to resolution.Governance, Compliance & Change ManagementWork within formal change management and governance processes, assess technical risk, validate implementation and rollback plans, and ensure approved changes are executed and documented.Define and enforce network and cloud governance standards covering IP addressing, segmentation, security zoning, routing, firewall policies, and secure connectivity.Support audits and regulatory reviews by providing configuration evidence, network diagrams, security-control documentation, and remediation status reports.Coordinate internal and external vulnerability assessments and penetration testing activities and track remediation actions through closure.Maintain network architecture documentation, security policy records, IP address management records, standard operating procedures, and operational runbooks.Technical Leadership & Vendor ManagementAct as a technical focal point for network, cloud, security, SOC/NOC, and managed service operations, validating proposed configurations before production deployment.Lead technical discussions for new solutions, migrations, architecture changes, and incident resolution with infrastructure, cloud, application, information security, and business stakeholders.Review service performance, SLA/KPI achievements, recurring incidents, and operational risks, escalating material gaps to management as required.Provide technical direction, mentoring, knowledge transfer, and troubleshooting support to engineering and operations teams, and review technical documentation from suppliers and service providers.Support onboarding of new technologies and service providers, including design validation, implementation planning, operational handover, and readiness assessmentsEssential: Bachelor's degree in Computer Science, Information Technology, Network Engineering, Cybersecurity, or a related discipline.Desirable:Strong enterprise networking knowledge covering TCP/IP, VLANs, routing, switching, high availability, LAN/WAN, IPsec/SSL VPN, DNS, and network segmentation.Hands-on experience with Cisco enterprise routing and switching, Cisco firewall platforms, Cisco ISE, Network Access Control (NAC), 802.1X, RADIUS, TACACS+, and AAA.Hands-on experience with next-generation firewalls, WAF, IPS/IDS, SASE/ZTNA, remote access, and security monitoring platforms, preferably across Fortinet and Palo Alto Networks technologies.Hands-on experience with Microsoft Azure networking, hybrid cloud connectivity, network virtual appliances, Private Link/Private Endpoints, load balancing, WAF, and cloud network governance.Strong understanding of HTTP/HTTPS, TLS, certificates, NAT, stateful firewall behaviour, application publishing, and packet-level troubleshooting.Experience working in regulated environments with formal change management, audit evidence, vulnerability remediation, disaster recovery, and security compliance requirements.Relevant professional certifications such as Cisco CCNA/CCNP, Fortinet, Palo Alto Networks, or Microsoft Azure certifications are preferred.Strong written and verbal communication skills with the ability to explain technical risk, coordinate vendors, document solutions, and support critical incidents.