St. Fox
Posted 2w ago

L3 Network Security Engineer (Managed Firewall | Network Infrastructure)

St. Fox
Pune, Maharashtra, India
OnsiteFull Time
Responsibilities
  • managing firewalls
  • troubleshooting networks
  • mentoring engineers
Requirements
  • Requires 8+ years of network security engineering experience
  • Including 4+ years at L3 level
  • Cisco and Palo Alto firewall expertise
  • Enterprise switching and routing skills, and CCNP Security or Enterprise certification
Technical tools mentioned
Cisco ASAFirepower Threat Defense (FTD)Palo Alto NetworksApp-IDUser-IDPalo Alto PanoramaCisco CatalystCisco NexusVLANSTPVPCQoSWireless LAN Controllers (WLC)Cisco Access PointsOSPFBGPEIGRPCisco AnyConnectGlobalProtectSD-WANSASERSTPSPANWiresharkNAC802.1XRADIUSIPsecSSL-VPNPBRFirepower Management CenterWildFire

Job description

About the Role:

Saint Fox is looking for an experienced L3 Network Security Engineer to own the design, deployment, and day-to-day management of enterprise network security infrastructure for our clients. This is a senior hands-on role. You will work across Cisco and Palo Alto environments, drive incident escalations to closure, mentor junior engineers, and contribute to architecture decisions. You will sit within the Managed Firewall and Secure Access practice, working closely with Security Analysts and Principal Engineers to keep client environments stable, documented, and audit-ready.

Key Responsibilities:

Firewall Operations
• Design, deploy, and manage Cisco ASA and Firepower Threat Defense (FTD) firewalls in enterprise and multi-site environments.
• Operate and tune Palo Alto Networks next-generation firewalls including policy management, App-ID, User-ID, and threat prevention profiles.
• Manage Palo Alto Panorama for centralised policy and device management across multiple firewalls.
• Perform rule-base reviews, clean-up, and optimisation on a scheduled basis to reduce attack surface and policy drift.
• Respond to and resolve L3 firewall incidents and escalations within agreed SLA windows.

Network Infrastructure
• Configure and manage Cisco Catalyst and Nexus switching platforms including VLANs, STP, VPC, and QoS.
• Administer Cisco Wireless infrastructure including WLC (Wireless LAN Controllers) and Cisco Access Points across campus and branch environments.
• Troubleshoot complex Layer 2 and Layer 3 network issues from physical through to application layer.
• Maintain and enforce network segmentation policies aligned to Zero Trust principles. Routing and Connectivity
• Configure and manage dynamic routing protocols including OSPF, BGP, and EIGRP.
• Manage site-to-site and remote-access VPN including Cisco AnyConnect and Palo Alto Global Protect.
• Support SD-WAN and SASE integration efforts where applicable

Operations and Governance
• Own change management for network security changes including planning, testing, and rollback procedures.
• Maintain accurate and current network diagrams, run books, and configuration documentation.
• Participate in vulnerability and patch management cycles for network devices.
• Support internal and external audits by providing evidence and configuration reviews.
• Provide mentoring and technical guidance to L1 and L2 engineers

Requirements

Experience
• 8 to 15 years of hands-on experience in network security engineering.
• At least 4 years working at L3 or equivalent senior engineer level.
• Demonstrated production experience with Cisco ASA and/or FTD firewalls.
• Demonstrated production experience with Palo Alto Networks NGFW and Panorama.
• Solid experience with Cisco Catalyst and Nexus switching in enterprise environments.
• Working experience with Cisco WLC and enterprise access point management.

Technical Skills
• Cisco Firewall: ACLs, NAT, VPN, HA, and Firepower management centre.
• Cisco Switching: VLAN, STP, RSTP, VPC/vPC, port-channel, QoS, and SPAN.
• Cisco Wireless: WLC management, AP provisioning, SSID design, RF planning basics, and client troubleshooting.
• Palo Alto: Security policies, NAT, decryption, URL filtering, Wildfire, Panorama, and HA configuration.
• Routing: OSPF, BGP, EIGRP, PBR, and route redistribution.
• VPN: IPsec, SSL-VPN, GlobalProtect, and AnyConnect.
• Packet analysis using Wireshark or equivalent.
• Working knowledge of NAC, 802.1X, and RADIUS.

Preferred Certifications:
• Required: CCNP Security or CCNP Enterprise (current and valid).
• Preferred: Palo Alto PCNSE (or working towards it).
• Preferred: Cisco CCIE Security or equivalent advanced certification.

Soft Skills:
• Clear communicator. You can explain a complex network problem to a non-technical stakeholder without burying them in acronyms.
• Methodical under pressure. You follow process during incidents and document what happened after ward.
• Self-directed. You manage your workload, flag blockers early, and do not wait to be chased.
• Collaborative. You work well with security analysts, project managers, and client technical teams

Benefits

Why Join St. Fox:

• Opportunity to work onsite at a leading customer location, enabling direct engagement with innovative projects.
• A collaborative and dynamic working environment focused on continuous learning and professional growth.
• Exposure to advanced technologies and ongoing training opportunities.
• Clear career progression pathways supported by experienced leadership.

What We Offer:

• An opportunity to work in a rapidly growing company with potential for personal and professional growth.
• Opportunity to work in a rapidly growing company with potential for personal and professional growth.
• A collaborative and inclusive culture that values each employee’s contribution towards our goals.
• Competitive compensation package including attractive bonus structures and benefits

How to Apply: Interested candidates should submit a detailed resume and a cover letter outlining their qualifications and experience relevant to the role applied for. Applications should be sent via our careers portal or to [email protected]

St. Fox is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.

About St. Fox

Provider of AI-first cybersecurity and managed security services.

Similar jobs

Network Security Engineer roles near Pune, Maharashtra
21h
Save
Mark Applied
Hide
Network Security Engineer
Pune, Maharashtra, India
OnsiteFull Time
Corning
CorningNYSE: GLW: Develops and manufactures specialty glass, ceramics, and optical fiber.
Requires a 4-year degree or equivalent, Cisco ISE enterprise experience, network authentication and NAC expertise, automation with Python and Ansible, API integration, English fluency, and after-hours on-call availability.
Cisco ISE, Python, Ansible, Infrastructure as Code (IaC), API, ServiceNow, RADIUS, TACACS, Juniper Mist, Arista, Agile
2d
Save
Mark Applied
Hide
Network Security Engineer – Palo Alto & Data Centre Migration
Pune or Ahmedabad or Bengaluru or Chennai or Coimbatore or Gurugram or Hyderabad or Kochi or Kolkata or Noida or Thiruvananthapuram
OnsiteFull Time
UST
UST: Global provider of digital transformation and IT services.
5+ YOERequires 5+ years administering Palo Alto Networks firewalls, enterprise data center migration experience, Layer 3–7 troubleshooting, security policy expertise, and knowledge of TCP/IP, routing, DNS, and load balancing.
Firewall, Zscaler, Palo Alto Networks, Microsoft Azure, Application-ID, User-ID, Panorama, SAML, Zero Trust Network Access (ZTNA), ZPA, TCP/IP, DNS
1mo
Save
Mark Applied
Hide
Senior Network Security Engineer
Erandwane, Maharashtra, India
₹1000k-₹1300k/yr FieldFull Time
SNS India
SNS India: Provides comprehensive cybersecurity solutions and managed security services.
Hands-on Fortinet experience, knowledge of Check Point or Palo Alto, relevant certifications (NSE/FCP, CCNA), valid driving license, and ability to travel within Pune.
Fortinet Firewalls, FortiAnalyzer, FortiManager, Fortinet SD-WAN, Fortinet Switches, Check Point, Palo Alto Networks
1mo
Save
Mark Applied
Hide
Senior Engineer - Network Security (Zscaler & Palo Alto)
Pune, Maharashtra, India
OnsiteFull Time
Wipro
WiproNYSE: WIT: Global technology services and consulting for digital transformation.
1+ YOEHands-on experience with Zscaler (ZIA/ZPA/ZCC) and Palo Alto (including Panorama), strong TCP/IP and routing knowledge, incident/change management experience, excellent troubleshooting and communication; 1-3 years experience.
Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Client Connector (ZCC), Palo Alto Firewalls, Panorama, Cisco ISE, Infoblox, Citrix NetScaler, Cisco ACI
1mo
Save
Mark Applied
Hide
Sr Principal Network & Security
Pune, Maharashtra, India
OnsiteFull Time
Northern Trust
Northern TrustNASDAQ: NTRS: Financial services for individuals, families, and global institutions.
Expertise in enterprise network security with deep Check Point and F5 experience, routing (BGP/OSPF), wireless and proxy security, automation (scripting/IaC), incident response, documentation, and strong stakeholder communication.
Check Point, F5, BGP, OSPF, iRules, Ansible, Terraform, Python, Git, CI/CD, ServiceNow, Azure, AWS, GCP
2mo
Save
Mark Applied
Hide
Senior Network Security Engineer
Pune, Maharashtra, India
OnsiteFull Time
Agivant
Agivant: AI-first digital and cloud engineering services.
4+ YOEMinimum 4+ years experience with network/security technologies; bachelor's degree or equivalent; proficiency with Python, Ansible, OpenStack, Terraform, REST API automation; experience with firewall, SASE, ZTA, Cisco/Aruba/Palo Alto devices; knowledge of NIST/CIS/STIG frameworks.
Python, Ansible, OpenStack, Terraform, REST API, NIST, CIS Benchmark, STIG, SASE, ZIA, ZPA, Palo Alto, Zscaler, Cisco ACI, Aruba ClearPass, Cisco, Versa, Aruba, scikit-learn, PyTorch, Azure ML, GCP, Azure, AWS, MFA, SSO, SAML, BGP, OSPF, DMVPN, IPSec, IKE, GRE, TACACS, RADIUS, 802.1x
5mo
Save
Mark Applied
Hide
Network Security Engineer - Fortigate Firewalls - VOIS-Bangalore (Pune, IN)
Pune, Maharashtra, India
OnsiteFull Time
Vodafone
VodafoneLondon Stock Exchange: VOD: Global provider of mobile and fixed-line telecommunications services.
Fortigate firewall expertise; FortiManager/ FortiAnalyzer; ITIL-based incident/change management; strong troubleshooting; vendor coordination; continuous learning.
Fortigate Firewall, FortiManager, FortiAnalyzer, IDS/IPS
6d
Save
Mark Applied
Hide
Cloud Network Security Engineer
Pune, Maharashtra, India
₹8-₹25/mo OnsiteFull Time
Applied Cloud Computing
Applied Cloud Computing: Provides cloud consulting, managed services, and software engineering solutions.
3+ YOE3+ years' experience with multi-cloud networking and security, AWS/Azure/GCP/OCI, Palo Alto and Fortinet firewalls, Terraform, routing protocols, cloud connectivity, and scripting.
AWS, Azure, Google Cloud Platform (GCP), Oracle Cloud Infrastructure (OCI), Palo Alto Panorama, Fortinet FortiGate, Azure Native Firewall, Azure NGFW, AWS Direct Connect, Azure ExpressRoute, Google Cloud Interconnect, Oracle Cloud Infrastructure FastConnect, Terraform, Python, Bash, PowerShell, BGP, OSPF, VRF, IPsec