St. Fox
Posted 2w ago

L3 Network Security Engineer (Managed Firewall | Network Infrastructure)

St. Fox
Bangalore, Karnataka, India
OnsiteFull Time
Responsibilities
  • managing firewalls
  • configuring networks
  • mentoring engineers
Requirements
  • Requires 8–15 years of network security engineering experience
  • Including 4 years at L3 level
  • Cisco and Palo Alto expertise, and current CCNP Security or CCNP Enterprise certification
Technical tools mentioned
Cisco ASAFirepower Threat Defense (FTD)Palo Alto NetworksPalo Alto PanoramaCisco CatalystCisco NexusCisco Wireless LAN Controllers (WLC)Cisco Access PointsOSPFBGPEIGRPCisco AnyConnectPalo Alto GlobalProtectSD-WANSASEWiresharkNAC802.1XRADIUSVLANSTPVPCQoSRSTPSPANIPsecSSL-VPNMicrosoft Excel

Job description

About the Role:

Saint Fox is looking for an experienced L3 Network Security
Engineer to own the design, deployment, and day-to-day management of
enterprise network security infrastructure for our clients. This is a senior
hands-on role. You will work across Cisco and Palo Alto environments, drive
incident escalations to closure, mentor junior engineers, and contribute to
architecture decisions.
You will sit within the Managed Firewall and Secure Access practice, working
closely with Security Analysts and Principal Engineers to keep client
environments stable, documented, and audit-ready.

Key Responsibilities:

Firewall Operations
• Design, deploy, and manage Cisco ASA and Firepower Threat Defense (FTD)
firewalls in enterprise and multi-site environments.

• Operate and tune Palo Alto Networks next-generation firewalls including
policy management, App-ID, User-ID, and threat prevention profiles.

• Manage Palo Alto Panorama for centralised policy and device management
across multiple firewalls.

• Perform rule-base reviews, clean-up, and optimisation on a scheduled basis
to reduce attack surface and policy drift.

• Respond to and resolve L3 firewall incidents and escalations within agreed
SLA windows.

Network Infrastructure
• Configure and manage Cisco Catalyst and Nexus switching platforms
including VLANs, STP, VPC, and QoS.

• Administer Cisco Wireless infrastructure including WLC (Wireless LAN
Controllers) and Cisco Access Points across campus and branch
environments.

• Troubleshoot complex Layer 2 and Layer 3 network issues from physical
through to application layer.

• Maintain and enforce network segmentation policies aligned to Zero Trust
principles.
Routing and Connectivity

• Configure and manage dynamic routing protocols including OSPF, BGP, and
EIGRP.

• Manage site-to-site and remote-access VPN including Cisco AnyConnect and
Palo Alto Global Protect.

• Support SD-WAN and SASE integration efforts where applicable

Operations and Governance
• Own change management for network security changes including planning,
testing, and rollback procedures.

• Maintain accurate and current network diagrams, run books, and
configuration documentation.

• Participate in vulnerability and patch management cycles for network
devices.

• Support internal and external audits by providing evidence and configuration
reviews.

• Provide mentoring and technical guidance to L1 and L2 engineers

Requirements

Experience
• 8 to 15 years of hands-on experience in network security engineering.

• At least 4 years working at L3 or equivalent senior engineer level.

• Demonstrated production experience with Cisco ASA and/or FTD firewalls.

• Demonstrated production experience with Palo Alto Networks NGFW and
Panorama.

• Solid experience with Cisco Catalyst and Nexus switching in enterprise
environments.

• Working experience with Cisco WLC and enterprise access point
management.

Technical Skills
• Cisco Firewall: ACLs, NAT, VPN, HA, and Firepower management centre.

• Cisco Switching: VLAN, STP, RSTP, VPC/vPC, port-channel, QoS, and SPAN.

• Cisco Wireless: WLC management, AP provisioning, SSID design, RF planning
basics, and client troubleshooting.

• Palo Alto: Security policies, NAT, decryption, URL filtering, Wildfire, Panorama,
and HA configuration.

• Routing: OSPF, BGP, EIGRP, PBR, and route redistribution.

• VPN: IPsec, SSL-VPN, GlobalProtect, and AnyConnect.

• Packet analysis using Wireshark or equivalent.

• Working knowledge of NAC, 802.1X, and RADIUS.


Preferred Certifications:
• Required: CCNP Security or CCNP Enterprise (current and valid).

• Preferred: Palo Alto PCNSE (or working towards it).

• Preferred: Cisco CCIE Security or equivalent advanced certification.


Soft Skills:
• Clear communicator. You can explain a complex network problem to a non-technical stakeholder without burying them in acronyms.

• Methodical under pressure. You follow process during incidents and
document what happened after ward.

• Self-directed. You manage your workload, flag blockers early, and do not wait
to be chased.

• Collaborative. You work well with security analysts, project managers, and
client technical teams

Benefits

Why Join St. Fox:

• Opportunity to work onsite at a leading customer location, enabling direct
engagement with innovative projects.

• A collaborative and dynamic working environment focused on continuous
learning and professional growth.

• Exposure to advanced technologies and ongoing training opportunities.

• Clear career progression pathways supported by experienced leadership.

What We Offer:


• An opportunity to work in a rapidly growing company with potential for
personal and professional growth.

• Opportunity to work in a rapidly growing company with potential for
personal and professional growth.

• A collaborative and inclusive culture that values each employee’s
contribution towards our goals.

• Competitive compensation package including attractive bonus structures
and benefits


How to Apply: Interested candidates should submit a detailed resume and a
cover letter outlining their qualifications and experience relevant to the role
applied for. Applications should be sent via our careers portal or to [email protected]

St. Fox is an Equal Opportunity Employer. We celebrate diversity and are
committed to creating an inclusive environment for all employees.


About St. Fox

Provider of AI-first cybersecurity and managed security services.

Similar jobs

Network Security Engineer roles near Bangalore, Karnataka
1d
Save
Mark Applied
Hide
DIGITAL SECURITY - Threat Prevention - NETWORK SECURITY - Proxy
Hyderabad or Bengaluru or Milpitas or Seattle or Princeton or Cape Town or London or Zurich or Singapore or Mexico City
RemoteFull Time
Zensar
ZensarNational Stock Exchange of India: ZENSARTECH: Global technology firm providing digital transformation and infrastructure services.
7+ YOERequires 7+ years in network and security engineering, 4+ years with Zscaler, global enterprise experience, and a bachelor's degree or equivalent practical experience.
Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Cloud Firewall, CASB, Browser Isolation, Data Loss Prevention (DLP), SSL Inspection, Azure AD (Entra ID), Okta, Ping Identity, Active Directory, SAML, OAuth, OpenID Connect, Multi-Factor Authentication (MFA), Python, YAML, Jira, Confluence, Ansible
2d
Save
Mark Applied
Hide
Senior Network Security Engineer – Firewall & ZTNA
Bangalore or Thiruvananthapuram
OnsiteFull Time
UST
UST: Global provider of digital transformation and IT services.
10+ YOERequires 10+ years in network security and enterprise infrastructure, firewall segmentation expertise, hybrid environment security, and a bachelor's degree or equivalent experience.
Juniper, Palo Alto, Fortinet, ZTNA, Zero Trust Architecture (ZTA), VPN, SIEM, IAM, EDR/XDR, ITIL
2d
Save
Mark Applied
Hide
Sr. Network Security Engineer with ZTNA
Bengaluru, Karnataka, India
OnsiteFull Time
Birlasoft
BirlasoftNational Stock Exchange of India: BSOFT: Provides digital transformation and IT consulting services for global enterprises.
8+ YOERequires 8–11 years of network security experience, with mandatory hands-on ZTNA/SASE/SSE expertise, Zscaler ZIA/ZPA and Axis Security or Aruba SSE, identity integration, firewalls, SIEM, VPN, and network security architecture.
Zscaler, ZIA, ZPA, Axis Security, Aruba SSE, Azure AD, Okta, EDR, XDR, SIEM, SOAR, SASE, SSE, SWG, CASB, DLP, SAML, OAuth, MFA, Fortinet, Palo Alto, Juniper, IDS/IPS, VPN, NAC, WAAP
5d
Save
Mark Applied
Hide
Administrator - Networks
Bangalore, Karnataka, India
OnsiteFull Time
Manhattan Associates
Manhattan AssociatesNASDAQ: MANH: Develops software to manage supply chains and omnichannel operations.
3+ YOERequires 3–4 years in network security engineering or operations, 1+ year in cloud security, TCP/IP and VPN expertise, Cisco security experience, and a related bachelor's degree or equivalent practical experience.
Cisco ISE, Cisco ASA, Cisco Firepower Threat Defense (FTD), VPN, IPsec, Cisco Umbrella, Secure Access, Splunk, SIEM, Cisco Secure Cloud Analytics (XDR), Azure, ServiceNow, Microsoft cloud security integrations, TCP/IP, IDS/IPS
1w
Save
Mark Applied
Hide
Network Security Engineer
Bengaluru, Karnataka, India
OnsiteFull Time
Point72
Point72: Global alternative investment firm managing capital and venture investments.
5+ YOERequires 5–7 years in network security, preferably in financial services or regulated environments, with firewall, cloud networking, segmentation, SASE, NDR, compliance, and security certification experience.
Illumio, Palo Alto Networks, GlobalProtect, Prisma Access, Cloudflare, Cisco ISE, AWS, Microsoft Azure, Google Cloud Platform (GCP), Guardicore, VMware NSX, VMware NSX-T, vArmour, Cisco ACI, ShieldX, Unisys Stealth, Zero Networks, zScaler, NetSkope, Darktrace, ExtraHop, Vectra, PCI DSS, HIPAA, GDPR
1w
Save
Mark Applied
Hide
L2 Network Security Engineer
Bengaluru, Karnataka, India
OnsiteFull Time
Systal
Systal: Global provider of managed network, cloud, and security solutions.
Enterprise or managed-services network security experience; networking, firewalls, VPNs, security incidents, SIEM, ServiceNow, ITIL, troubleshooting, documentation, and stakeholder communication skills.
TCP/IP, Check Point, IDS/IPS, SIEM, syslog, SolarWinds, Splunk, ServiceNow, ITIL, Cisco CCNA Security, CompTIA Security+
1w
Save
Mark Applied
Hide
Network Security Engineer
Bangalore, Karnataka, India
OnsiteFull Time
Unisys
UnisysNYSE: UIS: Provides enterprise-scale IT services and digital transformation solutions.
4+ YOEBachelor's degree and 4–6 years of relevant experience, or an equivalent combination of education and experience; expertise in security controls, deployments, automation, APIs, and incident resolution.
API
1w
Save
Mark Applied
Hide
Network Security Engineer
Bengaluru, Karnataka, India
₹350k-₹600k/yr OnsiteFull Time
SNS India
SNS India: Provides comprehensive cybersecurity solutions and managed security services.
Bachelor's degree in a related field; hands-on FortiGate, FortiSwitch, or Check Point experience; Kannada proficiency; networking, troubleshooting, communication, and analytical skills.
FortiGate, FortiSwitch, Check Point, TCP/IP, VLANs