Firewall and VPN Security Engineer
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Every deployed mission network has an edge, and somebody has to be sure of it. This role is that person: third-line engineering on the boundary protection layer — next-generation firewalls, the rulesets that run on them, and the tunnels that carry traffic between sites.
It is a job for someone who is genuinely at home in a firewall policy: not only pushing the change, but arguing about whether the rule should exist, what it opens, and how it will be audited a year from now.
What you would be doing
- Build, configure and maintain next-generation firewalls across the mission estate, including high-availability pairs and central management.
- Design, implement and review security policies and rulesets, and adapt them as the operational picture changes.
- Configure and troubleshoot VPN and secure interconnection between sites.
- Take third-line incidents through to root cause, working with the network and platform teams rather than throwing tickets over a wall.
- Automate the repetitive parts — signature updates, configuration backups, health checks.
- Keep procedures and security documentation current, and report monthly on service performance.
What you would bring
- At least three years in firewall administration and network security.
- Palo Alto certification (PCNSE or equivalent) and real depth in configuration, management and troubleshooting.
- Security+ or an equivalent security qualification.
- Sound networking fundamentals — protocols, routing, architecture — and VPN technologies.
- Scripting and automation, and the habit of using them.
- Professional English, spoken and written, to a standard that carries a technical briefing.
The work is on site in Mons, in normal office hours, with occasional planned night work for change windows and roughly one trip a month to other European locations. CISSP or CCNA is welcome but not expected.