Network Security Engineer — Deployable Communications Boundary for NATO with security clearance

Il y a 6 heures

Hainaut, Wallonia, Belgique WLG Temps plein
ppEvery deployed mission network has an edge, and somebody has to be sure of it. This role is that person: third-line engineering on the boundary protection layer — next-generation firewalls, the rulesets that run on them, and the tunnels that carry traffic between sites. It is a job for someone who is genuinely at home in a firewall policy: not only pushing the change, but arguing about whether the rule should exist, what it opens, and how it will be audited a year from now. /p h3What You Would Be Doing /h3 ul liBuild, configure and maintain next-generation firewalls across the mission estate, including high-availability pairs and central management. /li liDesign, implement and review security policies and rulesets, and adapt them as the operational picture changes. /li liConfigure and troubleshoot VPN and secure interconnection between sites. /li liTake third-line incidents through to root cause, working with the network and platform teams rather than throwing tickets over a wall. /li liAutomate the repetitive parts — signature updates, configuration backups, health checks. /li liKeep procedures and security documentation current, and report monthly on service performance. /li /ul h3What you would bring /h3 ul liAt least three years in firewall administration and network security. /li liPalo Alto certification (PCNSE or equivalent) and real depth in configuration, management and troubleshooting. /li liSecurity+ or an equivalent security qualification. /li liSound networking fundamentals — protocols, routing, architecture — and VPN technologies. /li liScripting and automation, and the habit of using them. /li liProfessional English, spoken and written, to a standard that carries a technical briefing. /li /ul pThe work is on site in Mons, in normal office hours, with occasional planned night work for change windows and roughly one trip a month to other European locations. CISSP or CCNA is welcome but not expected. /p /p