Network Security Job Descriptions

May 10, 2026 ยท View on GitHub

Representative Network Security, Firewall, VPN, SASE / Zero Trust, and Network Architect JDs.

Companion roadmap: Network Security Career Roadmap


1. Network Security Analyst (Entry) \u2014 MSSP

Responsibilities

  • Monitor firewall, IDS/IPS, VPN, and proxy logs across customer environments
  • Triage and escalate network-borne alerts (port scans, brute force, beaconing, DNS exfil)
  • Apply rule changes under change-management process
  • Run packet captures and basic traffic analysis with Wireshark / tcpdump
  • Document and maintain network diagrams and rule justifications

Required

  • 1\u20132 years in IT / networking / security
  • Solid TCP/IP, DNS, HTTP, IPsec basics
  • Familiarity with at least one firewall vendor (Palo Alto, Fortinet, Check Point, Cisco)
  • Wireshark / tcpdump usage
  • CompTIA Security+ or Network+ preferred

2. Network Security Engineer (Mid) \u2014 Mid-size enterprise

Responsibilities

  • Design, deploy, and operate firewalls, VPNs, NAC, and proxies
  • Implement and tune IDS/IPS signatures
  • Build and document network segmentation; enforce east-west controls
  • Lead incident response for network-borne attacks (DDoS, intrusions, exfil)
  • Automate firewall changes via Ansible / Terraform / vendor APIs
  • Partner with cloud teams on hybrid network design (AWS Transit Gateway, Azure vWAN)

Required

  • 3\u20135 years in network security engineering
  • Vendor depth in one of: Palo Alto (PCNSA / PCNSE), Fortinet (NSE 4\u20136), Cisco (CCNP Security), Check Point
  • Strong scripting (Python with netmiko / nornir, or PowerShell)
  • Solid cloud networking (AWS VPC, Azure VNet, or GCP VPC)
  • Familiarity with SD-WAN and SASE concepts

Preferred

  • Zero Trust hands-on (Zscaler, Cloudflare, Netskope, Twingate)
  • AWS Security Specialty / AZ-500

3. Senior Network Security / Zero Trust Engineer \u2014 BFSI

Responsibilities

  • Design and operate Zero Trust Network Architecture across workforce + workloads
  • Migrate legacy site-to-site VPNs to ZTNA / SSE / SASE
  • Lead micro-segmentation rollout (Illumio, Cisco Secure Workload, native cloud)
  • Manage internal PKI / mTLS programs
  • Lead network security incident response and tabletop exercises
  • Mentor 2\u20133 mid-level engineers

Required

  • 6\u20139 years in network security
  • Deep firewall + cloud network + identity-aware proxy experience
  • Strong understanding of NIST SP 800-207 (Zero Trust Architecture)
  • Cert: CCNP Security, Palo Alto PCNSE, AZ-500, or CISSP
  • Excellent technical writing

4. Network Security Architect \u2014 Global enterprise

Responsibilities

  • Set the multi-year network security architecture for global enterprise (10+ regions)
  • Define the standard pattern for hybrid + multi-cloud + SASE
  • Run vendor consolidation (firewall, ZTNA, SD-WAN, NDR)
  • Chair the network change advisory board
  • Represent network security to regulators and external auditors

Required

  • 10+ years total, 5+ in network security architecture
  • Demonstrated multi-region, multi-cloud experience
  • Multiple senior certifications (CCIE Security or equivalent vendor depth + CISSP)
  • Strong cross-functional leadership

What recruiters search for

  • Firewalls: Palo Alto, Fortinet, Check Point, Cisco ASA / Firepower / FTD, Juniper SRX, iptables/nftables, pf
  • SD-WAN / SASE / SSE: Cisco Viptela, VMware VeloCloud, Palo Alto Prisma SD-WAN, Fortinet Secure SD-WAN, Cato, Netskope, Zscaler, Cloudflare One
  • NAC: Cisco ISE, Aruba ClearPass, Forescout
  • Proxies / WAF: Squid, Blue Coat / Symantec, Zscaler ZIA, Cloudflare WAF, AWS WAF, Akamai
  • NDR: Vectra, Darktrace, ExtraHop, Cisco StealthWatch / Secure Network Analytics
  • Detection: Suricata, Snort, Zeek
  • Cloud network: AWS VPC / Transit Gateway / Network Firewall / Shield, Azure NSG / Azure Firewall / vWAN, GCP VPC / Cloud Armor
  • Certs: CCNA / CCNP / CCIE Security, Palo Alto PCNSA / PCNSE, Fortinet NSE 4-7, AZ-500, AWS Security Specialty, GIAC GMON, CISSP

Have a Network Security JD to add? PR welcome \u2014 see Contribute.md.