Network Security Job Descriptions
May 10, 2026 ยท View on GitHub
Representative Network Security, Firewall, VPN, SASE / Zero Trust, and Network Architect JDs.
Companion roadmap: Network Security Career Roadmap
1. Network Security Analyst (Entry) \u2014 MSSP
Responsibilities
- Monitor firewall, IDS/IPS, VPN, and proxy logs across customer environments
- Triage and escalate network-borne alerts (port scans, brute force, beaconing, DNS exfil)
- Apply rule changes under change-management process
- Run packet captures and basic traffic analysis with Wireshark / tcpdump
- Document and maintain network diagrams and rule justifications
Required
- 1\u20132 years in IT / networking / security
- Solid TCP/IP, DNS, HTTP, IPsec basics
- Familiarity with at least one firewall vendor (Palo Alto, Fortinet, Check Point, Cisco)
- Wireshark / tcpdump usage
- CompTIA Security+ or Network+ preferred
2. Network Security Engineer (Mid) \u2014 Mid-size enterprise
Responsibilities
- Design, deploy, and operate firewalls, VPNs, NAC, and proxies
- Implement and tune IDS/IPS signatures
- Build and document network segmentation; enforce east-west controls
- Lead incident response for network-borne attacks (DDoS, intrusions, exfil)
- Automate firewall changes via Ansible / Terraform / vendor APIs
- Partner with cloud teams on hybrid network design (AWS Transit Gateway, Azure vWAN)
Required
- 3\u20135 years in network security engineering
- Vendor depth in one of: Palo Alto (PCNSA / PCNSE), Fortinet (NSE 4\u20136), Cisco (CCNP Security), Check Point
- Strong scripting (Python with netmiko / nornir, or PowerShell)
- Solid cloud networking (AWS VPC, Azure VNet, or GCP VPC)
- Familiarity with SD-WAN and SASE concepts
Preferred
- Zero Trust hands-on (Zscaler, Cloudflare, Netskope, Twingate)
- AWS Security Specialty / AZ-500
3. Senior Network Security / Zero Trust Engineer \u2014 BFSI
Responsibilities
- Design and operate Zero Trust Network Architecture across workforce + workloads
- Migrate legacy site-to-site VPNs to ZTNA / SSE / SASE
- Lead micro-segmentation rollout (Illumio, Cisco Secure Workload, native cloud)
- Manage internal PKI / mTLS programs
- Lead network security incident response and tabletop exercises
- Mentor 2\u20133 mid-level engineers
Required
- 6\u20139 years in network security
- Deep firewall + cloud network + identity-aware proxy experience
- Strong understanding of NIST SP 800-207 (Zero Trust Architecture)
- Cert: CCNP Security, Palo Alto PCNSE, AZ-500, or CISSP
- Excellent technical writing
4. Network Security Architect \u2014 Global enterprise
Responsibilities
- Set the multi-year network security architecture for global enterprise (10+ regions)
- Define the standard pattern for hybrid + multi-cloud + SASE
- Run vendor consolidation (firewall, ZTNA, SD-WAN, NDR)
- Chair the network change advisory board
- Represent network security to regulators and external auditors
Required
- 10+ years total, 5+ in network security architecture
- Demonstrated multi-region, multi-cloud experience
- Multiple senior certifications (CCIE Security or equivalent vendor depth + CISSP)
- Strong cross-functional leadership
What recruiters search for
- Firewalls: Palo Alto, Fortinet, Check Point, Cisco ASA / Firepower / FTD, Juniper SRX, iptables/nftables, pf
- SD-WAN / SASE / SSE: Cisco Viptela, VMware VeloCloud, Palo Alto Prisma SD-WAN, Fortinet Secure SD-WAN, Cato, Netskope, Zscaler, Cloudflare One
- NAC: Cisco ISE, Aruba ClearPass, Forescout
- Proxies / WAF: Squid, Blue Coat / Symantec, Zscaler ZIA, Cloudflare WAF, AWS WAF, Akamai
- NDR: Vectra, Darktrace, ExtraHop, Cisco StealthWatch / Secure Network Analytics
- Detection: Suricata, Snort, Zeek
- Cloud network: AWS VPC / Transit Gateway / Network Firewall / Shield, Azure NSG / Azure Firewall / vWAN, GCP VPC / Cloud Armor
- Certs: CCNA / CCNP / CCIE Security, Palo Alto PCNSA / PCNSE, Fortinet NSE 4-7, AZ-500, AWS Security Specialty, GIAC GMON, CISSP
Have a Network Security JD to add? PR welcome \u2014 see Contribute.md.