Consultant - Network Security
EPAM Systems
- Praca zdalna
To stanowisko wymaga obecności na miejscu. Zobacz podobne oferty poniżej.
We are seeking a Consultant – Network Security to design, implement, and operate secure, compliant network segmentation between regional environments and Global networks. This role leverages a standardized control stack including Check Point Security Gateways, Palo Alto Networks next-generation firewalls, Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA), and Cloudflare for DDoS mitigation, WAF, and application protection. The position blends architecture, hands-on engineering, automation, and L3/L4 operational leadership to deliver policy-driven connectivity under strict regulatory and operational requirements. Responsibilities Define trust zones, routing boundaries, and inter-zone controls for regional and Global Network, covering north-south and east-west paths, micro-segmentation for sensitive tiers, and explicit cross-border allow-listsProduce HLD/LLD, threat models, and control mappings aligned to internal standards and regional regulation to enable secure communication between regional and Global customer sitesDesign and operate dual-vendor firewall perimeters with clear control allocation, HA/cluster design, deterministic failover, NAT domain strategy, SSL/TLS inspection governance, and Threat Prevention/WildFire/URL filtering tuned for jurisdictionEngineer ZIA for identity-aware egress controls, SSL inspection with jurisdiction-aware bypasses, inline CASB/DLP, and sanctioned SaaS governanceImplement ZPA for per-application zero-trust access, with connector placement, posture checks, conditional access, and app segmentation replacing legacy VPN where feasibleDesign and deliver Site-to-Site VPN (IPSec), Cloud Interconnect/Partner Interconnect equivalents, and BGP-based dual-tunnel HA per site for cloud hybrid connectivityDeploy Cloudflare Magic Transit/Magic WAN, WAF Management, and rate limiting for internet-facing services, and integrate with on-prem perimeters for layered defenceEngineer SD-WAN/MPLS/SASE paths with policy-based routing, strong encryption, and defined key custody/rotation by jurisdictionTranslate regulatory and internal control requirements into enforceable technical controls for logging, data residency, TLS inspection scope, and lawful intercept considerationsNormalise telemetry from firewall, Zscaler, and Cloudflare platforms into SIEM with regional data handling rules, and build detections for cross-border anomalies and policy driftLead L3/L4 incidents, coordinate issue containment, and drive RCAs with corrective actions codifiedManage firewall, Zscaler, and Cloudflare policy through Terraform/Ansible and vendor APIs, and implement CI/CD with policy linting, unit tests, and path simulation Requirements 5+ years of experience in network security architecture and operations, with a focus on cross-border or multi-region connectivityExpertise in Check Point Security Gateways, Palo Alto Networks next-generation firewalls, and Panorama managementProficiency in Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) for zero-trust architectureSkills in Cloudflare Magic Transit/Magic WAN, WAF Management, and DDoS mitigation strategiesKnowledge of cloud hybrid connectivity, including Site-to-Site VPN, Cloud Interconnect, and BGP routingBackground in SD-WAN, MPLS, and SASE architectures with policy-based routing and strong encryption protocolsUnderstanding of regulatory and compliance frameworks relevant to data residency, TLS inspection, and lawful interceptFamiliarity with SIEM platforms and telemetry normalisation for cross-border security monitoringCompetency in Terraform, Ansible, and vendor APIs for policy-as-code and CI/CD pipeline integrationCapability to lead L3/L4 incident response and conduct root cause analysis with corrective action planning We offer We gather like-minded people:Top tech minds driving innovation in AI, cloud and digital platform modernizationSupportive team and agile, startup-like cultureHybrid by design mode and opportunity to work remotely within PolandChance to work abroad for up to 60 days annuallyBusiness-driven relocation opportunitiesWe provide growth opportunities:Career development programsThought leadership, mentoring, soft skills and well-being programsCertification (Anthropic, Gemini, GCP, Azure, AWS)English classesWe cover it all:Stable payParticipation in the Employee Stock Purchase Plan with a 15% discountBenefits package (health insurance, multisport, shopping vouchers)Referral bonuses up to $2,000Offices featuring entertainment and relaxation zones, table tennis and football, free snacks, coffee and moreCorporate, social and well-being eventsPlease, note:Benefits listed above are available to employees onlyWe are open for working with Contractors. Terms of B2B cooperation agreements are agreed individuallyWe will reach out to selected candidates exclusively EPAM is global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, we empower our clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.
- senior cybersecurity analyst Radom
- senior IT security data analyst Radom
- group information security analyst Radom
- senior IT security consultant Radom
- cyber threat analyst Radom
- cyber security specialist Radom
- senior soc analyst Radom
- IT security consultant Radom
- działu rozwoju sieci Radom
- nadzoru sieci Radom