Title: Network Security-Juniper SRX
Area(s) of responsibility
Skills: Network Security Engineer with Juniper SRX
Experience: 6-10 years
Location: Bangalore(Preferred) / Hyderabad/ Mumbai/ Pune/ Chennai/ Noida
Key Responsibilities
Segmentation & Zero Trust Responsibilities (Juniper SRX Focus)
- Architect and implement network segmentation strategies using Juniper SRX firewalls across data center, campus, and cloud environments to limit lateral movement and enforce least-privilege access.
- Design and operationalize Zero Trust Architecture (ZTA) principles, integrating identity, application, and network-based policy enforcement using firewall controls.
- Collaborate with application owners to discover, validate, and map application dependencies to enable policy-driven segmentation via firewall rules and security zones.
- Define and enforce granular security policies using zone-based segmentation, VRFs, and SRX policy constructs across hybrid environments.
- Integrate segmentation with firewalls, SIEM, IAM, EDR/XDR, and cloud-native controls for unified policy enforcement.
- Lead adoption and standardization of Juniper SRX as the primary segmentation enforcement platform across enterprise environments.
- Develop segmentation governance models, policy lifecycle management, and compliance alignment (CIS/NIST/Zero Trust frameworks).
Network Security & Infrastructure
- Strong experience managing LAN/WAN security technologies, including firewalls, IDS/IPS, SIEM, VPN, and NAC.
- Expertise in firewall architecture and design with strong hands-on experience in Juniper SRX (primary), along with Fortinet and Palo Alto.
- Deep expertise in:
- Security zones, policies, NAT, routing
- Application control and threat prevention
- High-availability clustering and scale design
- Experience securing public and private cloud (AWS, Azure, GCP) environments.
- Design and implementation of Web Application and API Protection (WAAP) solutions.
- Strong experience in proxy (forward/reverse), load balancing, and application security integration.
- Experience with SDN and SD-WAN architectures, including segmentation use cases.
Networking & Protocol Expertise
- Strong knowledge of:
- Routing protocols: BGP, OSPF, RIP, MPLS
- Network services: DNS, DHCP, NTP
- IPv4/IPv6 architecture and traffic management
- Experience in QoS, NetFlow, ACLs, NAT, multicast, and wireless technologies (802.11 variants).
- Experience with F5 GTM/LTM, VPN technologies, and Internet proxy solutions.
Data Center & Infrastructure
- Experience managing enterprise data center environments with technologies including:
- Aruba, Arista, Juniper switching
- Firewalls, WAN optimization, IDS/IPS, DLP
Strong understanding of structured cabling and network facilities