Title: Network Security-Microsegmentation
Area(s) of responsibility
Skills: Network & Security Engineer- Microsegmentation
Experience: 6-10 years
Location: Bangalore Preferred/ Mumbai/ Pune/ Noida/ Hyderabad
Key Responsibilities
- Translate high-level business strategic objectives and goals into Enterprise IT requirements and conceptual designs.
- Develop and support comprehensive solutions that meet requirements and align with global network security and microsegmentation strategy.
- Develop and maintain a multi-year strategic network and security architecture roadmap, incorporating Zero Trust and segmentation-driven security models.
- Lead end-to-end network and security architecture across global platforms ensuring secure, high-performing, fault-tolerant, and resilient environments.
Microsegmentation & Zero Trust Responsibilities
- Architect and implement microsegmentation strategies across data center, campus, and cloud environments to limit lateral movement and enforce least-privilege access.
- Design and operationalize Zero Trust Architecture (ZTA) principles, integrating identity, application, and network-based policy enforcement.
- Integrate microsegmentation with firewalls, SIEM, IAM, EDR/XDR, and cloud-native controls for unified policy enforcement.
- Develop segmentation governance models, policy lifecycle management, and compliance alignment (CIS/NIST/Zero Trust frameworks).
Microsegmentation & Advanced Security
- Strong hands-on experience in designing and implementing microsegmentation solutions in complex enterprise environments.
- Proven capability to build application-aware segmentation policies based on traffic flow analysis.
- Experience with policy simulation, enforcement, monitoring, and optimization in segmentation platforms.
- Understanding of east-west traffic inspection, workload protection, and software-defined segmentation.
- Familiarity with Zero Trust Network Access (ZTNA) and identity-driven access models.
Network Security & Infrastructure
- Strong experience managing LAN/WAN security technologies, including firewalls, IDS/IPS, SIEM, VPN, and NAC.
- Expertise in firewall architecture and design with hands-on experience in:
- Fortinet (Fortigate), Palo Alto, Juniper
- Policy design, NAT, routing, application control, and threat prevention profiles
- Experience securing public and private cloud (AWS, Azure, GCP) environments.
- Design and implementation of Web Application and API Protection (WAAP) solutions.
- Strong experience in proxy (forward/reverse), load balancing, and application security integration.
- Experience with SDN and SD-WAN architectures, including segmentation use cases.
Networking & Protocol Expertise
- Strong knowledge of:
- Routing protocols: BGP, OSPF, RIP, MPLS
- Network services: DNS, DHCP, NTP
- IPv4/IPv6 architecture and traffic management
- Experience in QoS, NetFlow, ACLs, NAT, multicast, and wireless technologies (802.11 variants).
- Experience with F5 GTM/LTM, VPN technologies, and Internet proxy solutions.