We are looking for a Lead Consultant who will design, build, and manage secure, compliant network segmentation connecting regional environments to Global networks. This position utilizes a standardized security toolset, including Check Point Security Gateways, Palo Alto Networks next-generation firewalls, Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), and Cloudflare for DDoS protection, WAF, and application security. The role combines architectural design, hands-on engineering, automation, and L3/L4 operational leadership to provide policy-driven connectivity that meets strict regulatory and operational standards.
Responsibilities
- Establish trust zones, routing boundaries, and inter-zone controls across regional and Global Networks, addressing north-south and east-west traffic, micro-segmentation for sensitive layers, and explicit cross-border allow-lists
- Create HLD/LLD documentation, threat models, and control mappings that align with internal standards and regional regulations to support secure communication between regional and Global customer sites
- Build and manage dual-vendor firewall perimeters with defined control distribution, HA/cluster architecture, predictable failover, NAT domain strategy, SSL/TLS inspection governance, and jurisdiction-tuned Threat Prevention/WildFire/URL filtering
- Configure ZIA to provide identity-aware egress controls, jurisdiction-sensitive SSL inspection bypasses, inline CASB/DLP, and governance for approved SaaS applications
- Deploy ZPA to enable per-application zero-trust access, including connector placement, posture verification, conditional access, and app segmentation to replace legacy VPN solutions where possible
- Architect and implement Site-to-Site VPN (IPSec), Cloud Interconnect/Partner Interconnect equivalents, and BGP-based dual-tunnel HA per site to support hybrid cloud connectivity
- Roll out Cloudflare Magic Transit/Magic WAN, WAF Management, and rate limiting for internet-facing services, integrating with on-premises perimeters for layered protection
- Design SD-WAN/MPLS/SASE pathways featuring policy-based routing, robust encryption, and jurisdiction-specific key custody and rotation practices
- Convert regulatory and internal control mandates into actionable technical controls covering logging, data residency, TLS inspection scope, and lawful intercept requirements
- Consolidate telemetry from firewall, Zscaler, and Cloudflare platforms into SIEM following regional data handling policies, and develop detection rules for cross-border anomalies and policy drift
- Direct L3/L4 incident response efforts, coordinate containment measures, and oversee RCAs with documented corrective actions
- Oversee firewall, Zscaler, and Cloudflare policy management using Terraform/Ansible and vendor APIs, and establish CI/CD pipelines incorporating policy linting, unit testing, and path simulation
Requirements
- 5+ years of experience in network security architecture and operations, specializing in cross-border or multi-region connectivity
- Expertise in Check Point Security Gateways, Palo Alto Networks next-generation firewalls, and Panorama management
- Proficiency in Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) for zero-trust architecture
- Skills in Cloudflare Magic Transit/Magic WAN, WAF Management, and DDoS mitigation strategies
- Knowledge of cloud hybrid connectivity, including Site-to-Site VPN, Cloud Interconnect, and BGP routing
- Background in SD-WAN, MPLS, and SASE architectures with policy-based routing and strong encryption protocols
- Understanding of regulatory and compliance frameworks relevant to data residency, TLS inspection, and lawful intercept
- Familiarity with SIEM platforms and telemetry normalization for cross-border security monitoring
- Competency in Terraform, Ansible, and vendor APIs for policy-as-code and CI/CD pipeline integration
- Capability to lead L3/L4 incident response and conduct root cause analysis with corrective action planning
- English proficiency at B2 level or higher