Quick Overview
Job Description
Job Description
Job Title: Network Security Engineer L3
Location: New York, NY (Onsite)
Department: Cybersecurity Operations (SecOps)
Reports To: Cybersecurity Operations Lead
Employment Type:
Level: L3 Senior Individual Contributor
Position Summary
Client is seeking a senior Network Security Engineer (L3) with deep, hands-on expertise in network security (including network detection & response and network traffic visibility), network access control (NAC), and email security, complemented by sound conceptual knowledge across the broader cybersecurity landscape endpoint security, data loss prevention, cloud security, and SIEM. This is a senior, high-judgment individual contributor role: the candidate is expected to independently resolve the most complex escalations in their core domains, exercise good technical judgment across adjacent domains, and bring a genuine security engineering mindset rather than simply executing runbooks. The candidate will cover AMER business hours (from 9:00 AM ET) and maintain visibility into offshore team activity to ensure continuity of judgment across the day.
This is not a GRC or compliance role. The candidate is, however, expected to bring a practical risk-review mindset able to look at the environment, identify gaps, and recommend improvements that add tangible value, without taking on formal governance deliverables.
Key Responsibilities
2.1 Network Security (Hands-On Core Depth Required)
Example platforms: Palo Alto NGFW, Panorama, GlobalProtect, Prisma Access, Darktrace, Gigamon (or equivalent).
Own, administer, and troubleshoot the organization's next-generation firewall estate end-to-end policy management, centralized management console administration, remote access VPN, and SASE/cloud-delivered access.
Execute and provide final technical sign-off on firewall rule changes, certificate lifecycle management, OS/firmware upgrades and CVE patching, high-availability failover, and network segmentation/zone architecture.
Own network detection and response operations reviewing, validating, and acting on NDR platform alerts, including autonomous containment actions and outbound threat investigation.
Operate network traffic visibility tooling to support traffic inspection, SPAN/TAP architecture, and incident investigation.
Independently diagnose and resolve complex network security incidents without requiring escalation on standard issue types.
Network Access Control (NAC) Hands-On, Full Solutioning
Example platform: Forescout or Cisco ISE or Aruba Clear Pass (or equivalent NAC platform).
Own end-to-end NAC solution design and operation device detection and classification, policy enforcement, listing workflows, and remediation of non-corporate/non-compliant endpoints.
Identify recurring NAC alert patterns and drive tuning, policy refinement, or automation improvements rather than absorbing repetitive manual triage.
Email Security Hands-On
Example platform: Proofpoint (or equivalent email security gateway).
Lead triage, investigation, and remediation of email-borne threats phishing, malware, spoofing including message quarantine and release workflows.
Maintain working familiarity with complementary email authentication controls (e.g., DMARC/DKIM/SPF enforcement tooling) sufficient to assess and improve overall email domain posture.
Endpoint Security (Conceptual Knowledge)
Example platforms: CrowdStrike Falcon, Microsoft Defender for Endpoint (or equivalent).
Maintain solid conceptual understanding of modern EDR/XDR principles sufficient to interpret endpoint-related findings, understand their relevance to network and NAC incidents, and communicate credibly with the engineers who own this domain.
Data Loss Prevention / Data Protection (Conceptual Knowledge)
Example platforms: Palo Alto DLP, Microsoft Purview (or equivalent).
Maintain conceptual understanding of DLP principles and common tooling approaches sufficient to recognize data-exposure risk surfaced through network or email findings and recommend appropriate escalation.
Cloud Security (Conceptual Knowledge, Value-Add)
Example platforms: Wiz, Prisma Cloud (or equivalent).
Maintain conceptual awareness of cloud security posture management principles to connect network-exposed cloud misconfigurations back to perimeter and NAC risk. Treated as a value-add rather than a baseline expectation.
SIEM / Detection Support (Conceptual Knowledge)
Example platform: Splunk (or equivalent).
Maintain working familiarity with SIEM-based alert triage and correlation concepts sufficient to interpret alerts relevant to network and NAC domains and route them appropriately.
Value Creation & Security Landscape Thinking
Proactively review the environment's security posture and tooling effectiveness, surfacing practical, risk-informed recommendations grounded in pattern recognition across tickets, alerts, and recurring issues not formal governance deliverables.
Provide the broader engineering team with informed, impactful technical input on tuning, escalation handling, and process improvement that measurably improves operational quality.
Coverage Model
Primary coverage: AMER business hours, from 9:00 AM ET.
Maintains ongoing visibility into offshore team activity and open items to ensure continuity of judgment and consistent escalation handling across the full day.
Acts as the real-time point of technical reference during AMER hours for issues requiring senior-level judgment.
Required Qualifications
Category | Requirement |
Experience | 10 15 years of Network Security Engineering / Cybersecurity Platform experience |
Tenure & Track Record | Demonstrated tenure operating at a senior (L3) level independently handling the most complex escalations in core domains without requiring guidance on standard issue types |
Network Security | Deep, hands-on experience with enterprise next-generation firewall platforms, centralized policy management, VPN/SASE access, network detection & response, and network traffic visibility tooling (e.g., Palo Alto NGFW/Panorama/GlobalProtect/Prisma Access, Darktrace, Gigamon, or equivalent) |
NAC | Hands-on experience designing and operating NAC solutions end-to-end (e.g., Forescout, or equivalent) |
Email Security | Hands-on experience with email security gateway platforms and threat remediation workflows (e.g., Proofpoint, or equivalent) |
Endpoint Security | Solid conceptual knowledge of EDR/XDR principles and common platforms (e.g., CrowdStrike, Microsoft Defender for Endpoint) |
DLP | Conceptual understanding of data loss prevention principles and common approaches (e.g., Palo Alto DLP, Microsoft Purview) |
SIEM | Working familiarity with SIEM-based triage and correlation concepts (e.g., Splunk) |
Work Model | Comfortable working fixed AMER business hours (from 9:00 AM ET) while maintaining real-time visibility into offshore team activity; no shift rotation required |
Preferred / Value-Add Qualifications
Conceptual or working exposure to cloud security posture management tooling (e.g., Wiz, Prisma Cloud).
Prior experience operating in a managed SOC co-sourced delivery environment with blended onshore/offshore teams.
Explicitly Out of Scope
Formal GRC/compliance ownership risk register maintenance, formal control-efficacy reporting, and audit deliverables sit outside this role. The candidate is expected to bring risk-aware thinking to daily operations, not own governance documentation.
Leadership Expectation (Operational, Not Managerial)
While this is not a formal team lead position, the candidate must be comfortable maintaining oversight of the offshore team's activity in real time, providing timely technical direction when offshore engineers need senior input, and keeping a consistent, hands-on handle on daily operations across the full day ensuring nothing material is dropped between the offshore and onshore windows.
Similar jobs
- KT
Senior Cybersecurity Architect
NewKforce Technology Staffing
Juno Beach, FL🇺🇸Hybrid19 hours agoAWSEncryptionMFA+6Technology - OG
Security Analyst
NewOn-Demand Group
Minneapolis, MN🇺🇸$35 - $43/hrOn-site19 hours agoPythonPowerShellAWS+4Technology - MI
Principal Cyber Threat Intelligence Analyst with Security Clearance
MITRE Corporation
McLean, VA🇺🇸$172.8k - $216k/yrOn-site5 weeks agoTechnology - LE
Information Systems Security Manager (ISSM) with Security Clearance
NewLeidos
Huntsville, AL🇺🇸$107.9k - $195.1k/yrOn-site19 hours agoPenetration TestingTechnology - SA
Information System Security Engineer with Security Clearance
NewSAIC
Panama City Beach, FL🇺🇸On-site19 hours agoTechnology - HM
Security Coordinator - (Industrial Security Analyst 2) with Security Clearance
NewHII Mission Technologies
Key West, FL🇺🇸$57.7k - $80k/yrHybrid19 hours agoMachine LearningMicrosoft OfficeTechnology