Haystack
← Back to Jobs
Technology
RS

Sr Network Security Engineer L3

Reliancesoft Systems IncNew York, NY🇺🇸United StatesPosted Oct 7, 2026

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
New York, NY, United States
Posted
19 hours ago
SplunkPrisma

Job Description

Job Description

Job Title: Network Security Engineer L3

Location: New York, NY (Onsite)

Department: Cybersecurity Operations (SecOps)

Reports To: Cybersecurity Operations Lead

Employment Type:

Level: L3 Senior Individual Contributor

Position Summary

Client is seeking a senior Network Security Engineer (L3) with deep, hands-on expertise in network security (including network detection & response and network traffic visibility), network access control (NAC), and email security, complemented by sound conceptual knowledge across the broader cybersecurity landscape endpoint security, data loss prevention, cloud security, and SIEM. This is a senior, high-judgment individual contributor role: the candidate is expected to independently resolve the most complex escalations in their core domains, exercise good technical judgment across adjacent domains, and bring a genuine security engineering mindset rather than simply executing runbooks. The candidate will cover AMER business hours (from 9:00 AM ET) and maintain visibility into offshore team activity to ensure continuity of judgment across the day.

This is not a GRC or compliance role. The candidate is, however, expected to bring a practical risk-review mindset able to look at the environment, identify gaps, and recommend improvements that add tangible value, without taking on formal governance deliverables.

Key Responsibilities

2.1 Network Security (Hands-On Core Depth Required)

Example platforms: Palo Alto NGFW, Panorama, GlobalProtect, Prisma Access, Darktrace, Gigamon (or equivalent).

Own, administer, and troubleshoot the organization's next-generation firewall estate end-to-end policy management, centralized management console administration, remote access VPN, and SASE/cloud-delivered access.

Execute and provide final technical sign-off on firewall rule changes, certificate lifecycle management, OS/firmware upgrades and CVE patching, high-availability failover, and network segmentation/zone architecture.

Own network detection and response operations reviewing, validating, and acting on NDR platform alerts, including autonomous containment actions and outbound threat investigation.

Operate network traffic visibility tooling to support traffic inspection, SPAN/TAP architecture, and incident investigation.

Independently diagnose and resolve complex network security incidents without requiring escalation on standard issue types.

Network Access Control (NAC) Hands-On, Full Solutioning

Example platform: Forescout or Cisco ISE or Aruba Clear Pass (or equivalent NAC platform).

Own end-to-end NAC solution design and operation device detection and classification, policy enforcement, listing workflows, and remediation of non-corporate/non-compliant endpoints.

Identify recurring NAC alert patterns and drive tuning, policy refinement, or automation improvements rather than absorbing repetitive manual triage.

Email Security Hands-On

Example platform: Proofpoint (or equivalent email security gateway).

Lead triage, investigation, and remediation of email-borne threats phishing, malware, spoofing including message quarantine and release workflows.

Maintain working familiarity with complementary email authentication controls (e.g., DMARC/DKIM/SPF enforcement tooling) sufficient to assess and improve overall email domain posture.

Endpoint Security (Conceptual Knowledge)

Example platforms: CrowdStrike Falcon, Microsoft Defender for Endpoint (or equivalent).

Maintain solid conceptual understanding of modern EDR/XDR principles sufficient to interpret endpoint-related findings, understand their relevance to network and NAC incidents, and communicate credibly with the engineers who own this domain.

Data Loss Prevention / Data Protection (Conceptual Knowledge)

Example platforms: Palo Alto DLP, Microsoft Purview (or equivalent).

Maintain conceptual understanding of DLP principles and common tooling approaches sufficient to recognize data-exposure risk surfaced through network or email findings and recommend appropriate escalation.

Cloud Security (Conceptual Knowledge, Value-Add)

Example platforms: Wiz, Prisma Cloud (or equivalent).

Maintain conceptual awareness of cloud security posture management principles to connect network-exposed cloud misconfigurations back to perimeter and NAC risk. Treated as a value-add rather than a baseline expectation.

SIEM / Detection Support (Conceptual Knowledge)

Example platform: Splunk (or equivalent).

Maintain working familiarity with SIEM-based alert triage and correlation concepts sufficient to interpret alerts relevant to network and NAC domains and route them appropriately.

Value Creation & Security Landscape Thinking

Proactively review the environment's security posture and tooling effectiveness, surfacing practical, risk-informed recommendations grounded in pattern recognition across tickets, alerts, and recurring issues not formal governance deliverables.

Provide the broader engineering team with informed, impactful technical input on tuning, escalation handling, and process improvement that measurably improves operational quality.

Coverage Model

Primary coverage: AMER business hours, from 9:00 AM ET.

Maintains ongoing visibility into offshore team activity and open items to ensure continuity of judgment and consistent escalation handling across the full day.

Acts as the real-time point of technical reference during AMER hours for issues requiring senior-level judgment.

Required Qualifications

Category

Requirement

Experience

10 15 years of Network Security Engineering / Cybersecurity Platform experience

Tenure & Track Record

Demonstrated tenure operating at a senior (L3) level independently handling the most complex escalations in core domains without requiring guidance on standard issue types

Network Security

Deep, hands-on experience with enterprise next-generation firewall platforms, centralized policy management, VPN/SASE access, network detection & response, and network traffic visibility tooling (e.g., Palo Alto NGFW/Panorama/GlobalProtect/Prisma Access, Darktrace, Gigamon, or equivalent)

NAC

Hands-on experience designing and operating NAC solutions end-to-end (e.g., Forescout, or equivalent)

Email Security

Hands-on experience with email security gateway platforms and threat remediation workflows (e.g., Proofpoint, or equivalent)

Endpoint Security

Solid conceptual knowledge of EDR/XDR principles and common platforms (e.g., CrowdStrike, Microsoft Defender for Endpoint)

DLP

Conceptual understanding of data loss prevention principles and common approaches (e.g., Palo Alto DLP, Microsoft Purview)

SIEM

Working familiarity with SIEM-based triage and correlation concepts (e.g., Splunk)

Work Model

Comfortable working fixed AMER business hours (from 9:00 AM ET) while maintaining real-time visibility into offshore team activity; no shift rotation required

Preferred / Value-Add Qualifications

Conceptual or working exposure to cloud security posture management tooling (e.g., Wiz, Prisma Cloud).

Prior experience operating in a managed SOC co-sourced delivery environment with blended onshore/offshore teams.

Explicitly Out of Scope

Formal GRC/compliance ownership risk register maintenance, formal control-efficacy reporting, and audit deliverables sit outside this role. The candidate is expected to bring risk-aware thinking to daily operations, not own governance documentation.

Leadership Expectation (Operational, Not Managerial)

While this is not a formal team lead position, the candidate must be comfortable maintaining oversight of the offshore team's activity in real time, providing timely technical direction when offshore engineers need senior input, and keeping a consistent, hands-on handle on daily operations across the full day ensuring nothing material is dropped between the offshore and onshore windows.

Similar jobs