Why This Role Stands Out
This role offers a fantastic opportunity to shape the future of network security within a leading technology company, leveraging your expertise in microsegmentation to drive innovative Zero Trust strategies. You'll thrive here if you're a seasoned network security professional eager to architect and implement advanced solutions that significantly enhance global security posture. Apply now to make a significant impact and advance your career in a dynamic environment.
Quick Overview
Job Description
Role: Senior Network Security Engineer (Microsegmentation)
Location: Houston, TX (Onsite).
Note: Microsegmentation experience is a must.
Client is an innovative, dynamic company with a rich past and promising future. Originally Client has continuously reinvented itself. Today, Client is one of the world''s leading technology companies and provides wired and wireless networking, servers, storage, IT and Cloud services, and software solutions for the next generation of IT infrastructure.
Key Responsibilities
· Translate high-level business strategic objectives and goals into Enterprise IT requirements and conceptual designs.
· Develop and support comprehensive solutions that meet requirements and align with Client’s global network security and microsegmentation strategy.
· Develop and maintain a multi-year strategic network and security architecture roadmap, incorporating Zero Trust and segmentation-driven security models.
· Lead end-to-end network and security architecture across global platforms ensuring secure, high-performing, fault-tolerant, and resilient environments.
Microsegmentation & Zero Trust Responsibilities
· Architect and implement microsegmentation strategies across data center, campus, and cloud environments to limit lateral movement and enforce least-privilege access.
· Design and operationalize Zero Trust Architecture (ZTA) principles, integrating identity, application, and network-based policy enforcement.
· Collaborate with application owners to discover, validate, and map application dependencies to enable policy-driven segmentation.
· Define and enforce granular security policies using label/tag-based segmentation approaches across hybrid environments.
· Integrate microsegmentation with firewalls, SIEM, IAM, EDR/XDR, and cloud-native controls for unified policy enforcement.
· Lead adoption of microsegmentation platforms (e.g, Guardicore/Akamai Segmentation).
· Develop segmentation governance models, policy lifecycle management, and compliance alignment (CIS/NIST/Zero Trust frameworks).
Core Network Security Responsibilities
· Participate in network security design reviews and ensure all implementations meet enterprise security standards.
· Analyze business requirements to design and implement security across data centers, campus networks, and hybrid environments.
· Provide ongoing risk metrics, control effectiveness tracking, and security posture reporting.
· Conduct and support internal and external security audits and compliance assessments.
· Maintain awareness of emerging threats and update policies accordingly.
· Develop and manage policies, processes, and procedures ensuring reliability, availability, and security of network systems.
· Manage and optimize Security Information and Event Management (SIEM) systems.
· Collaborate with Cyber Security, infrastructure, and application teams toward compliance and operational excellence.
Technical Qualifications
· 10+ years of experience in enterprise network security architecture, engineering, and operations.
Microsegmentation & Advanced Security
· Strong hands-on experience in designing and implementing microsegmentation solutions in complex enterprise environments.
· Proven capability to build application-aware segmentation policies based on traffic flow analysis.
· Experience with policy simulation, enforcement, monitoring, and optimization in segmentation platforms.
· Understanding of east-west traffic inspection, workload protection, and software-defined segmentation.
· Familiarity with Zero Trust Network Access (ZTNA) and identity-driven access models.
Network Security & Infrastructure
· Strong experience managing LAN/WAN security technologies, including firewalls, IDS/IPS, SIEM, VPN, and NAC.
· Expertise in firewall architecture and design with hands-on experience in:
o Fortinet (Fortigate), Palo Alto, Juniper
o Policy design, NAT, routing, application control, and threat prevention profiles
· Experience securing public and private cloud (AWS, Azure, Google Cloud Platform) environments.
· Design and implementation of Web Application and API Protection (WAAP) solutions.
· Strong experience in proxy (forward/reverse), load balancing, and application security integration.
· Experience with SDN and SD-WAN architectures, including segmentation use cases.
Networking & Protocol Expertise
· Strong knowledge of:
o Routing protocols: BGP, OSPF, RIP, MPLS
o Network services: DNS, DHCP, NTP
o IPv4/IPv6 architecture and traffic management
· Experience in QoS, NetFlow, ACLs, NAT, multicast, and wireless technologies (802.11 variants).
· Experience with F5 GTM/LTM, VPN technologies, and Internet proxy solutions.
Data Center & Infrastructure
· Experience managing enterprise data center environments with technologies including:
o Aruba, Arista, Juniper switching
o Firewalls, WAN optimization, IDS/IPS, DLP
· Strong understanding of structured cabling and network facilities.
Operations & Lifecycle Management
· Plan, implement, and document infrastructure changes, including upgrades and migrations.
· Work within ITIL frameworks for incident, change, and problem management.
Education & Certifications
· Bachelor’s Degree in Computer Science, Network Engineering, or related field (or equivalent experience).
· 10+ years of experience in global network security environments.
· Preferred certifications:
o CCNP / CCIE
o JNCIE
o Security certifications (CISSP, CISM, or equivalent) are a plus
Key Differentiators Added (for your context)
This version strengthens the JD by:
· Embedding microsegmentation as a core capability (not just one bullet)
· Aligning with Zero Trust and application dependency mapping (important for your programs)
· Emphasizing cross-team collaboration with application owners (critical for rollout success)
· Integrating segmentation with existing firewall + SIEM ecosystem (not replacing, but complementing)
Similar jobs
- DD
Cybersecurity Engineer
NewDelta Defense
West Bend, Wisconsin🇺🇸Hybrid8 minutes agoTechnology - QU
Senior Cybersecurity Engineer - 930
Quantinuum
US Broomfield🇺🇸$112k - $140k/yrOn-site5 days agoTechnology - QU
Principal Security Specialist - 939
Quantinuum
US Broomfield🇺🇸$160k - $200k/yrOn-site1 week agoContinuous ImprovementRisk Management - CI
Senior Information Security Analyst / Engineer
Cirrus
Austin🇺🇸Hybrid2 weeks agoTechnology - ZS
Practice Architect - Data Security
NewZscaler
USA - Update Location🇺🇸YesterdayPCI DSSAgileCustomer Success+7 - ZS
Threat Response Engineer (TRE) - Day Shift (10am-6pm MT)
Zscaler
USA - Update Location🇺🇸6 days agoAgileArticulateEEOC+4Engineering