Quick Overview
Job Description
Job Title: Network Security Engineer L3
Location: New York, NY - Hybrid
Mode of Hire: Contract
Job Description:
Department: Cybersecurity Operations (SecOps)
Reports To: Cybersecurity Operations Lead
1. Position Summary
Client is seeking a senior Network Security Engineer (L3) with deep, hands-on expertise in network security (including network detection & response and network traffic visibility), network access control (NAC), and email security, complemented by sound conceptual knowledge across the broader cybersecurity landscape - endpoint security, data loss prevention, cloud security, and SIEM. This is a senior, high-judgment individual contributor role: the candidate is expected to independently resolve the most complex escalations in their core domains, exercise good technical judgment across adjacent domains, and bring a genuine security engineering mindset rather than simply executing runbooks. The candidate will cover AMER business hours (from 9:00 AM ET) and maintain visibility into offshore team activity to ensure continuity of judgment across the day.
This is not a GRC or compliance role. The candidate is, however, expected to bring a practical risk-review mindset - able to look at the environment, identify gaps, and recommend improvements that add tangible value, without taking on formal governance deliverables.
2. Key Responsibilities:
2.1 Network Security (Hands-On - Core Depth Required)
Example platforms: Palo Alto NGFW, Panorama, Global Protect, Prisma Access, Darktrace, Gigamon (or equivalent).
Own, administer, and troubleshoot the organization's next-generation firewall estate end-to-end - policy management, centralized management console administration, remote access VPN, and SASE/cloud-delivered access.
Execute and provide final technical sign-off on firewall rule changes, certificate lifecycle management, OS/firmware upgrades and CVE patching, high-availability failover, and network segmentation/zone architecture.
Own network detection and response operations - reviewing, validating, and acting on NDR platform alerts, including autonomous containment actions and outbound threat investigation.
Operate network traffic visibility tooling to support traffic inspection, SPAN/TAP architecture, and incident investigation.
Independently diagnose and resolve complex network security incidents without requiring escalation on standard issue types.
2.2 Network Access Control (NAC) - Hands-On, Full Solutioning
Example platform: Forescout or Cisco ISE or Aruba Clear Pass (or equivalent NAC platform).
Own end-to-end NAC solution design and operation - device detection and classification, policy enforcement, listing workflows, and remediation of non-corporate/non-compliant endpoints.
Identify recurring NAC alert patterns and drive tuning, policy refinement, or automation improvements rather than absorbing repetitive manual triage.
2.3 Email Security - Hands-On
Example platform: Proofpoint (or equivalent email security gateway).
Lead triage, investigation, and remediation of email-borne threats - phishing, malware, spoofing - including message quarantine and release workflows.
Maintain working familiarity with complementary email authentication controls (e.g., DMARC/DKIM/SPF enforcement tooling) sufficient to assess and improve overall email domain posture.
2.4 Endpoint Security (Conceptual Knowledge)
Example platforms: CrowdStrike Falcon, Microsoft Defender for Endpoint (or equivalent).
Maintain solid conceptual understanding of modern EDR/XDR principles - sufficient to interpret endpoint-related findings, understand their relevance to network and NAC incidents, and communicate credibly with the engineers who own this domain.
2.5 Data Loss Prevention / Data Protection (Conceptual Knowledge)
Example platforms: Palo Alto DLP, Microsoft Purview (or equivalent).
Maintain conceptual understanding of DLP principles and common tooling approaches sufficient to recognize data-exposure risk surfaced through network or email findings and recommend appropriate escalation.
2.6 Cloud Security (Conceptual Knowledge, Value-Add)
Example platforms: Wiz, Prisma Cloud (or equivalent).
Maintain conceptual awareness of cloud security posture management principles to connect network-exposed cloud misconfigurations back to perimeter and NAC risk. Treated as a value-add rather than a baseline expectation.
2.7 SIEM / Detection Support (Conceptual Knowledge)
Example platform: Splunk (or equivalent).
Maintain working familiarity with SIEM-based alert triage and correlation concepts sufficient to interpret alerts relevant to network and NAC domains and route them appropriately.
2.8 Value Creation & Security Landscape Thinking
Proactively review the environment's security posture and tooling effectiveness, surfacing practical, risk-informed recommendations grounded in pattern recognition across tickets, alerts, and recurring issues - not formal governance deliverables.
Provide the broader engineering team with informed, impactful technical input on tuning, escalation handling, and process improvement that measurably improves operational quality.
3. Coverage Model
Primary coverage: AMER business hours, from 9:00 AM ET.
Maintains ongoing visibility into offshore team activity and open items to ensure continuity of judgment and consistent escalation handling across the full day.
Acts as the real-time point of technical reference during AMER hours for issues requiring senior-level judgment.
4. Required Qualifications:
| Category | Requirement |
| Experience | 10 15 years of Network Security Engineering / Cybersecurity Platform experience |
| Tenure & Track Record | Demonstrated tenure operating at a senior (L3) level - independently handling the most complex escalations in core domains without requiring guidance on standard issue types |
| Network Security | Deep, hands-on experience with enterprise next-generation firewall platforms, centralized policy management, VPN/SASE access, network detection & response, and network traffic visibility tooling (e.g., Palo Alto NGFW/Panorama/GlobalProtect/Prisma Access, Darktrace, Gigamon, or equivalent) |
| NAC | Hands-on experience designing and operating NAC solutions end-to-end (e.g., Forescout, or equivalent) |
| Email Security | Hands-on experience with email security gateway platforms and threat remediation workflows (e.g., Proofpoint, or equivalent) |
| Endpoint Security | Solid conceptual knowledge of EDR/XDR principles and common platforms (e.g., CrowdStrike, Microsoft Defender for Endpoint) |
| DLP | Conceptual understanding of data loss prevention principles and common approaches (e.g., Palo Alto DLP, Microsoft Purview) |
| SIEM | Working familiarity with SIEM-based triage and correlation concepts (e.g., Splunk) |
| Work Model | Comfortable working fixed AMER business hours (from 9:00 AM ET) while maintaining real-time visibility into offshore team activity; no shift rotation require |
5. Preferred / Value-Add Qualifications
Conceptual or working exposure to cloud security posture management tooling (e.g., Wiz, Prisma Cloud).
Prior experience operating in a managed SOC co-sourced delivery environment with blended onshore/offshore teams.
6. Explicitly Out of Scope
Formal GRC/compliance ownership - risk register maintenance, formal control-efficacy reporting, and audit deliverables sit outside this role. The candidate is expected to bring risk-aware thinking to daily operations, not own governance documentation.
7. Leadership Expectation (Operational, Not Managerial)
While this is not a formal team lead position, the candidate must be comfortable maintaining oversight of the offshore team's activity in real time, providing timely technical direction when offshore engineers need senior input, and keeping a consistent, hands-on handle on daily operations across the full day - ensuring nothing material is dropped between the offshore and onshore windows.
PSRTEK is a reputed technology recruitment and IT staffing brand with a global footprint and an admired client base. As an ideas and innovation powerhouse with a culture of excellence, we bring remarkable expertise and deliver powerfully transformative results.
Similar jobs
- NC
Head of Dallas Expansion & Summer Camp Operations (STEM Enrichment)
NewNory Co
Dallas🇺🇸$100k - $130k/yrOn-site7 hours agoRoboticsComplianceOnboarding+3 - NC
Customer Happiness Representative (Remote, Seasonal, Part-Time)
NewNory Co
New York🇺🇸$20/hrRemote7 hours agoCustomer SuccessOutreach - NC
Summer Camp Site Director (Part-Time) - Lead NYC Premier STEM Camp
NewNory Co
New York🇺🇸Remote8 hours agoRoboticsREST - NC
School Break Day Camp Site Leader Ages 3–12 (Manhattan & Brooklyn)
NewNory Co
New York🇺🇸$20/hrOn-site8 hours agoRoboticsCompliance - NC
Summer Camp Site Director (Manhattan, Ages 3-12)
NewNory Co
New York🇺🇸$1.3k - $1.6k/moOn-site8 hours agoRoboticsCompliance - NC
After School Lead Counselor (Manhattan, Brooklyn)
NewNory Co
New York🇺🇸$39 - $52/hrOn-site8 hours ago