Security Engineer - L2
Job Description
How to read:
The job description below should be read in conjunction with the purpose of the job family.
Job Title: Assistant Manager â Job Family
<Insert Job Family definition here>
Job Purpose:
This role involves executing projects efficiently, ensuring deadlines and quality standards are met. The role holder ensures seamless execution of operations in assigned function by completion of their tasks. They assist their supervisors in managerial tasks. While this role is largely an individual contributor role, in some cases they may lead a small team. The role holder should be able to collaborate with other teams and proactively identify and resolve issues in their span of work.
͏
Job Duties and Responsibilities:
- Operate independently under general supervision, making decisions based on defined guidelines and practices.
- Work with teams across functions to deliver on specific project deliverables or achieve outcomes in their span of work
- Work with external stakeholders (ex: vendors) to deliver in their area of work,
- Create plans and drive their execution to ensure deliverables are met in their span of work
- Assist supervisor in completion of managerial tasks & responsibilities.
- Oversee operations to guarantee adherence to policies, procedures, and internal controls.
- Identify opportunities for process improvements and contribute ideas for enhancing efficiency.
- Address and resolve issues within a, sub process, or constituent group.
- Mentor team members, in case the role holder is managing a team.
- Exhibit full professional competency in their area of work - using acquired job skills, policies, and procedures to complete moderately difficult assignments/projects/tasks
͏
͏
͏
Responsibilities
- Solution Deployment: Lead the installation, configuration, and migration of core security technologies (NGFWs, WAFs, and Proxies).
- Policy Hardening: Design and implement granular security policies, including firewall rules, SSL inspection, and URL filtering, following the principle of least privilege.
- VPN & Connectivity: Configure and troubleshoot complex VPN tunnels (Site-to-Site, Remote Access SSL VPN) and SD-WAN security integrations.
- Infrastructure Integration: Integrate security solutions with existing directory services (AD/LDAP/SAML) for Identity and Access Management (IAM).
- Vulnerability Remediation: Work with the vulnerability management team to implement technical fixes and patches across security appliances.
- Project Handover: Create comprehensive technical documentation, including High-Level (HLD) and Low-Level Designs (LLD), and provide knowledge transfer to the L1/L2 Operations team.
Technical Skills Required
- Firewall Expertise: Advanced configuration skills in at least two major vendors (e.g., Palo Alto or Check Point CCSA).
- Network Security: Strong understanding of the OSI model, particularly L4–L7 security, NAT, Routing (BGP/OSPF), and Switching.
- SASE/Cloud Proxy: Experience deploying Zero Trust solutions like Zscaler (ZIA/ZPA), Cisco Umbrella, or Prisma Access.
- EDR/XDR Setup: Hands-on experience with the deployment and policy tuning of CrowdStrike, SentinelOne, or Microsoft Defender for Endpoint.
- Automation: Basic proficiency in Python or Ansible for automating repetitive configuration tasks.
Experience & Certifications
- Experience: 7-10 years in IT Security, with a minimum of 2 years focused specifically on project-based implementation or deployments.
- Top Certifications (Preferred):
- Palo Alto Networks Certified Network Security Engineer (PCNSE)
- CCSE - (Checkpoint Certified Security Expert )
- Cisco Certified Professional (CCNP Security)
Soft Skills
- Critical Thinking: Ability to anticipate how a new security implementation might impact existing network traffic.
- Ownership: Capability to manage a deployment project from the "Initial Setup" phase to the "Operational Handover."
- Detail-Oriented: Precision in documenting rule changes and configuration backups.