Job Title: Network Security Team Lead
Location: New York City
Work Model: In-office (5 days per week)
Experience: 5-7 years
Key Responsibilities
• Lead and mentor a team of network security engineers, providing technical direction, performance guidance, and career development support
• Serve as the lead engineer and architect for network security solutions, including:
Network and micro-segmentation
Firewalls and next-generation firewall platforms
VPN and SASE technologies
Web application protection
Network Detection and Response (NDR)
Network Access Control (NAC)
Browser isolation and centralized policy management
• Design, configure, and manage advanced security configurations for next-generation firewalls across local and global environments
• Ensure compliance with regulatory and industry standards such as PCI DSS, HIPAA, and GDPR through policy development, controls implementation, and regular audits
• Configure, maintain, and optimize network security platforms including firewalls, IDS, and IPS, ensuring alignment with industry best practices
• Partner with infrastructure, cloud, and application teams to securely integrate cloud environments (AWS, Azure, GCP), implementing access controls, encryption, and segmentation strategies
• Develop and enforce network segmentation and zero-trust architectures to minimize lateral movement and reduce attack surfaces
• Conduct security risk assessments, vulnerability analysis, and penetration testing; recommend and implement remediation plans
• Oversee vulnerability management initiatives and continuous improvement programs
• Develop training materials and deliver regular security awareness and best-practice training for internal stakeholders
Required Qualifications
• Bachelor’s degree in Computer Science, Information Security, or a related field
• 5–7 years of hands-on network security experience in a highly regulated environment
• Proven experience leading or managing security engineering teams
• Strong leadership mindset with a passion for mentoring and developing talent
Technical Expertise
• Deep expertise in network and security technologies, including:
• Palo Alto Networks firewalls (User-ID, App-ID, IDS/IPS)
• Web Application Firewalls (WAF) and DDoS protection
• Network Access Control (NAC)
• Strong experience with network segmentation and zero-trust platforms, such as:
• Illumio, Guardicore, VMware NSX/NSX-T, vArmour, Cisco ACI, ShieldX, Unisys Stealth, Zero Networks
• Hands-on experience with SASE and CASB solutions (Prisma Access, Zscaler, Netskope)
• Experience managing NDR platforms such as Darktrace, ExtraHop, or Vectra
• Solid understanding of cloud networking in AWS, Azure, and/or GCP
Certifications (Preferred)
• CISSP
• CCNA / CCNP (Routing & Switching or Security)
• Palo Alto Networks (PCSNE)
• Security+