Network_Security_Techinical_Lead
Malomatia- Location
- Doha, Qatar
- Workplace
- —
- Employment
- Full Time
- Salary
- —
Posted 3d ago
Own the end-to-end architecture, design, deployment, and 24/7 operational management of secure network and security infrastructure across cloud (Azure, GCP, OCI) and on-premises environments — spanning routing, switching, and cybersecurity engineering. Act as the technical authority responsible for designing highly available, resilient architectures; leading deployment and configuration of new environments; and operating the infrastructure around the clock to ensure it remains stable, secure, and audit-ready. Skilled in preparing operational reports and presentations, running operational meetings, handling escalations, and managing major changes — while retaining hands-on accountability for daily operations.
- Design secure reference architectures for hub-spoke topologies, VNet/VPC/VCN environments, subnetting, IP/CIDR planning, and static/BGP dynamic routing across Azure, GCP, and OCI, as well as on-prem routing and switching infrastructure.
- Architect secure connectivity patterns — VPN, peering, and dedicated interconnects (ExpressRoute, Interconnect, FastConnect) — and lead network security design reviews with actionable, best-practice recommendations.
- Lead deployment and configuration of network security environments: Site-to-Site VPNs with redundant tunnels and BGP routing, VPC/VCN peering, NSGs, security lists/ACLs, NVAs, next-gen firewalls, and Internet/NAT/Service Gateways for new builds and migrations.
- Design, deploy, and operate infrastructure to meet 24/7 availability targets, including redundancy, failover, load balancing, and disaster recovery across hybrid and multi-cloud environments.
- Own round-the-clock operational management of the network and security environment: change management, patching/upgrades of NVAs, vulnerability tracking and remediation, and coordination of patch windows and incident response.
- Manage and oversee day-to-day network and security operations across routing, switching, and cybersecurity engineering, keeping leadership informed of status, risks, and escalations.
- Configure and maintain monitoring, logging, and diagnostics (Azure Monitor, GCP Cloud Monitoring, OCI Monitoring, flow logs) to proactively detect and resolve availability, performance, and security issues.
- Harden network device and cloud configurations against industry benchmarks (e.g., CIS, NIST) and internal security baselines; remediate findings from internal/external audits.
- Prepare and present operational reports, dashboards, and presentations summarizing network/security performance, availability, incidents, and risk posture to leadership and stakeholders.
- Plan and run operational meetings — daily/weekly stand-ups, service reviews, and incident review sessions — driving action items to closure.
- Act as the senior escalation point for critical operational and security issues across all managed platforms, ensuring timely resolution and clear communication.
- Own and handle major changes end-to-end — planning, risk assessment, change advisory board (CAB) submissions, implementation, and post-change validation — with minimal impact to 24/7 availability.
- Design, deploy, and validate backup and restore procedures for NVAs, firewall policies, and network configuration state; own disaster recovery and cross-region DR networking design.
- Coordinate cross-functional activities with cloud, security, application, and operations teams to ensure consistent security posture and always-on availability across the environment.
- Maintain accurate architecture documentation, network diagrams, runbooks, and operational procedures; ensure changes follow proper governance, risk, and change-control processes.
- Mentor engineers and act as a point of technical escalation for complex operational or security issues.
- Participate in an on-call rotation and respond to critical incidents outside business hours to maintain 24/7 availability; travel to datacenter or client sites as needed.
- 10–12 years of experience in cloud infrastructure, network operations, and cybersecurity engineering, including hands-on ownership of designing, deploying, and operating secure network infrastructure.
- Demonstrable depth across at least two of Microsoft Azure, Google Cloud Platform, and Oracle Cloud Infrastructure (all three strongly preferred).
- Proven experience designing and operating infrastructure to meet 24/7 availability, redundancy, and disaster recovery requirements.
- Demonstrated experience overseeing or coordinating multi-disciplinary operations (network + security) and reporting outcomes to leadership.
- Strong skills in preparing operational reports, dashboards, and presentations for leadership and stakeholder audiences.
- Proven track record running operational meetings and driving structured escalation handling to resolution.
- Hands-on experience managing major changes, including change planning, risk assessment, CAB processes, and post-implementation review.
- Hands-on expertise with enterprise routers, switches, firewalls, NVAs, and cloud-native network security monitoring tools.
- Experience hardening network and cloud infrastructure against security frameworks and remediating audit findings.
- Strong troubleshooting and incident-response experience across routing, switching, cloud networking, and security domains.
- Excellent coordination and communication skills, with the ability to work closely with leadership and cross-functional stakeholders.
- Willing and able to participate in an on-call rotation and travel to datacenter/client sites as needed to maintain 24/7 availability.
Required Certifications
- Cisco CCNP (Enterprise / Security) or equivalent vendor-neutral routing & switching certification.
- Microsoft Certified: Azure Network Security Engineer Associate (or Azure Solutions Architect Expert).
- Google Professional Cloud Network Engineer / Cloud Security Engineer.
- Oracle Cloud Infrastructure (OCI) Network Security Professional or Architect Professional.
- CISSP (Certified Information Systems Security Professional) or working toward certification.
- Firewall/NGFW vendor certification (e.g., Palo Alto PCNSA/PCNSE, Fortinet NSE, or Check Point CCSA/CCSE).
Preferred
CCIE, CISM, CEH. At least two of Azure, GCP, and OCI required; all three strongly preferred. Certifications must be current; equivalent recognized credentials considered subject to approval.
Skills
- Azure
- GCP
- OCI
- VPC
- BGP
- VPN
- Azure Monitor
- Cloud Monitoring
- NIST
- Oracle Cloud
- Cisco
- CISSP
More jobs at Malomatia
All 55Senior Engineer - Linux
Malomatia · Doha, Qatar · yesterday
Senior Engineer - Java and Microservice Development
Malomatia · Doha, Qatar · yesterday
Senior Consultant-Program Management
Malomatia · Doha, Qatar · yesterday
Cloud Security Engineer
Malomatia · Doha, Qatar · yesterday
Cloud Security Consultant
Malomatia · Doha, Qatar · yesterday