JobHabor

Network_Security_Techinical_Lead

Malomatia
Location
Doha, Qatar
Workplace
Employment
Full Time
Salary
Apply on the employer’s site

Posted 3d ago

Own the end-to-end architecture, design, deployment, and 24/7 operational management of secure network and security infrastructure across cloud (Azure, GCP, OCI) and on-premises environments — spanning routing, switching, and cybersecurity engineering. Act as the technical authority responsible for designing highly available, resilient architectures; leading deployment and configuration of new environments; and operating the infrastructure around the clock to ensure it remains stable, secure, and audit-ready. Skilled in preparing operational reports and presentations, running operational meetings, handling escalations, and managing major changes — while retaining hands-on accountability for daily operations.

  • Design secure reference architectures for hub-spoke topologies, VNet/VPC/VCN environments, subnetting, IP/CIDR planning, and static/BGP dynamic routing across Azure, GCP, and OCI, as well as on-prem routing and switching infrastructure.
  • Architect secure connectivity patterns — VPN, peering, and dedicated interconnects (ExpressRoute, Interconnect, FastConnect) — and lead network security design reviews with actionable, best-practice recommendations.
  • Lead deployment and configuration of network security environments: Site-to-Site VPNs with redundant tunnels and BGP routing, VPC/VCN peering, NSGs, security lists/ACLs, NVAs, next-gen firewalls, and Internet/NAT/Service Gateways for new builds and migrations.
  • Design, deploy, and operate infrastructure to meet 24/7 availability targets, including redundancy, failover, load balancing, and disaster recovery across hybrid and multi-cloud environments.
  • Own round-the-clock operational management of the network and security environment: change management, patching/upgrades of NVAs, vulnerability tracking and remediation, and coordination of patch windows and incident response.
  • Manage and oversee day-to-day network and security operations across routing, switching, and cybersecurity engineering, keeping leadership informed of status, risks, and escalations.
  • Configure and maintain monitoring, logging, and diagnostics (Azure Monitor, GCP Cloud Monitoring, OCI Monitoring, flow logs) to proactively detect and resolve availability, performance, and security issues.
  • Harden network device and cloud configurations against industry benchmarks (e.g., CIS, NIST) and internal security baselines; remediate findings from internal/external audits.
  • Prepare and present operational reports, dashboards, and presentations summarizing network/security performance, availability, incidents, and risk posture to leadership and stakeholders.
  • Plan and run operational meetings — daily/weekly stand-ups, service reviews, and incident review sessions — driving action items to closure.
  • Act as the senior escalation point for critical operational and security issues across all managed platforms, ensuring timely resolution and clear communication.
  • Own and handle major changes end-to-end — planning, risk assessment, change advisory board (CAB) submissions, implementation, and post-change validation — with minimal impact to 24/7 availability.
  • Design, deploy, and validate backup and restore procedures for NVAs, firewall policies, and network configuration state; own disaster recovery and cross-region DR networking design.
  • Coordinate cross-functional activities with cloud, security, application, and operations teams to ensure consistent security posture and always-on availability across the environment.
  • Maintain accurate architecture documentation, network diagrams, runbooks, and operational procedures; ensure changes follow proper governance, risk, and change-control processes.
  • Mentor engineers and act as a point of technical escalation for complex operational or security issues.
  • Participate in an on-call rotation and respond to critical incidents outside business hours to maintain 24/7 availability; travel to datacenter or client sites as needed.
  • 10–12 years of experience in cloud infrastructure, network operations, and cybersecurity engineering, including hands-on ownership of designing, deploying, and operating secure network infrastructure.
  • Demonstrable depth across at least two of Microsoft Azure, Google Cloud Platform, and Oracle Cloud Infrastructure (all three strongly preferred).
  • Proven experience designing and operating infrastructure to meet 24/7 availability, redundancy, and disaster recovery requirements.
  • Demonstrated experience overseeing or coordinating multi-disciplinary operations (network + security) and reporting outcomes to leadership.
  • Strong skills in preparing operational reports, dashboards, and presentations for leadership and stakeholder audiences.
  • Proven track record running operational meetings and driving structured escalation handling to resolution.
  • Hands-on experience managing major changes, including change planning, risk assessment, CAB processes, and post-implementation review.
  • Hands-on expertise with enterprise routers, switches, firewalls, NVAs, and cloud-native network security monitoring tools.
  • Experience hardening network and cloud infrastructure against security frameworks and remediating audit findings.
  • Strong troubleshooting and incident-response experience across routing, switching, cloud networking, and security domains.
  • Excellent coordination and communication skills, with the ability to work closely with leadership and cross-functional stakeholders.
  • Willing and able to participate in an on-call rotation and travel to datacenter/client sites as needed to maintain 24/7 availability.

Required Certifications

  • Cisco CCNP (Enterprise / Security) or equivalent vendor-neutral routing & switching certification.
  • Microsoft Certified: Azure Network Security Engineer Associate (or Azure Solutions Architect Expert).
  • Google Professional Cloud Network Engineer / Cloud Security Engineer.
  • Oracle Cloud Infrastructure (OCI) Network Security Professional or Architect Professional.
  • CISSP (Certified Information Systems Security Professional) or working toward certification.
  • Firewall/NGFW vendor certification (e.g., Palo Alto PCNSA/PCNSE, Fortinet NSE, or Check Point CCSA/CCSE).

Preferred

CCIE, CISM, CEH. At least two of Azure, GCP, and OCI required; all three strongly preferred. Certifications must be current; equivalent recognized credentials considered subject to approval.

Skills

  • Azure
  • GCP
  • OCI
  • VPC
  • BGP
  • VPN
  • Azure Monitor
  • Cloud Monitoring
  • NIST
  • Oracle Cloud
  • Cisco
  • CISSP

More jobs at Malomatia

All 55