At a Glance
- Tasks: Design and implement cutting-edge network security solutions in a collaborative environment.
- Company: Join a $13+ billion global tech leader with a startup mindset.
- Benefits: Enjoy hybrid work, competitive salary, and opportunities for professional growth.
- Other info: Dynamic team culture with excellent career advancement opportunities.
- Why this job: Make a real impact in cybersecurity while working with innovative technologies.
- Qualifications: 8+ years in Network Security Engineering and strong troubleshooting skills required.
The predicted salary is between 66150 - 80850 £ per year.
We are a $13+ billion global technology company, home to more than 224,000 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud, and AI, powered by a broad portfolio of technology services and products. HCLTech is a globally recognized leader in the Tech and IT industry, but we’ve never forgotten the startup mindset that got us here. We’ve always approached our work with an idea-first attitude because every one of our accomplishments — no matter how big or small — can be traced back to an idea’s single spark. It’s that spark — that inner drive — that sets our people apart from our competitors. It enables us not just to pull off game-changing feat after game-changing feat but to better our world in the process. We want you to find your spark. Because that’s what drives you to be better, be more and ultimately, be more fulfilled.
Location: London, UK
Hybrid mode - 3 days' work from office
This is a Fixed term contract role FTC/FTE.
Requirements / Qualifications / Tasks
- Zero Trust & Network Security Engineering
- Partner with internal stakeholders and technology vendors to evaluate, select, and implement Zero Trust security solutions.
- Design and engineer scalable, resilient, and secure enterprise network and security architectures.
- Collaborate across Network Engineering, Security Engineering, IAM, Cloud, EUC, and Operations teams to deliver security transformation initiatives.
- Contribute to technical strategy, standards, reference architectures, and design patterns.
- Deliver solutions tailored to internal business requirements. Articulate design rationale, flexibly adapt solutions, and iterate designs when required.
- Develop High-Level Designs (HLD), Low-Level Designs (LLD), migration plans, operational procedures, and architecture documentation.
- Support vendor evaluations, Proof of Concepts (PoCs), pilot deployments, and production rollouts.
- Lead technical assessments, architecture reviews, root cause analysis, and engineering recommendations.
- Design, deploy, and operate Palo Alto, Fortinet or Cisco NGFW platforms and their respective (Cloud) Manager, (Strata Cloud, FortiManager, Cisco Security Cloud).
- Design and implement SASE/SSE solutions for enterprise-scale deployments.
- Implement centralized security management, policy governance, logging, monitoring, and reporting using the Vendors ecosystem or solutions like Tufin or Algosec.
- Network Security & Segmentation
- Design and implement on-premises Zero Trust Enforcement Points (NGFW).
- Develop segmentation and micro-segmentation strategies across data centres, campuses, cloud, and branch environments.
- Define secure traffic flows and trust boundaries.
- Support migration from traditional network-centric security models to Zero Trust architectures.
- Enterprise Networking
- Routers, switches, LAN/WAN design and engineering.
- VPN technologies, IPSec, TLS encryption, and NAC integration.
- Hands-on experience with:
- Cisco ASR / ISR / Catalyst 8k
- Cisco Catalyst and Nexus platforms
- Arista switching platforms
- Strong experience with:
- BGP
- OSPF
- EVPN
- VXLAN
- MPLS
- VRF-based segmentation
- Deep understanding of Layer 2 and Layer 3 network technologies.
- Security & Integration
- Experience integrating network security solutions with:
- Microsoft Entra ID
- Active Directory
- Cisco ISE / NAC platforms
- EDR/XDR solutions
- SIEM platforms
- ServiceNow
- Cloud platforms (Azure, AWS, GCP)
- 8+ years of experience in Network Security Engineering and Enterprise Networking.
- Demonstrated experience designing and implementing:
- SASE/SSE
- ZTNA
- Network Segmentation
- Identity-Based Access Controls
- Enterprise Firewall architectures
- Strong understanding of Zero Trust Architecture principles.
- Ability to produce technical assessments, architecture reviews, PoCs, migration strategies, and engineering documentation.
- Strong troubleshooting and root cause analysis capabilities.
- Excellent written and verbal communication skills.
- Palo Alto, Fortinet certification
- CCNP Enterprise / Security
- CCIE Enterprise Infrastructure / Security
- CISSP
- Experience within large-scale financial services environments.
- Knowledge of NIST Zero Trust Architecture, DORA, NIS2, and modern cybersecurity frameworks.
Qualifications Required
Preferred
Network Security Engineer in City of London employer: HCLTech
HCLTech is an exceptional employer that fosters a dynamic and inclusive work culture, where innovation thrives and employees are empowered to grow their skills in cutting-edge technologies. With a global presence and a commitment to employee development, HCLTech offers numerous opportunities for career advancement, particularly in the exciting field of AI and frontend development. Joining our team means being part of a collaborative environment that values creativity and encourages meaningful contributions to impactful projects.