Network Security Consultant
Canada – Remote / Hybrid / On-site
Regina, Saskatchewan is the primary client location.
Employment Type: Contract
Work Schedule: Monday–Friday,
8:00 AM–5:00 PM CST
Shift: Day Shift
Work Setting: Remote, Hybrid, or On-site as required.
The consultant must be able to travel within Saskatchewan for site visits when required on his own expenses.
Client is seeking a
Senior Network Security Consultant to join its Information Security Operations team and provide senior-level subject matter expertise in enterprise network security governance, architecture, design, and operational oversight.
The consultant will be responsible for securing enterprise on-premises and hybrid-cloud environments, with a strong focus on
Cisco security platforms, enterprise firewalls, VPNs, IPS/IDS, network segmentation, zoning, and Zero Trust principles.
The role will also provide security guidance for network and application architectures, participate in Architecture Review Board activities, support Azure security initiatives, incident response, vulnerability management, penetration testing, disaster recovery, and business continuity planning.
Key Responsibilities
- Design, implement, and manage enterprise network security controls.
- Work extensively with:
- Cisco Firepower Threat Defense (FTD)
- Cisco FMC
- LINA and SNORT engines
- Cisco Umbrella / OpenDNS
- Cisco Web Security Appliance (WSA)
- Cisco Secure Malware Analytics / Sandboxing
- Provide governance and security expertise for remote-access solutions and Cisco FTD VPN services.
- Ensure firewall and remote-access configurations align with enterprise security standards and Zero Trust principles.
- Troubleshoot and triage network security incidents, alerts, and anomalies.
- Continuously review and tune IPS/IDS signatures, firewall rules, and traffic inspection policies.
- Participate in Architecture Review Board (ARB) meetings.
- Review network and application architectures for security, zoning, and segmentation compliance.
- Review and approve firewall rule changes.
- Provide secure network design guidance for new and existing services.
- Design and secure hybrid environments integrating on-premises infrastructure with Microsoft Azure.
- Provide expertise with Azure:
- VNets
- Subnets
- NSGs
- Azure Firewall
- Application Gateways
- IAM
- PAM
- Conditional Access
- RBAC
- Support security integration with Broadcom VMware Cloud Foundation (VCF).
- Evaluate emerging security technologies, automation, orchestration, and AI/ML-based threat detection.
- Conduct deep traffic analysis and threat investigations using telemetry, packet capture, and security analytics.
- Lead or support network-security incident response, containment, root-cause analysis, and remediation.
- Identify network security gaps, misconfigurations, and risks and recommend remediation.
- Collaborate with infrastructure and security teams on vulnerability identification and remediation.
- Support network security penetration testing and validation.
- Contribute to disaster recovery and business continuity strategies.
- Review F5 load-balancer traffic flow, distribution, and backend-server redirection configurations.
- Ensure network-security controls support resilience, failover, and replication across datacenters.
- Develop and maintain network-security architecture designs, standards, and operational procedures.
- Act as a trusted security advisor to cross-functional teams.
Experience
- Minimum 10 years of progressively responsible, hands-on IT experience.
- Minimum 8 years of direct experience in one or more of:
- Network Security Engineering
- Network Security Architecture
- Network Security Operations
- Enterprise Firewall Engineering / Administration
- Secure Network Design and Implementation.
Mandatory Certification
Candidate must hold
at least one active professional-level or expert-level certification from the approved list:
- CISSP – Certified Information Systems Security Professional
- CISM – Certified Information Security Manager
- CCSP – Certified Cloud Security Professional
- CCIE Security
- CCNP Security
- JNCIP-SEC
- JNCIE-SEC
- CCSE
- Palo Alto Networks Certified Network Security Professional
- Palo Alto Networks Certified Network Security Architect
- Microsoft Azure Security Engineer Associate
- Microsoft Azure Solutions Architect Expert
- Microsoft Azure Network Engineer Associate.
Important: The certification must be active/current and a copy of the certification must be submitted during submission.
Preferred Qualifications
- Bachelor's degree in:
- Information Security
- Computer Science
- Engineering
- Related field
- 10+ years of network security and enterprise infrastructure experience.
- Strong network security architecture, design, and governance experience.
- Strong experience with:
- Network segmentation
- Security zoning
- Zero Trust
- Cisco FTD/FMC
- IPS/IDS
- Cisco Umbrella/OpenDNS
- WSA
- Hybrid-cloud and Azure security experience.
- Experience with SIEM, SOAR, NDR, EDR, and vulnerability-management technologies.
- Network traffic analysis and packet-capture experience.
- Incident response and threat investigation experience.
- Security risk assessment and remediation experience.
- Penetration-testing experience.
- DR/BCP security experience.
- F5 load-balancer experience.
- VMware Cloud Foundation security experience.
- Experience with automation, orchestration, and AI/ML threat detection.
- Strong documentation, communication, and stakeholder-management skills.