Information Security Engineer, Network Security Engineering
Location
Texas
Posted
15 hours ago
Salary
$154K - $161K / year
Seniority
Senior
Job Description
Information Security Engineer, Network Security Engineering
Jones Lang LaSalle Americas, Inc.
• Serve as the primary subject matter expert for Palo Alto Networks technologies (NGFWs, Cloud NGFW, Panorama), Web Application Firewall, Content Delivery Network, API Security, IDS/IPS, and DDoS prevention • Own onboarding, policy tuning, and lifecycle management for WAF and CDN platforms; lead firewall ruleset optimization, IDS/IPS tuning, and DDoS protection configuration • Partner with internal teams to drive the global rollout, tuning, and operational management of URL filtering and TLS decryption across the network estate • Lead API security efforts — ensuring API traffic routes through security tooling, identifying vulnerabilities, and working with application teams on fixes • Lead troubleshooting of complex, multi-layer global network and application issues — from packet captures on inter-continental BGP topologies to WAF false-positive triage • Partner with business and application teams to produce clear, actionable security documentation, change proposals, and executive-ready findings • Analyze existing network security architectures, processes, and procedures to identify gaps and drive meaningful improvements • Configure and report on defensive measures against advanced threat actor tactics; maintain current awareness of the evolving threat landscape and the effectiveness of our defenses against them • Communicate complex technical problems and solutions clearly to both global engineering teams and C-suite stakeholders • Champion the broader Security team’s initiatives, not just Network Security Engineering • Participate in the maintenance and tuning of all network security technologies including WAFs, CDNs, VPNs, and application-aware firewalls • Leverage and contribute to automation pipelines for global firewall rule deployment and policy management across the network estate • Utilize security tooling telemetry and data collection automations to produce actionable reporting and metrics for internal teams and executive stakeholders
Job Requirements
- 5+ years of hands-on network security engineering experience designing and implementing enterprise-scale security solutions
- Expert-level proficiency in Palo Alto Networks — NGFWs, Panorama policy management, and PAN-OS; PCNSE or PCNSC certification strongly preferred
- Expert troubleshooting skills across network and application layers, including packet capture analysis on complex, dynamically routed architectures
- Deep understanding of layer 7 web application technologies and WAF/CDN platforms (e.g. Akamai, Cloudflare, Imperva, F5) — onboarding, policy tuning, break/fix troubleshooting, and operational management
- Solid grounding in API security — ensuring API traffic routes through security tooling, evaluating identified vulnerabilities, and partnering with application teams to drive remediation
- Strong HTTP/application security knowledge: TLS interception, SQL injection, XSS, CSRF, command injection, LFI/RFI, rate limiting, bot detection, geo-blocking, and sinkholing
- Intermediate to advanced network routing and switching knowledge with focus on DNS, TCP/IP, IPsec, TLS, GRE, OSPF, and BGP
- Proficiency in at least one scripting language (Python preferred) and familiarity with Linux/CLI tooling
- Working knowledge of public cloud environments (Azure, AWS, GCP)
- Experience with at least one SIEM platform for log analysis, behavioral analytics, and rule tuning
- Proven written and verbal communication skills, including presenting to both technical and non-technical audiences
- Proven track record of taking ownership in unstructured environments — cutting through ambiguity, making sound decisions with incomplete information, building stakeholder consensus, and delivering security improvements without waiting for top-down direction.
Benefits
- 401(k) plan with matching company contributions
- Comprehensive Medical, Dental & Vision Care
- Paid parental leave at 100% of salary
- Paid Time Off and Company Holidays
- Early access to earned wages through Daily Pay
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Role Description The Senior Consultant, Application Security is a senior technical practitioner in IOActive's Application Security practice, with secure code review as the central specialty. The role centers on deep manual code audit work across web and systems languages, paired with application penetration testing, threat modeling, and Secure Development Lifecycle (SDLC) advisory engagements. - Code review engagements span the full landscape: - Source code reviews on production codebases for enterprise web applications, mobile backends, embedded systems, and cryptographic implementations - Application penetration testing against web, API, and mobile targets - Threat modeling for new product designs - SDLC advisory work helping clients integrate security into their development processes - The Senior Consultant brings particular depth in code review and broad competence across the adjacent work. Qualifications - 5+ years in offensive security services, with at least 2–3 years focused on application security and source code review - Hands-on engagement delivery across multiple AppSec disciplines — code review, application penetration testing, threat modeling, or SDLC consulting - Deep code review expertise in at least two of: - JavaScript / TypeScript (Node.js, modern frontends) - Python (Django, Flask, FastAPI) - Java (Spring, J2EE) - C# / .NET (ASP.NET, Core) - C / C++, Rust, GoLang - Working knowledge of common framework patterns, ORM behavior, authentication and authorization libraries, cryptographic libraries, and the security pitfalls particular to each - Familiarity with vulnerability classes - Nice to have - Familiarity with relevant standards and frameworks: OWASP ASVS, NIST SSDF, BSIMM, SAMM Requirements - Strong technical credibility and the comfort to operate as the senior voice on engagements - Excellent written communication — producing actionable reports for developers - Strong verbal communication, capable of presenting complex concepts to diverse audiences - Comfort moving between languages and stacks - Collaborative mindset — close coordination with delivery teams and client developers - Genuine curiosity about how systems work, and patience for reading code carefully Benefits - A chance to work with an industry leader in cyber security - Access to world-class technical teams and research - A high-energy, collaborative team that values innovation - Flexibility—work remotely or from the office as needed - Opportunities for travel - Competitive compensation and performance-based incentives - US base salary range $75,000 - $175,000, depending on experience level, background and location.
• Design, develop, and implement automations and workflows to improve security processes within security-oriented platforms and other IT platforms. • Build and optimize integrations between security tools/platforms. • Develop dashboards, reports, and technical documentation for stakeholders to track security operations deliverables, trends, and progress on security posture. • Support incident response and other security operations tasks through automation and orchestration. • Contribute to continuous improvement initiatives by applying DevOps and agile principles to security engineering tasks. • Collaborate with global teams to ensure alignment on security engineering, standards, and best practices.
• Avaliação de Arquitetura: Analisar e revisar arquiteturas de soluções OT, garantindo aderência às boas práticas de segurança cibernética. • Segurança de Equipamentos OT: Realizar avaliações de segurança em equipamentos como IEDs, PLCs, AMIs e dispositivos de campo. • Controles Cibernéticos: Desenvolver e implementar controles de segurança em ambientes OT, alinhados às normas e regulamentações vigentes. • Gestão de Vulnerabilidades: Identificar, classificar e gerenciar vulnerabilidades, garantindo ações corretivas em tempo hábil. • Monitoramento e Ferramentas: Configurar e operar ferramentas de IDS, antivírus e firewalls específicas para OT. • Análise e Troubleshooting: Realizar análise de pacotes e redes OT, solucionando problemas de desempenho e segurança. • KPIs e OKRs: Definir e acompanhar indicadores de desempenho e objetivos de segurança cibernética.
Role Description Reporting to the Global CTO/CISO, the Head of Security owns the full security program across Ignyte and its operating companies: engineering, operations, governance/risk/compliance, and incident response. You will run day-to-day security operations and detection & response, own and rationalize the security technology stack, lead the GRC and regulatory agenda, drive cyber due diligence and post-close security integration for acquisitions, and own incident response end to end. You will lead a direct team of four and manage key security vendors, partners, and budget. Key Responsibilities - Security Engineering & Operations: - Own day-to-day security operations: detection & response, EDR/XDR, email security, endpoint management, SIEM/log management, and vulnerability management. - Drive measurable gains in detection coverage, mean time to detect/respond, and operational maturity. - Manage MDR/MSSP and tooling vendor relationships. - Cloud & Identity Security: - Lead security posture across Microsoft Azure and Microsoft 365 / Entra ID (Microsoft Defender suite, conditional access, identity governance, and privileged access). - Operate cloud security posture management and drive remediation to closure. - M&A Cyber Due Diligence & Integration: - Lead pre-acquisition cyber due diligence: external attack surface mapping, gap assessment, etc. - Own post-close security integration (onboarding acquired entities onto the common baseline, rationalizing overlapping tooling, and supporting TSA stand-up and exit). - Incident Response: - Own the incident response program (playbooks, tabletop exercises, forensics/vendor coordination, and executive communication during incidents). - Governance, Risk & Compliance: - Own the GRC function: security risk management, the risk register, policy and standards, and control-framework alignment (NIST CSF / CIS Controls). - Run the security exception, remediation, and risk-acceptance process and surface residual risk to executive leadership. - Leadership: - Lead, mentor, and grow the security team. - Build global relationships within a matrixed organization. - Own the security operations budget and roadmap; report posture and risk to the CISO and leadership. Qualifications - 10+ years in information security, including 4+ years in security leadership. - Experience owning aspects of a security program end to end: engineering, operations, GRC, and incident response (not just a single function). - Deep, hands-on expertise with the CrowdStrike suite of tools, including Falcon (EDR/XDR, threat hunting, response, Spotlight). - Strong Microsoft Azure and Microsoft 365 / Entra ID security expertise (Defender, conditional access, identity governance). - Hands-on incident response leadership and modern SecOps practices (detection engineering, vulnerability management). - Experience in a regulated industry (insurance or financial services), with working knowledge of NYDFS 23 NYCRR 500 or a comparable regime. - Demonstrable experience with email threat detection and endpoint management, log management/detection (SIEM), and external attack surface management. Preferred Qualifications - Previous MSP/MSSP experience highly desired. - Experience in a highly acquisitive, multi-entity environment. - Insurance, MGA/MGU, or brokerage industry background. - Relevant certifications (e.g., CISSP, CCSP, Azure Security Engineer, GIAC). - Track record standing up or maturing a security program through rapid inorganic growth. - Demonstrated M&A cyber due diligence and integration experience, assessing and onboarding acquired companies onto a common security baseline. Benefits - Competitive benefits offering including medical, dental, vision, and supplemental benefits. - Company-paid life insurance, long-term and short-term disability policies. - 14 annual paid holidays and generous PTO plan. - 401(k) with annual Safe Harbor and profit share contributions. - Open to remote work environment.



