31 Aug
|
DASRO CONSULTING
|
Regina
31 Aug
DASRO CONSULTING
Regina
Dasro is looking for a Network Security Consultant for one of its clients in Regina, SK.
Location: Remote from Canada; hybrid/in office as required. Regina, Saskatchewan office availability is an asset.
Hours: 8:00 AM–5:00 PM CST, Monday–Friday
Initial Contract Term: Upon Agreement execution through March 31, 2027
Extension: Two additional one-year terms.
Travel: Must be able to travel within Saskatchewan for site visits; travel associated with remote/hybrid arrangements is the supplier's responsibility.Job Summary The consultant will act as a subject matter expert responsible for the governance, architecture, implementation oversight and security of enterprise network controls across on-premises and hybrid cloud environments.
The role has a strong emphasis on Cisco security technologies, enterprise firewalls, network segmentation, zoning, zero-trust architecture, remote access security and Azure hybrid-cloud security . The consultant will also participate in Architecture Review Board activities and support incident response, vulnerability management, penetration testing and disaster recovery initiatives.Key Responsibilities
- Design, implement and manage enterprise network security controls across:
- Cisco Firepower Threat Defense (FTD)
- Cisco FMC
- Cisco Umbrella/OpenDNS
- Cisco Web Security Appliances
- Cisco Secure Malware Analytics
- Provide security governance and expertise for VPN and remote-access solutions.
- Ensure network security configurations align with enterprise security standards, access-control policies and zero-trust principles.
- Act as the SME for troubleshooting and triaging firewall, IPS, DNS and web-security incidents.
- Review and tune IDS/IPS signatures, firewall rules and traffic-inspection policies.
- Participate in Architecture Review Board (ARB) meetings.
- Review network and application architectures for security, zoning and segmentation compliance.
- Review and approve firewall-rule changes.
- Provide security architecture and design recommendations for new and existing services.
- Design and secure hybrid on-premises/Azure environments.
- Provide expertise in Azure VNets, subnets, NSGs, Azure Firewall, Application Gateway, IAM, PAM, Conditional Access and RBAC.
- Support Broadcom VMware Cloud Foundation (VCF) security integration.
- Evaluate emerging security technologies, automation/orchestration and AI/ML-based threat detection.
- Conduct network traffic analysis, threat investigations and packet analysis.
- Lead or support network-security incident response, containment, root-cause analysis and remediation.
- Identify security gaps, misconfigurations and risks and recommend remediation.
- Support vulnerability assessment and remediation activities.
- Participate in network-security penetration testing and validation.
- Contribute to DR/BCP planning from a network-security perspective.
- Assess F5 load-balancing configurations and traffic flows from a security perspective.
- Ensure security controls are resilient and aligned with failover and replication strategies.
- Develop and maintain network-security architecture, standards and operational documentation.
- Act as a trusted security advisor to infrastructure, cloud, architecture and other cross-functional teams.
Mandatory Qualifications
- Candidates must meet all mandatory requirements:10+ years of progressively responsible, hands-on IT experience.
- At least 8 years of direct experience in one or more of:
- Network security engineering
- Network security architecture
- Network security operations
- Enterprise firewall engineering/administration
- Secure network design and implementation
- Must hold at least one active professional- or expert-level certification from the approved list:
- CISSP
- CISM
- CCSP
- CCIE Security
- CCNP Security
- JNCIP-SEC
- JNCIE-SEC
- Check Point CCSE
- Palo Alto Networks Certified Network Security Professional
- Palo Alto Networks Certified Network Security Architect
- Microsoft Azure Security Engineer Associate
- Microsoft Azure Solutions Architect Expert
- Microsoft Azure Network Engineer Associate
- Certification must be current/active and must be explicitly identified on the resume; a copy of the certificate must be provided.
- Must be legally permitted to work in Canada.
- Must be able to travel within Saskatchewan.
- Must be available full-time during 8 AM–5 PM CST, Monday–Friday .
Preferred / Rated Qualifications
- Bachelor's degree in Information Security, Computer Science, Engineering or related field.
- 10+ years in network security and enterprise infrastructure.
- Strong network-security architecture, design and governance experience.
- Expertise in segmentation, zoning and zero-trust principles.
- Strong Cisco Firepower FTD/FMC experience.
- Cisco Umbrella/OpenDNS and WSA experience.
- Firewall, IPS/IDS, VPN, encryption, URL/DNS filtering and segmentation expertise.
- Routing, switching and network-protocol knowledge.
- Network traffic analysis and threat detection.
- SIEM, SOAR, NDR, EDR and vulnerability-management exposure.
- Azure hybrid-cloud security.
- Network-security penetration testing.
- DR/BCP security experience.
- F5 load-balancing knowledge.
- Strong communication and stakeholder-management skills.
- Cisco security certifications and CISSP/CISM/CCSP are desirable.
📌 Network Security Consultant (Regina)
🏢 DASRO CONSULTING
📍 Regina