Network Security Engineer

1 week ago


Riyadh, Ar Riyāḑ, Saudi Arabia IT-Security C&T Full time

1. Advanced Support and Escalation Management

  • Act as the final escalation point for complex incidents affecting firewalls, VPN, proxy, IPS, SSL inspection, DDoS, and network ATP.
  • Perform deep troubleshooting, packet analysis, and protocol level investigations for critical issues.
  • Own root cause analysis for recurring or high impact incidents and define corrective and preventive actions.

2. Configuration, Optimization and Maintenance

  • Design, implement, and tune policies on Palo Alto, Cisco ASA or FTD, and Fortinet firewalls. Including segmentation, zero trust style rules, NAT, and security policies.
  • Manage VPN services for remote access and site to site connectivity. Including authentication, MFA integration, and high availability.
  • Administer Forcepoint Web proxy and SSL decryption policies. including safe bypass lists, categories, and exception handling.
  • Operate Gigamon SSL inspection, Arbor DDoS, and network IPS or ATP solutions. ensuring signatures, profiles, and protections are updated and tuned.
  • Own backup, restore, and lifecycle tasks for all network security devices. including upgrades, certificate rotations, and HA testing.

3. Architecture and Design

  • Contribute to low level designs, network security architectures, and change plans for new services and projects.
  • Recommend improvements in zoning, traffic flows, and control placement to align with SAMA CSF and NCA ECC requirements for network and perimeter security.

4. Incident Response and Reporting

  • Lead network security incident response during major events. coordinate with SOC, infrastructure, and application owners.
  • Produce detailed RCAs, including packet captures, logs, timeline, business impact. and hardening recommendations.
  • Provide dashboards and reports on policy changes, rule usage, blocked traffic trends, and attack statistics.

5. Technical Leadership and Mentoring

  • Mentor L2 Network Security Engineers on troubleshooting methods, tooling usage, and SOPs.
  • Review and approve L2 changes for complex or high-risk activities.
  • Contribute to our own runbooks, hardening guides, and standard templates for network security changes.

6. Governance, Compliance and ITIL

  • Ensure all work is executed under formal Change and Incident Management with CAB ready plans, test cases, and rollback procedures.
  • Map device configurations and monitoring to SAMA Cybersecurity Framework and NCA ECC technical controls for network security, perimeter defense, and secure remote access.
  • Maintain audit ready evidence. approvals, logs, configuration exports, and RCAs.

7. Collaboration and Stakeholder Engagement

  • Work closely with
  • F5 Application Security tower for traffic flows, VIPs, and DDoS or WAF interactions
  • L3 Email Security Engineer for handoffs where issues are clearly network or clearly mail gateway
  • SOC and SIEM teams for rule tuning and log quality
  • Infrastructure and application teams to ensure secure and stable deployments

Tooling Scope

Must have strong hands-on expertise in most of

  • Palo Alto NGFW and GlobalProtect
  • Cisco ASA or FTD and Cisco IPS
  • Fortinet FortiGate
  • Forcepoint Web Security and SSL interception
  • Gigamon SSL inspection
  • Arbor DDoS
  • Trellix or FireEye NX or equivalent network ATP

Good to have

  • Experience with automation or scripting around these tools, plus strong packet analysis using tools such as Wireshark or vendor built in captures.
Desired Candidate Profile

Required Qualifications

  • Bachelor s degree in Computer Science, Information Technology, Cybersecurity, or related field.
  • Minimum 7 years in network security engineering. with at least 3 to 5 years managing multi-vendor firewalls, VPN, proxy, IPS, DDoS, and SSL inspection in large enterprises.
  • Deep understanding of TCP or IP, routing, VPN protocols, TLS, HTTP or HTTPS, DNS, and common attack techniques against network and perimeter infrastructure.
  • Proven track record leading incident response and complex troubleshooting in high availability. environments.

Desired Skills and Certifications

  • Palo Alto PCNSE or PCNSA, Cisco CCNP Security or equivalent, Fortinet NSE4 or higher.
  • ITIL Foundation or experience operating under ITIL processes.
  • CISSP, CISM, or equivalent is a plus for seniority and governance alignment.


  • Riyadh, Ar Riyāḑ, Saudi Arabia Security Matterz Full time

    About the RoleSecurity Matterz is looking for a Pre-Sales Cybersecurity Engineer to support our sales team in designing and positioning advanced security solutions for our customers. You will work closely with account managers, vendors, and technical teams to understand client requirements, build tailored solutions, and help win strategic opportunities...


  • Riyadh, Ar Riyāḑ, Saudi Arabia NourNet Full time

    Engineer core Responsibilities include:Daily operational support for switches, routers, firewalls, and wireless systemsTroubleshooting and resolution of complex Layer 2 and Layer 3 issuesImplementation of network configurations and policy enforcementCoordination with vendors and internal teams for upgrades and projectsMaintain detailed network diagrams,...


  • Riyadh, Ar Riyāḑ, Saudi Arabia Exquitech Group Full time

    Company: Exquitech (PIF Project)Job Summary:We are seeking a skilled and motivatedNetwork & Security Engineerto join a high-profilePIF projectinRiyadh. with 2–3 years of hands-on experience. The ideal candidate will be responsible for designing, implementing, maintaining, and securing network infrastructure while ensuring optimal performance and protection...


  • Riyadh, Ar Riyāḑ, Saudi Arabia CONNECT Professional Services Full time

    Job SummaryThe Network Security Engineer will be responsible for operating and administering secure network infrastructures to ensure the confidentiality, integrity, and availability of organizational systems. The role involves close collaboration with IT teams, vendors, and stakeholders to deliver reliable and secure solutions.Job DescriptionPlan, acquire,...


  • Riyadh, Ar Riyāḑ, Saudi Arabia Twaasol Full time

    Network & Security EngineerCompany DescriptionAt Twaasol, we don't just sell technology — we build long-term partnerships and help organizations make the right decisions. As we continue our growth across Saudi Arabia and the region, we're looking for aNetwork & Security Engineerto join our team.Our Core Values:At Twaasol, we live by our values:Be HonestBe...


  • Riyadh, Ar Riyāḑ, Saudi Arabia Addar Water Factory Full time

    L3 Network Security EngineerHiring L3 Network Security Engineer  – SAUDI NATIONAL only for our Client in Riyadh, KSA.


  • Riyadh, Ar Riyāḑ, Saudi Arabia Penta Consulting Full time

    Penta Consulting are a technology service provider and leading outsourced partner helping to deliver professional and managed solutions across EMEA.We're looking for an experiencedSenior Network Security Engineerto join our high‑performing security team supporting one of our major enterprise customers. This is a hands‑on, customer‑facing role where...


  • Riyadh, Ar Riyāḑ, Saudi Arabia 2P Perfect Presentation Full time

    TheL2 Network Security Engineeris responsible for operating, supporting, and maintaining network security infrastructure. This role involves implementing security controls, handling L2 incidents, troubleshooting issues, and ensuring high availability and disaster recovery readiness.Job Responsibilities:Operate network security solutions to maintain stability...


  • Riyadh, Ar Riyāḑ, Saudi Arabia Rackspace Technology Full time

    Rackspace Technology is a leading provider of expertise and managed services across all the major public and private cloud technologies. We've evolved Fanatical Support to encompass the entire customer journey — providing Fanatical Experience from first consultation to daily operations. Our passionate experts combine the power of proactive, always-on...


  • Riyadh, Ar Riyāḑ, Saudi Arabia Rackspace Full time

    Rackspace Technology is a leading provider of expertise and managed services across all the major public and private cloud technologies. We've evolved Fanatical Support to encompass the entire customer journey — providing Fanatical Experience from first consultation to daily operations. Our passionate experts combine the power of proactive, always-on...