Network Engineer III - IN (Palo Alto & FortiGate)
Rackspace Technology · Gurugram, Haryana, India
Rackspace Technology · Gurugram, Haryana, India
**About Rackspace Cyber Defence** Rackspace Cyber Defence is our next generation cyber defence and security operations capability that builds on 20+ years of securing customer environments to deliver proactive, risk-based, threat-informed and intelligence driven security services. **Our purpose** is to enable our customers to defend against the evolving threat landscape across on-premises, private cloud, public cloud and multi-cloud workloads. **Our goal** is to go beyond traditional security controls to deliver cloud-native, DevOps-centric and fully integrated 24x7x365 cyber defence capabilities that deliver a **proactive**, **threat-informed**, **risk-based**, **intelligence-driven** approach to detecting and responding to threats. **Our mission** is to help our customers: - Proactively detect and respond to cyber-attacks – 24x7x365. - Defend against new and emerging risks that impact their business. - Reduce their attack surface across private cloud, hybrid cloud, public cloud, and multi-cloud environments. - Reduce their exposure to risks that impact their identity and brand. - Develop operational resilience. - Maintain compliance with legal, regulatory and compliance obligations. **Key Accountabilities** - Act as the highest level of technical escalation for complex network security and cloud security incidents across customer environments. - Provide expert-level support and troubleshooting for Palo Alto, Fortinet, Azure networking, and hybrid network security infrastructures and architectures. - Lead technical resolution of critical (P1/P2) incidents and major service outages, driving recovery activities and stakeholder communications. - Perform deep-dive Root Cause Analysis (RCA) and recommend permanent corrective and preventive actions to improve service stability. - Design, implement, and optimize secure network security architectures for customer environments across cloud, on-premises, and hybrid deployments. - Lead customer onboarding activities involving complex network designs, large-scale migrations, and security transformation initiatives. - Review and approve firewall policies, network segmentation strategies, VPN designs, security controls, and architecture changes. - Provide governance and technical oversight for major changes, upgrades, migrations, and platform lifecycle management activities. - Design and implement scalable solutions utilizing: - Palo Alto VM-Series and Panorama - FortiGate VM and FortiManager - Azure Networking and Security Services - Hybrid Connectivity Solutions - Lead troubleshooting and optimization of: - IPsec & Remote VPNs - Static and dynamic routing - SD-WAN & BGP - Azure Routing - Azure Load Balancing - Network Performance Issues - Security Policy Conflicts - Drive continuous service improvement initiatives through automation, standardization, and operational excellence. - Develop and maintain architecture standards, operational runbooks, design documentation, and knowledge repositories. - Collaborate with Microsoft, Palo Alto, Fortinet, and other vendors for product escalations and advanced troubleshooting. - Evaluate emerging security technologies and recommend enhancements to customer security posture. - Act as a technical mentor for L1 and L2 engineers, providing coaching, reviews, and knowledge transfer sessions. - Participate in customer technical governance meetings, architecture reviews, and strategic planning discussions. - Support after-hours critical incidents, major projects, and planned maintenance activities when required. Skills & Experience Mandatory Technical Expertise - 8+ years of hands-on experience in Network Security Engineering, Security Operations, or Security Architecture roles. - Expert-level knowledge of: - Palo Alto Networks VM-Series Firewalls - Panorama Management Platform - FortiGate VM Firewalls - FortiManager - Azure Networking and Security Services Advanced Azure Expertise - Deep understanding of: - Virtual Networks (VNets) - Virtual WAN (vWAN) - Route Tables - Network Security Groups (NSGs) - Azure Load Balancer - Application Gateway (WAF) - Azure Firewall - VPN Gateway - ExpressRoute - Azure Route Server - Private Endpoints - Hub-and-Spoke Architectures - Zero Trust Network Design Network Security Architecture - Extensive experience designing and implementing: - Enterprise Network Security Architectures - Cloud-Native Security Solutions - Hybrid Connectivity Solutions - Segmentation and Micro-Segmentation Strategies - Zero Trust Security Models - Secure Internet Egress Architectures - Multi-Cloud Connectivity Solutions Advanced Operational Skills - Expert troubleshooting experience in: - IPsec VPN - SSL VPN - Dynamic Routing - NAT - URL & APP-ID - Feature and Function optimizations - High Availability Clusters - Performance Optimization - Experience leading: - Firewall migrations - Cloud transformation projects - Network modernization initiatives - Security platform upgrades and refresh programs Automation & Engineering - Good to have experience with automation and Infrastructure-as-Code solutions such as: - PowerShell - Python - Terraform - ARM/Bicep Templates - Azure Automation - Ability to design automated operational workflows and reduce manual effort through scripting and orchestration. Certifications (Preferred) Palo Alto Networks - Palo Alto Networks Certified Network Security Engineer (PCNSE) - Palo Alto Networks Cybersecurity Certified Expert (PCCSE) Fortinet - Fortinet NSE 4+ / FCP Network Security Microsoft - Microsoft Certified: Azure Network Engineer Associate (AZ-700) - Microsoft Certified: Azure Fundamentals (AZ-900) - Microsoft Certified: Azure Security Engineer Associate (AZ-500) - Azure Solutions Architect Expert (AZ-305) Additional Security Certifications (Good to Have) - CISSP - CCSP - CCNP Security - CCIE Security Additional Security Certifications (Good