Network Security Engineer

Nebius · Remote - Europe · Engineering

Posted 2026-09-14

Apply for this role →

Role Summary

We are looking for a Network Security Engineer to join our Network team. This role combines deep expertise in network engineering and cybersecurity. You will help implement end-to-end network security architectures for enterprise and data center backbone/fabric environments, work with network architects and the management team to guide these designs through review and approval with the Security team, and operate and maintain the implemented solutions day-to-day.

You are expected to be hands-on with leading firewall platforms (Palo Alto, Check Point, etc.), understand complex routing and switching designs, and be comfortable implementing and troubleshooting these networks.

Responsibilities

Implement and maintain Zero Trust-aligned security architectures for both enterprise and data center networks.

Configure Layer 3/4 & Multi-VRF Segmentation, Security Policies, Secure Remote access.

Implement and test large hyper scale DC Security solutions :  IPS/NDR solutions ,  AntiDDOS solutions.

Integrate NGFW platforms with modern identity providers such as Microsoft Entra ID and Okta, maintain NGFW management, automation, and logging capabilities required by the Security team.

Implement and maintain Security Capabilities, including Layer 7 application inspection, IPS, user identification, ZTNA, and SASE integrations.

Integrate and operate monitoring tools such as Zabbix, Grafana, and Akvorado.

Regularly perform security hardening, vulnerability management, and patching and upgrades on network and infrastructure devices, and verify the effectiveness of these procedures.

Required Qualifications

Experience in networking and security protocols (TCP/IP, HTTP(S), DNS, TLS, IPsec, Routing protocols)

Experience and Knowledge of  Backbone & Datacenter technologies (EVPN, L3VPN MPLS, MPBGP, L2VPN..)

Hands-on experience with next-generation firewalls (Palo Alto Networks, Check Point, or similar).

Experience with automation using Python, Go, or equivalent.

Proficiency in Unix/Linux and experience with major network vendors (Cisco, Juniper, Aruba, etc.).

Experience configuring and troubleshooting NGFW capabilities and integrations, including IPS, User-ID, Microsoft Entra ID, and ZTNA.

Preferred Qualifications

Good knowledge of IPv6.

Experience with automation tools (Ansible, Terraform, NetBox, SaltStack, etc.).

Experience with large-scale, highly available distributed systems.

Knowledge of Zero Trust principles and micro-segmentation approaches.

Relevant certifications (CCNP/CCIE, PCNSE, NSE 4/7) and professional working proficiency in English.

Familiarity with commercial or open-source monitoring, logging, and security analytics solutions such as Splunk; EDR/XDR platforms such as CrowdStrike; and centralized NGFW management platforms such as Panorama, Strata Cloud Manager, and FortiManager.

Bonus: Exposure to DevSecOps practices (SAST/DAST), CSPM/CWPP platforms such as Wiz, EDR, offensive security (OSCP/CPTS, red teaming), or security frameworks, standards, and regulations such as ISO/IEC 27001, NIST CSF, and GDPR.

Apply for this role →

← Back to all jobs