Sungrow USA Corporation
Houston, Texas
Job Description Job Description About the Company : Sungrow North America is a leading provider of renewable energy solutions, specializing in the development and manufacturing of photovoltaic inverters and energy storage systems. The company offers a comprehensive range of products and services designed to optimize the performance and efficiency of solar power installations. Sungrow North America aims to provide sustainable and reliable energy solutions to meet the growing demand for clean power and is known for its commitment to innovation, high-quality standards, and exceptional customer service. Security Engineer - Network & Identity: The Security Engineer (Network & Identity) is a hands-on engineering role within the IT team responsible for designing, implementing, securing, and automating Sungrow USA's network security, PKI and certificate management, and identity & access infrastructure across on-premises, cloud, and SaaS environments. This role serves as the technical owner for network security architecture, cryptographic services, certificate lifecycle management, authentication, and access controls. The position focuses on Zero Trust security, network segmentation, certificate-based authentication, and identity protection to reduce organizational risk and enable secure business operations and platform ownership rather than SOC operations, threat monitoring, or incident response. Essential Duties and Responsibilities: Network Security Design, implement, and maintain secure enterprise network architectures across corporate offices, data centers, cloud platforms, and remote workforce environments. Architect network segmentation, Zero Trust access controls, and secure connectivity standards using Fortinet and Zscaler security solutions. Develop and maintain Zero Trust architectures across network, identity, endpoint, application, and cloud environments. Design and administer secure remote access using Zscaler Private Access, VPN technologies, and identity-aware access controls. Manage firewall policies, network security controls, routing security, DNS security, and hybrid-cloud connectivity. Design and support Network Access Control architectures using IEEE 802.1X, RADIUS, and certificate-based authentication. Assess network security posture, develop remediation plans, and drive continuous security improvements. Cryptography, PKI & Certificate Management Own the enterprise PKI, cryptography, and certificate lifecycle management architecture, standards, and governance program. Design and manage certificate-based authentication and machine identity solutions for users, devices, servers, applications, cloud workloads, and network infrastructure across Azure, AWS, and hybrid environments. Implement and maintain certificate lifecycle automation using Microsoft Cloud PKI, Keyfactor, CyberArk Certificate Manager, EJBCA, DigiCert, AppViewX, or comparable platforms. Manage certificate issuance, enrollment, discovery, deployment, monitoring, renewal, revocation, auditing, and compliance across the enterprise. Design and support cryptographic services and certificate-based security controls, including TLS/mTLS, code signing, PKI trust hierarchies, certificate-based authentication, SCEP, PKCS, and machine identities. Establish PKI and cryptographic standards, key management practices, and security controls to support Zero Trust, regulatory compliance, and enterprise security requirements. Troubleshoot and resolve complex certificate, cryptographic, trust chain, authentication, and secure communications issues across enterprise systems and applications. Identity & Access Define authentication and authorization standards for workforce, partner, application, service, and machine identities. Design, implement, and maintain Microsoft Entra ID architecture, tenant governance, and identity security controls. Develop, test, and enforce Conditional Access policies and Zero Trust access controls. Implement and maintain MFA, passwordless authentication, phishing-resistant authentication, and Microsoft Entra ID Protection capabilities. Design and support enterprise SSO and federation integrations using SAML, OAuth 2.0, OpenID Connect, and SCIM. Implement least-privilege and risk-based access models across enterprise platforms. Administer RBAC, administrative separation, Microsoft Entra Privileged Identity Management, and least-privilege access controls. Govern application registrations, service principals, enterprise applications, API permissions, and managed identities. Support B2B collaboration, guest-user governance, external workforce access, and third-party identity integrations. Design and implement security controls across Microsoft Azure and AWS environments. Apply least privilege, RBAC, encryption, secrets management, and secure configuration standards to on-prem and cloud resources. Automate identity provisioning and deprovisioning, access governance, certificate management, configuration validation, and security operations. Create reusable secure-by-default templates and reduce manual administration through automation and orchestration Conduct access reviews, entitlement certifications, and identity governance activities. Education or Desired License and Certificates: Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field, or equivalent professional experience. Microsoft Certified: Identity and Access Administrator Associate (SC-300) preferred. Microsoft Certified: Azure Security Engineer Associate (AZ-500) preferred. CCNA, Fortinet, Zscaler, AWS Security, CISSP, CISM, Terraform, or relevant PKI certification preferred Preferred Experience & Qualifications: 5+ years of experience in security engineering, identity & access management (IAM), network security, cloud security, or a related enterprise IT discipline. Hands-on experience with Microsoft Entra ID, including Conditional Access, MFA, SSO, Identity Protection, PIM, RBAC, identity governance, and modern authentication protocols (SAML, OAuth, OpenID Connect, SCIM). Experience designing, implementing, and securing enterprise identity, privileged access, and machine identity solutions across hybrid and multi-cloud environments. Hands-on experience with Fortinet, Zscaler (ZIA/ZPA), Zero Trust architectures, least-privilege access models, and network security controls. Experience designing and operating enterprise PKI, certificate lifecycle management, certificate-based authentication, and machine identity platforms such as Keyfactor, DigiCert, EJBCA, AppViewX, CyberArk Certificate Manager, or similar solutions. Experience securing Azure and AWS environments, including identity, networking, encryption, secrets management, logging, and security monitoring. Experience with PAM and IGA platforms such as CyberArk, Delinea, BeyondTrust, SailPoint, Saviynt, or similar technologies. Experience integrating identity, network, cloud, and security telemetry with SIEM and security operations platforms. Strong automation and Infrastructure as Code skills using PowerShell, Python, Microsoft Graph API, REST APIs, Terraform, or similar technologies. Strong troubleshooting skills across authentication, federation, certificates, PKI, network security, cloud access, application integrations, and enterprise identity services. Knowledge of cybersecurity and compliance frameworks including SOC 2, ISO/IEC 27001, NIST CSF, NIST 800-63, CIS Controls, Zero Trust, and NERC CIP. Competencies: Mandarin fluency preferred but not required. Strong analytical, troubleshooting, and problem-solving skills. Ability to work independently and collaboratively in a fast-paced environment. Excellent communication, stakeholder management, and technical documentation skills. Strong organization, attention to detail, initiative, and ownership. Ability to balance security, reliability, usability, scalability, and business requirements. Proactive approach to automation, standardization, and continuous improvement. Travel 5%-20% Work Location and Status: Full time, Hybrid at any Sungrow USA office in Phoenix, Costa Mesa, or Houston No visa sponsorship Compensation: Compensation commensurate with experience Competitive salary and annual bonus eligibility Comprehensive benefits package including health, dental, vision, and retirement plans Strong personal and company growth opportunities Sungrow is an equal opportunity employer. Due to strong interest in this position, Sungrow will only reach out to those candidates who best meet the requirements. Thank you for your interest in Sungrow.
Job Description Job Description About the Company : Sungrow North America is a leading provider of renewable energy solutions, specializing in the development and manufacturing of photovoltaic inverters and energy storage systems. The company offers a comprehensive range of products and services designed to optimize the performance and efficiency of solar power installations. Sungrow North America aims to provide sustainable and reliable energy solutions to meet the growing demand for clean power and is known for its commitment to innovation, high-quality standards, and exceptional customer service. Security Engineer - Network & Identity: The Security Engineer (Network & Identity) is a hands-on engineering role within the IT team responsible for designing, implementing, securing, and automating Sungrow USA's network security, PKI and certificate management, and identity & access infrastructure across on-premises, cloud, and SaaS environments. This role serves as the technical owner for network security architecture, cryptographic services, certificate lifecycle management, authentication, and access controls. The position focuses on Zero Trust security, network segmentation, certificate-based authentication, and identity protection to reduce organizational risk and enable secure business operations and platform ownership rather than SOC operations, threat monitoring, or incident response. Essential Duties and Responsibilities: Network Security Design, implement, and maintain secure enterprise network architectures across corporate offices, data centers, cloud platforms, and remote workforce environments. Architect network segmentation, Zero Trust access controls, and secure connectivity standards using Fortinet and Zscaler security solutions. Develop and maintain Zero Trust architectures across network, identity, endpoint, application, and cloud environments. Design and administer secure remote access using Zscaler Private Access, VPN technologies, and identity-aware access controls. Manage firewall policies, network security controls, routing security, DNS security, and hybrid-cloud connectivity. Design and support Network Access Control architectures using IEEE 802.1X, RADIUS, and certificate-based authentication. Assess network security posture, develop remediation plans, and drive continuous security improvements. Cryptography, PKI & Certificate Management Own the enterprise PKI, cryptography, and certificate lifecycle management architecture, standards, and governance program. Design and manage certificate-based authentication and machine identity solutions for users, devices, servers, applications, cloud workloads, and network infrastructure across Azure, AWS, and hybrid environments. Implement and maintain certificate lifecycle automation using Microsoft Cloud PKI, Keyfactor, CyberArk Certificate Manager, EJBCA, DigiCert, AppViewX, or comparable platforms. Manage certificate issuance, enrollment, discovery, deployment, monitoring, renewal, revocation, auditing, and compliance across the enterprise. Design and support cryptographic services and certificate-based security controls, including TLS/mTLS, code signing, PKI trust hierarchies, certificate-based authentication, SCEP, PKCS, and machine identities. Establish PKI and cryptographic standards, key management practices, and security controls to support Zero Trust, regulatory compliance, and enterprise security requirements. Troubleshoot and resolve complex certificate, cryptographic, trust chain, authentication, and secure communications issues across enterprise systems and applications. Identity & Access Define authentication and authorization standards for workforce, partner, application, service, and machine identities. Design, implement, and maintain Microsoft Entra ID architecture, tenant governance, and identity security controls. Develop, test, and enforce Conditional Access policies and Zero Trust access controls. Implement and maintain MFA, passwordless authentication, phishing-resistant authentication, and Microsoft Entra ID Protection capabilities. Design and support enterprise SSO and federation integrations using SAML, OAuth 2.0, OpenID Connect, and SCIM. Implement least-privilege and risk-based access models across enterprise platforms. Administer RBAC, administrative separation, Microsoft Entra Privileged Identity Management, and least-privilege access controls. Govern application registrations, service principals, enterprise applications, API permissions, and managed identities. Support B2B collaboration, guest-user governance, external workforce access, and third-party identity integrations. Design and implement security controls across Microsoft Azure and AWS environments. Apply least privilege, RBAC, encryption, secrets management, and secure configuration standards to on-prem and cloud resources. Automate identity provisioning and deprovisioning, access governance, certificate management, configuration validation, and security operations. Create reusable secure-by-default templates and reduce manual administration through automation and orchestration Conduct access reviews, entitlement certifications, and identity governance activities. Education or Desired License and Certificates: Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field, or equivalent professional experience. Microsoft Certified: Identity and Access Administrator Associate (SC-300) preferred. Microsoft Certified: Azure Security Engineer Associate (AZ-500) preferred. CCNA, Fortinet, Zscaler, AWS Security, CISSP, CISM, Terraform, or relevant PKI certification preferred Preferred Experience & Qualifications: 5+ years of experience in security engineering, identity & access management (IAM), network security, cloud security, or a related enterprise IT discipline. Hands-on experience with Microsoft Entra ID, including Conditional Access, MFA, SSO, Identity Protection, PIM, RBAC, identity governance, and modern authentication protocols (SAML, OAuth, OpenID Connect, SCIM). Experience designing, implementing, and securing enterprise identity, privileged access, and machine identity solutions across hybrid and multi-cloud environments. Hands-on experience with Fortinet, Zscaler (ZIA/ZPA), Zero Trust architectures, least-privilege access models, and network security controls. Experience designing and operating enterprise PKI, certificate lifecycle management, certificate-based authentication, and machine identity platforms such as Keyfactor, DigiCert, EJBCA, AppViewX, CyberArk Certificate Manager, or similar solutions. Experience securing Azure and AWS environments, including identity, networking, encryption, secrets management, logging, and security monitoring. Experience with PAM and IGA platforms such as CyberArk, Delinea, BeyondTrust, SailPoint, Saviynt, or similar technologies. Experience integrating identity, network, cloud, and security telemetry with SIEM and security operations platforms. Strong automation and Infrastructure as Code skills using PowerShell, Python, Microsoft Graph API, REST APIs, Terraform, or similar technologies. Strong troubleshooting skills across authentication, federation, certificates, PKI, network security, cloud access, application integrations, and enterprise identity services. Knowledge of cybersecurity and compliance frameworks including SOC 2, ISO/IEC 27001, NIST CSF, NIST 800-63, CIS Controls, Zero Trust, and NERC CIP. Competencies: Mandarin fluency preferred but not required. Strong analytical, troubleshooting, and problem-solving skills. Ability to work independently and collaboratively in a fast-paced environment. Excellent communication, stakeholder management, and technical documentation skills. Strong organization, attention to detail, initiative, and ownership. Ability to balance security, reliability, usability, scalability, and business requirements. Proactive approach to automation, standardization, and continuous improvement. Travel 5%-20% Work Location and Status: Full time, Hybrid at any Sungrow USA office in Phoenix, Costa Mesa, or Houston No visa sponsorship Compensation: Compensation commensurate with experience Competitive salary and annual bonus eligibility Comprehensive benefits package including health, dental, vision, and retirement plans Strong personal and company growth opportunities Sungrow is an equal opportunity employer. Due to strong interest in this position, Sungrow will only reach out to those candidates who best meet the requirements. Thank you for your interest in Sungrow.
Conglomerateit
Atlanta, Georgia
Role: Network Security Engineer Location: Atlanta,GA (Hybrid) Job Type: Contract Long Term I am forwarding you the job description for further review Job Description: Client is seeking a highly skilled Network Security Engineer to support, implement, and optimize enterprise network security infrastructure across on-premises and cloud environments. The ideal candidate will have strong hands-on expertise in firewalls, secure network access, VPN technologies, SD-WAN, and modern network security solutions aligned with Zero Trust and SASE principles. The engineer will work closely with architecture, infrastructure, cloud, and operations teams to ensure secure, scalable, and resilient network environments supporting global business operations. Key Responsibilities Implement, configure, and support enterprise network security solutions across on-prem and cloud environments Manage and optimize firewalls, VPNs, IDS/IPS, web security, and secure remote access technologies Support Zero Trust and SASE/SSE initiatives under the guidance of Network Security Architecture teams Monitor network security posture and respond to security incidents, vulnerabilities, and threats Troubleshoot complex network and security issues across LAN, WAN, SD-WAN, and cloud connectivity Configure and maintain routing and switching protocols including BGP, OSPF, EIGRP, TCP/IP, and UDP Collaborate with cross-functional teams for secure network design, deployment, and operational support Assist in implementing security policies, standards, and compliance requirements Evaluate and recommend network security improvements, optimizations, and automation opportunities Support network observability and automation initiatives Maintain documentation for network configurations, security controls, and operational procedures Stay updated on emerging network security technologies and industry best practices Required Qualifications Bachelors degree in Computer Science, Information Technology, Cybersecurity, or related field (or equivalent experience) 5+ years of hands-on experience in Network Security Engineering Strong experience with enterprise firewall technologies and network security platforms Solid understanding of, Zero Trust Network principles, SASE/SSE solutions, SD-WAN technologies and VPN technologies and secure remote access Hands-on experience with one or more solutions such as, Zscaler ZIA/ZPA, Palo Alto Prisma Access, Cisco Secure Access and Next-Generation Firewalls (NGFW) Strong understanding of, TCP/IP, UDP, BGP, OSPF, EIGRP, DNS, DHCP, NAT and TLS/SSL, PKI Experience with IDS/IPS, Deep Packet Inspection, Malware Protection technologies Familiarity with cloud networking and security concepts in AWS and/or Azure Experience with network monitoring, logging, and observability tools Exposure to network automation tools and scripting is preferred Strong troubleshooting, analytical, and communication skills Preferred Certifications CCNP Security CCIE Security Palo Alto Certifications Zscaler Certifications CISSP (preferred)
Role: Network Security Engineer Location: Atlanta,GA (Hybrid) Job Type: Contract Long Term I am forwarding you the job description for further review Job Description: Client is seeking a highly skilled Network Security Engineer to support, implement, and optimize enterprise network security infrastructure across on-premises and cloud environments. The ideal candidate will have strong hands-on expertise in firewalls, secure network access, VPN technologies, SD-WAN, and modern network security solutions aligned with Zero Trust and SASE principles. The engineer will work closely with architecture, infrastructure, cloud, and operations teams to ensure secure, scalable, and resilient network environments supporting global business operations. Key Responsibilities Implement, configure, and support enterprise network security solutions across on-prem and cloud environments Manage and optimize firewalls, VPNs, IDS/IPS, web security, and secure remote access technologies Support Zero Trust and SASE/SSE initiatives under the guidance of Network Security Architecture teams Monitor network security posture and respond to security incidents, vulnerabilities, and threats Troubleshoot complex network and security issues across LAN, WAN, SD-WAN, and cloud connectivity Configure and maintain routing and switching protocols including BGP, OSPF, EIGRP, TCP/IP, and UDP Collaborate with cross-functional teams for secure network design, deployment, and operational support Assist in implementing security policies, standards, and compliance requirements Evaluate and recommend network security improvements, optimizations, and automation opportunities Support network observability and automation initiatives Maintain documentation for network configurations, security controls, and operational procedures Stay updated on emerging network security technologies and industry best practices Required Qualifications Bachelors degree in Computer Science, Information Technology, Cybersecurity, or related field (or equivalent experience) 5+ years of hands-on experience in Network Security Engineering Strong experience with enterprise firewall technologies and network security platforms Solid understanding of, Zero Trust Network principles, SASE/SSE solutions, SD-WAN technologies and VPN technologies and secure remote access Hands-on experience with one or more solutions such as, Zscaler ZIA/ZPA, Palo Alto Prisma Access, Cisco Secure Access and Next-Generation Firewalls (NGFW) Strong understanding of, TCP/IP, UDP, BGP, OSPF, EIGRP, DNS, DHCP, NAT and TLS/SSL, PKI Experience with IDS/IPS, Deep Packet Inspection, Malware Protection technologies Familiarity with cloud networking and security concepts in AWS and/or Azure Experience with network monitoring, logging, and observability tools Exposure to network automation tools and scripting is preferred Strong troubleshooting, analytical, and communication skills Preferred Certifications CCNP Security CCIE Security Palo Alto Certifications Zscaler Certifications CISSP (preferred)
Eliassen Group
Cary, North Carolina
Job Description Job Description Description: Associate Network Security Engineer Cary, NC • Hybrid Our client is seeking an Associate Cybersecurity Engineer for a 12 month contract, with potential for permanent conversion, to support the Information Security organization. This role focuses on monitoring network security activities and operating and optimizing security infrastructure. The engineer will drive policy, rule, and architecture improvements to prevent and remediate incidents, perform security configuration changes, and collaborate with IT and business stakeholders on triage. The position emphasizes enterprise firewalls, SASE and ZTNA, identity and access management, Microsoft security tooling, and process development aligned to best practices and regulatory requirements. Rate : $42.00 - $48.00 per hour W2 Responsibilities: Monitor network security activities and maintain oversight of security infrastructure. Implement, monitor, and manage enterprise firewall solutions, including NGFW, to enforce network security policies. Operate and configure SASE capabilities including secure web gateways, ZTNA, and CASB. Execute security configuration changes and support incident prevention and remediation through policy, rule, and architecture optimization. Collaborate with IT and business stakeholders on security triage and operational support. Leverage Microsoft Security Suite such as Defender for Endpoint, Sentinel, and Entra/Azure AD across on premises and cloud environments. Develop and refine procedures, policies, and processes aligned with best practices and regulatory requirements. Recommend remediation measures to improve security posture and reduce risk. Communicate security concepts to cross functional teams and stakeholders. Perform other related duties as assigned. Experience Requirements: 3+ years in cloud or network security engineering, security operations, insider risk management, or security event management. Hands on experience with identity, firewall, cloud, and SIEM tools such as Microsoft Azure, Okta, Duo, Palo Alto, Fortinet, Zscaler, Windows Defender, OCI, and Sentinel. Ability to convey complex information risk and security issues in an actionable manner. Demonstrated judgment, urgency, ethical standards, regulatory awareness, customer service, and business integrity. Preferred proficiency with automation or scripting such as Ansible, Python, KQL, or PowerShell. Strong written and oral communication skills and the ability to work cross functionally with network, cloud, infrastructure, and application teams. Strong organizational skills with the ability to prioritize and deliver in a fast paced environment. Ability to accommodate approximately 5% travel. Recruitment Transparency Notice Eliassen Group values transparency in our recruitment practices. Please be advised that Eliassen Group utilizes artificial intelligence (AI) tools as part of its initial application screening and hiring process. You may receive email and SMS notifications from the Eliassen Virtual Recruiting Team ( , ) inviting you to complete a brief voice screening as part of your application process. These tools assist our hiring teams in different ways, including but not limited to, assistance in reviewing application materials to help identify candidates whose qualifications most closely match the requirements of the position. All AI-assisted evaluations and responses are reviewed by human recruiters before any hiring decisions are made. The use of AI in our process is intended to support fairness, efficiency, and consistency, and Eliassen Group takes measures to prevent bias or discrimination in connection with its hiring practices. By proceeding, you acknowledge, agree, and consent to Eliassen Group's use of these tools, including AI tools, as part of the application and hiring process. Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range.W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality.If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following: When you work with Eliassen Group, all email communication will come from an address, never Gmail, Yahoo, etc. Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group. If you have any indication of fraudulent activity, please contact . About Eliassen Group: Eliassen Group is a strategic consulting firm that helps organizations reach further and achieve more through our technology, business advisory, and life sciences solutions. For nearly 40 years, we have combined exceptional people, deep domain expertise, and intelligent capabilities to expand our clients' capacity and accelerate meaningful outcomes. We are driven by a purpose to positively impact the lives of our employees, clients, consultants, and the communities we serve. Eliassen is committed to building a diverse and inclusive team from a variety of backgrounds, perspectives, and skills. We are an Equal Opportunity and Affirmative Action Employer and all employment decisions are based on merit, performance, and business needs. Eliassen does not discriminate on the basis of race, color, gender identity or expression, sexual preference or orientation, sex (including pregnancy, childbirth, and related medical conditions), marital status, creed, religion, physical or mental disability, genetic information, military or veteran status, age, ancestry, national origin, citizenship status, prohibited criminal record inquiries of applicants and employees, or any other category protected by federal, state, or local laws. Don't miss out on our referral program! If we hire a candidate that you refer us to then you can be eligible for a $1,000 referral check!
Job Description Job Description Description: Associate Network Security Engineer Cary, NC • Hybrid Our client is seeking an Associate Cybersecurity Engineer for a 12 month contract, with potential for permanent conversion, to support the Information Security organization. This role focuses on monitoring network security activities and operating and optimizing security infrastructure. The engineer will drive policy, rule, and architecture improvements to prevent and remediate incidents, perform security configuration changes, and collaborate with IT and business stakeholders on triage. The position emphasizes enterprise firewalls, SASE and ZTNA, identity and access management, Microsoft security tooling, and process development aligned to best practices and regulatory requirements. Rate : $42.00 - $48.00 per hour W2 Responsibilities: Monitor network security activities and maintain oversight of security infrastructure. Implement, monitor, and manage enterprise firewall solutions, including NGFW, to enforce network security policies. Operate and configure SASE capabilities including secure web gateways, ZTNA, and CASB. Execute security configuration changes and support incident prevention and remediation through policy, rule, and architecture optimization. Collaborate with IT and business stakeholders on security triage and operational support. Leverage Microsoft Security Suite such as Defender for Endpoint, Sentinel, and Entra/Azure AD across on premises and cloud environments. Develop and refine procedures, policies, and processes aligned with best practices and regulatory requirements. Recommend remediation measures to improve security posture and reduce risk. Communicate security concepts to cross functional teams and stakeholders. Perform other related duties as assigned. Experience Requirements: 3+ years in cloud or network security engineering, security operations, insider risk management, or security event management. Hands on experience with identity, firewall, cloud, and SIEM tools such as Microsoft Azure, Okta, Duo, Palo Alto, Fortinet, Zscaler, Windows Defender, OCI, and Sentinel. Ability to convey complex information risk and security issues in an actionable manner. Demonstrated judgment, urgency, ethical standards, regulatory awareness, customer service, and business integrity. Preferred proficiency with automation or scripting such as Ansible, Python, KQL, or PowerShell. Strong written and oral communication skills and the ability to work cross functionally with network, cloud, infrastructure, and application teams. Strong organizational skills with the ability to prioritize and deliver in a fast paced environment. Ability to accommodate approximately 5% travel. Recruitment Transparency Notice Eliassen Group values transparency in our recruitment practices. Please be advised that Eliassen Group utilizes artificial intelligence (AI) tools as part of its initial application screening and hiring process. You may receive email and SMS notifications from the Eliassen Virtual Recruiting Team ( , ) inviting you to complete a brief voice screening as part of your application process. These tools assist our hiring teams in different ways, including but not limited to, assistance in reviewing application materials to help identify candidates whose qualifications most closely match the requirements of the position. All AI-assisted evaluations and responses are reviewed by human recruiters before any hiring decisions are made. The use of AI in our process is intended to support fairness, efficiency, and consistency, and Eliassen Group takes measures to prevent bias or discrimination in connection with its hiring practices. By proceeding, you acknowledge, agree, and consent to Eliassen Group's use of these tools, including AI tools, as part of the application and hiring process. Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range.W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality.If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following: When you work with Eliassen Group, all email communication will come from an address, never Gmail, Yahoo, etc. Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group. If you have any indication of fraudulent activity, please contact . About Eliassen Group: Eliassen Group is a strategic consulting firm that helps organizations reach further and achieve more through our technology, business advisory, and life sciences solutions. For nearly 40 years, we have combined exceptional people, deep domain expertise, and intelligent capabilities to expand our clients' capacity and accelerate meaningful outcomes. We are driven by a purpose to positively impact the lives of our employees, clients, consultants, and the communities we serve. Eliassen is committed to building a diverse and inclusive team from a variety of backgrounds, perspectives, and skills. We are an Equal Opportunity and Affirmative Action Employer and all employment decisions are based on merit, performance, and business needs. Eliassen does not discriminate on the basis of race, color, gender identity or expression, sexual preference or orientation, sex (including pregnancy, childbirth, and related medical conditions), marital status, creed, religion, physical or mental disability, genetic information, military or veteran status, age, ancestry, national origin, citizenship status, prohibited criminal record inquiries of applicants and employees, or any other category protected by federal, state, or local laws. Don't miss out on our referral program! If we hire a candidate that you refer us to then you can be eligible for a $1,000 referral check!
Zoox
San Mateo, California
Job Description Job Description Zoox's Network Security team architects and defends the digital borders of the company - from corporate offices to engineering labs and product/mission environments. As a Network Security Engineer, you will design, implement, and operate security controls across Zoox's enterprise, OT networks, and cloud infrastructure spanning on-premises data centers and public cloud environments (AWS, GCP), partnering closely with Network Engineering, IT, Product Security, and Software Engineering teams. In This Role, You Will Design, implement, and maintain secure hybrid/multi-cloud network architectures (AWS/GCP, CloudWAN); enforce zero-trust access controls and network segmentation across corporate, data center, lab, and edge environments; develop and maintain related policies, standards, and architecture diagrams Own and operate next-generation firewall platforms (Palo Alto Networks, Fortinet), managing policy architecture, segmentation, NAT, URL filtering, SSL/TLS decryption, and threat prevention tuning Architect, operate, and own the lifecycle of secure remote access solutions (VPN, ZTNA, site-to-site tunnels), ensuring high availability, certificate-based authentication, and integration with identity providers (SAML, Entra ID) Drive automation and Infrastructure-as-Code (IaC) using Terraform, Python, CI/CD, and REST APIs for configuration management, firewall policies, and security baselines; integrate LLM-based tools to streamline operational tasks and reduce manual toil Oversee security operations including 24/7 network security monitoring, traffic analysis, threat detection, vulnerability assessments, and remediation; support compliance requirements by conducting security reviews for new projects and infrastructure changes Drive 802.1X/certificate-based Network Access Control (NAC) initiatives across wired and wireless environments Collaborate with team members and contribute to cross-functional security initiatives with Product Security, SRE, IT, and Software Engineering teams Qualifications 6+ years of network security engineering experience securing enterprise, cloud, and OT/lab environments Platform Expertise: Deep, hands-on expertise in next-gen firewalls (Palo Alto, Fortinet), AWS NFW, WAFs, IDS/IPS, NAC/802.1X, PKI, VPN, and ZTNA solutions (Zscaler, Netskope, Prisma Access, or equivalent) Technical Knowledge: Strong understanding of core network protocols (TCP/IP, BGP, OSPF, VLAN, 802.1X, TLS/PKI) and cloud networking security principles (AWS, GCP, or Azure) Automation: Hands-on experience with IaC and automation tooling including Terraform, Python, CI/CD pipelines, and REST APIs Security Operations: Experience with network security monitoring, threat detection, and security operations tooling (SIEM, IDS/IPS, vulnerability management platforms), including integration with network controls Compliance: Proven experience supporting major compliance initiatives (NIST 800-53, CSF 2.0, ISO 27001), including control implementation and evidence collection Bonus Qualifications Experience in autonomous vehicle, robotics, IT/OT or automotive environments Certifications: PCNSE, AWS Security Specialty, CCNA Experience experimenting with or deploying AI/ML-based security capabilities (e.g., anomaly detection, behavioral analytics, LLM-driven copilots) in network or cloud security workflows There are three major components to compensation for this position: salary, Amazon Restricted Stock Units (RSUs), and Zoox Stock Appreciation Rights. A sign-on bonus may be offered as part of the compensation package. The listed range applies only to the base salary. Compensation will vary based on geographic location and level. Leveling, as well as positioning within a level, is determined by a range of factors, including, but not limited to, a candidate's relevant years of experience, domain knowledge, and interview performance. The salary range listed in this posting is representative of the range of levels Zoox is considering for this position. Zoox also offers a comprehensive package of benefits, including paid time off (e.g. sick leave, vacation, bereavement), unpaid time off, Zoox Stock Appreciation Rights, Amazon RSUs, health insurance, long-term care insurance, long-term and short-term disability insurance, and life insurance. About Zoox Zoox is developing the first ground-up, fully autonomous vehicle fleet and the supporting ecosystem required to bring this technology to market. Sitting at the intersection of robotics, machine learning, and design, Zoox aims to provide the next generation of mobility-as-a-service in urban environments. We're looking for top talent that shares our passion and wants to be part of a fast-moving and highly execution-oriented team. Follow us on LinkedIn Accommodations If you need an accommodation to participate in the application or interview process please reach out to or your assigned recruiter. A Final Note: You do not need to match every listed expectation to apply for this position. Here at Zoox, we know that diverse perspectives foster the innovation we need to be successful, and we are committed to building a team that encompasses a variety of backgrounds, experiences, and skills. We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Job Description Job Description Zoox's Network Security team architects and defends the digital borders of the company - from corporate offices to engineering labs and product/mission environments. As a Network Security Engineer, you will design, implement, and operate security controls across Zoox's enterprise, OT networks, and cloud infrastructure spanning on-premises data centers and public cloud environments (AWS, GCP), partnering closely with Network Engineering, IT, Product Security, and Software Engineering teams. In This Role, You Will Design, implement, and maintain secure hybrid/multi-cloud network architectures (AWS/GCP, CloudWAN); enforce zero-trust access controls and network segmentation across corporate, data center, lab, and edge environments; develop and maintain related policies, standards, and architecture diagrams Own and operate next-generation firewall platforms (Palo Alto Networks, Fortinet), managing policy architecture, segmentation, NAT, URL filtering, SSL/TLS decryption, and threat prevention tuning Architect, operate, and own the lifecycle of secure remote access solutions (VPN, ZTNA, site-to-site tunnels), ensuring high availability, certificate-based authentication, and integration with identity providers (SAML, Entra ID) Drive automation and Infrastructure-as-Code (IaC) using Terraform, Python, CI/CD, and REST APIs for configuration management, firewall policies, and security baselines; integrate LLM-based tools to streamline operational tasks and reduce manual toil Oversee security operations including 24/7 network security monitoring, traffic analysis, threat detection, vulnerability assessments, and remediation; support compliance requirements by conducting security reviews for new projects and infrastructure changes Drive 802.1X/certificate-based Network Access Control (NAC) initiatives across wired and wireless environments Collaborate with team members and contribute to cross-functional security initiatives with Product Security, SRE, IT, and Software Engineering teams Qualifications 6+ years of network security engineering experience securing enterprise, cloud, and OT/lab environments Platform Expertise: Deep, hands-on expertise in next-gen firewalls (Palo Alto, Fortinet), AWS NFW, WAFs, IDS/IPS, NAC/802.1X, PKI, VPN, and ZTNA solutions (Zscaler, Netskope, Prisma Access, or equivalent) Technical Knowledge: Strong understanding of core network protocols (TCP/IP, BGP, OSPF, VLAN, 802.1X, TLS/PKI) and cloud networking security principles (AWS, GCP, or Azure) Automation: Hands-on experience with IaC and automation tooling including Terraform, Python, CI/CD pipelines, and REST APIs Security Operations: Experience with network security monitoring, threat detection, and security operations tooling (SIEM, IDS/IPS, vulnerability management platforms), including integration with network controls Compliance: Proven experience supporting major compliance initiatives (NIST 800-53, CSF 2.0, ISO 27001), including control implementation and evidence collection Bonus Qualifications Experience in autonomous vehicle, robotics, IT/OT or automotive environments Certifications: PCNSE, AWS Security Specialty, CCNA Experience experimenting with or deploying AI/ML-based security capabilities (e.g., anomaly detection, behavioral analytics, LLM-driven copilots) in network or cloud security workflows There are three major components to compensation for this position: salary, Amazon Restricted Stock Units (RSUs), and Zoox Stock Appreciation Rights. A sign-on bonus may be offered as part of the compensation package. The listed range applies only to the base salary. Compensation will vary based on geographic location and level. Leveling, as well as positioning within a level, is determined by a range of factors, including, but not limited to, a candidate's relevant years of experience, domain knowledge, and interview performance. The salary range listed in this posting is representative of the range of levels Zoox is considering for this position. Zoox also offers a comprehensive package of benefits, including paid time off (e.g. sick leave, vacation, bereavement), unpaid time off, Zoox Stock Appreciation Rights, Amazon RSUs, health insurance, long-term care insurance, long-term and short-term disability insurance, and life insurance. About Zoox Zoox is developing the first ground-up, fully autonomous vehicle fleet and the supporting ecosystem required to bring this technology to market. Sitting at the intersection of robotics, machine learning, and design, Zoox aims to provide the next generation of mobility-as-a-service in urban environments. We're looking for top talent that shares our passion and wants to be part of a fast-moving and highly execution-oriented team. Follow us on LinkedIn Accommodations If you need an accommodation to participate in the application or interview process please reach out to or your assigned recruiter. A Final Note: You do not need to match every listed expectation to apply for this position. Here at Zoox, we know that diverse perspectives foster the innovation we need to be successful, and we are committed to building a team that encompasses a variety of backgrounds, experiences, and skills. We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.