View all jobs

Network Security Consultant

  • REMOTE, SK, AB, BC, MB, ON, QC

<meta />

Visionpool Business Servies is hiring a REMOTE Network Security Consultant Resource who will serve as a senior subject matter expert responsible for the governance, architecture, and oversight of enterprise network security controls across on-premises and hybrid cloud environments.  The Consultant will provide security guidance on network and application designs, with a focus on Cisco-based security platforms, ensuring alignment with enterprise standards, zoning and segmentation models, and zero trust principles.  

Responsibilities: 

  • Design, implement, and manage enterprise network security controls across Cisco security platforms including Cisco Firepower Threat Defense (FTD) firewalls (LINA and SNORT engines), Cisco FMC (Firepower Management Center), Cisco Umbrella DNS / OpenDNS, Cisco Web Security Appliances (WSA), Cisco Secure Malware Analytics (Sandboxing). 

  • Provide governance oversight and security expertise for remote access solutions, including VPN services on Cisco FTD platforms, ensuring configurations align with enterprise security standards, access control policies, and zero trust principles. 

  • Act as a subject matter expert for troubleshooting and triaging network security incidents, alerts, and anomalies related to firewall, IPS, DNS, and web security technologies. 

  • Perform continuous review and tuning of Intrusion Prevention System (IPS) / Intrusion Detection System (IDS) signatures, firewall rules, and traffic inspection policies to improve detection capabilities and reduce false positives. 

  • Participate in Architecture Review Board (ARB) meetings as the designated Network Security representative to review solution architectures. 

  • Evaluate proposed network and application architectures to ensure alignment with enterprise security standards, zoning models, and segmentation requirements. 

  • Review and approve firewall rule changes and ensure proper implementation of network segmentation and zone-based security controls within datacenter and hybrid environments. 

  • Provide security design guidance and recommendations for new and existing services, ensuring adherence to zero-trust principles and enterprise security frameworks. 

  • Design and secure hybrid environments integrating on-premises datacenter infrastructure with Azure cloud services. 

  • Provide expertise in Azure networking and security controls, including Virtual networks (VNets), subnets, and network security groups (NSGs), Azure Firewall and application gateways, Identity and Access Management (IAM), Privileged Access Management (PAM),Conditional Access, and Role-Based Access Control (RBAC) 

  • Support security integration efforts related to Broadcom VMware Cloud Foundation (VCF) technologies and associated virtualized networking/security stacks. 

  • Evaluate and integrate emerging network security technologies, including automation, orchestration, and Artificial Intelligence (AI) / Machine Learning (ML) - based threat detection capabilities. 

  • Conduct deep traffic analysis and threat investigations using network telemetry, packet capture tools, and security analytics platforms. 

  • Lead or support incident response activities related to network security breaches, including containment, root cause analysis, and remediation. 

  • Identify security gaps, misconfigurations, and risks in network security infrastructure and recommend remediation strategies aligned to best practices and compliance requirements. 

  • Collaborate with security and infrastructure teams to identify, assess, and remediate network-related vulnerabilities. 

  • Support and participate in network security penetration testing and validation activities. 

  • Contribute to the design and validation of disaster recovery (DR) and business continuity plan (BCP) strategies from a network security perspective. 

  • Strong understanding of load balancing technologies, particularly F5 load balancers, with the ability to review and assess traffic flow configurations, including traffic distribution and redirection to backend servers, ensuring alignment with enterprise security controls and design standards. 

  • Ensure critical network security controls are resilient, recoverable, and aligned with failover and replication strategies across datacenters. 

  • Develop and maintain high-quality documentation including network security architecture designs, standards, and operational procedures. 

  • Act as a trusted advisor to cross-functional teams, providing guidance on secure network design and implementation. 

Qualifications: 

  • Minimum of 10 years of progressively responsible, hands-on information technology experience  

  • Minimum 8 years of direct experience in one or more of the following areas: 

  • Network security engineering 

  • Network security architecture 

  • Network security operations 

  • Enterprise firewall engineering and administration 

  • Secure network design and implementation. 

  • Must hold at least one (1) active professional-level or expert-level certification from the following list: 

  • Certified Information Systems Security Professional — CISSP 

  • Certified Information Security Manager — CISM 

  • Certified Cloud Security Professional — CCSP 

  • Cisco Certified Internetwork Expert Security — CCIE Security 

  • Cisco Certified Network Professional Security — CCNP Security 

  • Juniper Networks Certified Professional, Security — JNCIP-SEC 

  • Juniper Networks Certified Expert, Security — JNCIE-SEC 

  • Check Point Certified Security Expert — CCSE 

  • Palo Alto Networks Certified Network Security Professional 

  • Palo Alto Networks Certified Network Security Architect 

  • Microsoft Certified: Azure Security Engineer Associate 

  • Microsoft Certified: Azure Solutions Architect Expert 

  • Microsoft Certified: Azure Network Engineer Associate 

  • Must be able to travel within Saskatchewan as required to support site visits across multiple locations. 

  • Bachelor’s degree in Information Security, Computer Science, Engineering, or a related field 

  • Minimum 10 years of experience in network security and enterprise infrastructure environments. 

  • Strong expertise in network security architecture, design, and governance, including segmentation, zoning, and zero trust principles. 

  • Demonstrated hands-on experience with enterprise network security technologies, including Cisco Firepower Threat Defense (FTD), FMC, IPS/IDS, DNS and web security controls (Cisco Umbrella/OpenDNS, Web Security Appliances) 

  • Deep understanding of network security controls including firewalls, IPS/IDS, VPNs, encryption, Uniform Resource Locator (URL) / Domain Name System (DNS) filtering, and network segmentation. 

  • Solid foundational knowledge of networking concepts including routing, switching, and common protocols. 

  • Experience in network traffic analysis, threat detection, and incident response using industry-standard monitoring and forensic tools. 

  • Familiarity with Security Information and Event Management SIEM), Security Orchestration, Automation, and Response (SOAR), Network Detection and Response (NDR), Endpoint Detection and Response (EDR), and vulnerability management platforms. 

  • Ability to identify security gaps, misconfigurations, and risks and recommend remediation strategies aligned with security best practices. 

  • Experience reviewing and validating network and security architectures to ensure alignment with enterprise security standards and compliance requirements. 

  • Ability to provide security governance, design recommendations, and risk assessments for new and existing solutions. 

  • Strong understanding of hybrid cloud security models, particularly within Microsoft Azure environments. 

  • Familiarity with network security penetration testing concepts and methodologies. 

  • Understanding of disaster recovery (DR) and business continuity planning (BCP) from a network security perspective. 

  • Proven ability to work with cross-functional teams, including infrastructure, cloud, and architecture teams. 

  • Strong communication skills with the ability to act as a subject matter expert and trusted advisor on network security matters. 

  • Cisco certifications such as CCNP Security or CCIE Security. 

  • Industry certifications such as CISSP, CISM, CCSP or equivalent. 

  • Cloud security certifications (e.g., Microsoft Azure Security) are an asset.