Principal Network Security Engineer

Verizon Verizon · Telecom · Southlake, TX +5

Principal Network Security Engineer at Verizon responsible for safeguarding critical routing infrastructure and data center fabrics. The role involves building threat detections, improving security hygiene, and implementing network security fundamentals. Requires expertise in various network operating systems (Cisco, Nokia, Juniper, F5) and the ability to translate security frameworks into device configurations. Responsibilities include log analysis, incident response, architecting security hardening, designing ACLs, and using automation tools for lifecycle management and threat modeling. The role also involves driving adversary emulation against MITRE ATT&CK for Network Devices.

What you'd actually do

  1. Providing recommendations to improve defensive cyberspace operations - internal defensive measures (DCO-IDM) and the cyber resiliency of the portfolio’s systems and services.
  2. Collaborating with stakeholders to improve the core networking security posture through the assessment and implementation of the Network Security Fundamentals (Access Management, Situational Awareness, Configuration Hardening, Vulnerability Mitigation).
  3. Providing recommendations to improve defensive cybersecurity practices.
  4. Discovering, identifying, and confirming inventory of all network assets and asset information (model, version, etc) in your respective area of responsibility.
  5. Building a deep understanding of the network assets and the roadmap to quickly assess the impact of vulnerabilities and identify End-of-Life/End-of-Support hardware/software.

Skills

Required

  • Data networking
  • Telecommunications
  • TCP/IP (IPv4 & IPv6)
  • VXLAN
  • SR
  • EVPN
  • OSPF
  • BGP
  • Cisco IOS XE/XR/NX-OS
  • Nokia SR OS
  • Juniper OS
  • F5 F5OS/TMOS
  • Spine-Leaf architecture
  • Data center fabrics
  • BGP security (RPKI, prefix-lists, TTL security)
  • IGP security (OSPF/IS-IS authentication)
  • CIS Benchmarks
  • MITRE ATT&CK for Network Devices
  • Ansible
  • Spunk
  • Log analysis
  • Incident response protocols
  • ACL design and auditing
  • Network asset inventory
  • Vulnerability assessment
  • End-of-Life/End-of-Support hardware/software identification
  • Threat modeling
  • Automation tools
  • Programmatic methods
  • Life cycle management workflows
  • Configuration compliance
  • Adversary emulation

Nice to have

  • CCIE (Service Provider or Security)
  • Nokia NRS II (Nokia Routing Specialist) or SRA (Service Routing Architect)
  • JNCIE (Service Provider or Security)
  • F5 Certified Technology Specialist (BIG-IP) or Solution Expert
  • CISSP

What the JD emphasized

  • expert knowledge of TCP/IP (IPv4 & IPv6), VXLAN, SR, EVPN, OSPF, and BGP
  • expert knowledge of Cisco IOS XE/XR/NX-OS, Nokia SR OS, Juniper OS, and F5 F5OS/TMOS
  • Proven experience securing Spine-Leaf architecture and data center fabrics with strong knowledge of BGP security (RPKI, prefix-lists, TTL security) and IGP security (OSPF/IS-IS authentication)
  • Framework fluency in CIS Benchmarks applying Level 1 & Level 2 hardening profiles
  • MITRE ATT&CK: Ability to explain how specific network controls mitigate specific TTPs (Tactics, Techniques, and Procedures) in the Network Devices matrix