Back to jobs
New

Security Network Engineer

Mexico City, Mexico City, Mexico

Location: Fully Remote

Work Arrangement: 100% remote

Contract Length: At least 1 year

Contract Rate: $29.30 per hour in USD. Final rate will be determined based on relevant experience and overall fit for the position.

NTT DATA is seeking a highly skilled Senior Network Security Engineer to help secure, optimize, and transform an enterprise network environment. This role will lead a key migration from Check Point to Fortinet firewalls while maintaining secure, reliable connectivity across corporate, cloud, branch, and remote environments. The engineer will also support and enhance SD-WAN, routing, cloud security, DDoS protection, and network automation capabilities.

Responsibilities:

  • Lead the migration from Check Point to Fortinet, including policy conversion, rule optimization, testing, and traffic validation.
  • Manage and maintain Cisco ASA, Palo Alto, Fortinet FortiGate, and Check Point firewalls across corporate, cloud, and remote sites.
  • Design and optimize firewall rule sets to improve security, performance, and compliance.
  • Perform network security risk assessments, firewall audits, and configuration reviews.
  • Manage and optimize SD-WAN architecture to improve application performance, resilience, and latency.
  • Implement policy-based traffic steering, failover mechanisms, and WAN optimization.
  • Integrate SD-WAN with firewalls, cloud security solutions, branch locations, and on-premises networks.
  • Troubleshoot SD-WAN performance issues, routing conflicts, and connectivity problems.
  • Design and implement static NAT, dynamic NAT, and Port Address Translation (PAT) policies.
  • Configure and troubleshoot EIGRP, BGP, and OSPF for enterprise and cloud routing.
  • Optimize routing policies for high availability, redundancy, and performance.
  • Administer and optimize Zscaler ZIA and ZPA for secure cloud access and web filtering.
  • Implement zero-trust security policies for cloud applications and remote users.
  • Troubleshoot Zscaler tunnels, proxy configurations, and application access issues.
  • Implement and maintain Radware DDoS protection against volumetric and application-layer attacks.
  • Configure IPS and IDS solutions to detect and mitigate security threats.
  • Partner with SOC teams to analyze and respond to security incidents.
  • Lead troubleshooting for firewall, SD-WAN, NAT, and routing issues affecting business-critical applications.
  • Use packet captures and security logs to diagnose complex network problems.
  • Coordinate with Cisco, Fortinet, Palo Alto, and Zscaler support teams to resolve complex technical issues.
  • Develop and enforce network security policies aligned with NIST, CIS Benchmarks, and ISO 27001.
  • Maintain current documentation for firewall rules, SD-WAN policies, routing, and security configurations.
  • Develop Python, Bash, or PowerShell scripts to automate firewall audits and SD-WAN policy updates.
  • Implement network automation frameworks to streamline security operations and improve efficiency.

Required Experience:

  • 5 to 8 years of experience in network security engineering.
  • Expertise with Fortinet FortiGate, Check Point, Palo Alto, and Cisco ASA firewalls.
  • Strong knowledge of SD-WAN solutions, including Fortinet SD-WAN, Cisco SD-WAN, and Prisma Access.
  • Experience configuring and troubleshooting EIGRP, BGP, and OSPF routing protocols.
  • Hands-on experience managing Zscaler ZIA and ZPA cloud security solutions.
  • Proficiency with VPN technologies, including IPsec, SSL, GRE, DMVPN, and L2TP, and an understanding of their security implications.
  • Strong skills in NAT, firewall rule optimization, and routing table analysis.
  • Experience with Radware DDoS protection, IPS/IDS, and threat mitigation.
  • Knowledge of zero-trust security architectures and secure SD-WAN implementation.
  • Strong analytical and troubleshooting skills using packet captures, firewall logs, and security telemetry.
  • Familiarity with ticketing tools.
  • Good communication and interpersonal skills, a proactive attitude, and the ability to work effectively as part of a team.

Nice-to-Have:

  • Experience leading enterprise firewall migration projects, particularly from Check Point to Fortinet.
  • Experience working in complex enterprise environments that connect on-premises, branch, remote-user, and cloud networks.
  • Network security automation experience using Python, Bash, or PowerShell.

Tools & Technologies:

  • Fortinet FortiGate and Fortinet SD-WAN; Check Point; Palo Alto and Prisma Access; Cisco ASA and Cisco SD-WAN.
  • Zscaler ZIA/ZPA; Radware DDoS protection; IPS/IDS technologies.
  • EIGRP, BGP, OSPF, NAT, PAT, IPsec, SSL, GRE, DMVPN, and L2TP.
  • Python, Bash, PowerShell, packet-capture tools, security logs, and ticketing platforms.
  • NIST, CIS Benchmarks, and ISO 27001 security frameworks and standards.

Education & Certifications:

Preferred certifications include Fortinet NSE 4 or NSE 7, Check Point CCSA or CCSE, Palo Alto PCNSA or PCNSE, Cisco CCNP Security, Zscaler ZCCP, and relevant SD-WAN certifications.

Required Equipment:

This role requires the use of a personal laptop. Candidates must be comfortable with company security software and device management tools being installed on their laptop as part of the onboarding process and for the duration of the engagement.

About NTT DATA

NTT DATA is a Top 5 global IT services provider with more than 190,000 professionals across 50+ countries. We combine industry expertise with capabilities in consulting, technology, AI, cloud, applications, infrastructure, and connectivity to help organizations innovate, optimize, and transform. Through responsible innovation, we deliver meaningful business outcomes, accelerate client success, and create a positive impact on society.

Equal Opportunity Employer

NTT DATA is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity/Affirmative Action-Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. NTT DATA is an Equal Opportunity Employer Male/Female/Disabled/Veteran and a VEVRAA Federal Contractor.

Req ID: 1345

 

Create a Job Alert

Interested in building your career at NTT DATA, Europe & LATAM, Branch in USA, Inc.? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Education

Select...
Select...
Select...
Select...
Select...

What is your desired hourly rate?

City, State

Select...

This position requires a person to be onsite in Boston, MA. Are you local or willing to relocate?

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in NTT DATA, Europe & LATAM, Branch in USA, Inc.’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...