Network Security Engineer
Safran
Job details Domain Performance and Support Job field / Job profile IT - Telecom network technician
Job title Network Security Engineer Employment type Permanent Professional category Employees / Staff Part time / Full time Full-time Job description The Network Security Engineer L3 is a hands-on technical role within Safran USA's (SUSA) IT Shared Services organization. This position is responsible for the day-to-day operations, administration, and continuous improvement of the SUSA corporate network and datacenter infrastructure across all US subsidiary entities. The engineer is expected to be deeply technical - configuring, troubleshooting, and maintaining the network stack directly - working under the Cloud & Infrastructure Manager and collaborating with Safran IT network peers globally on standards alignment. Global network architecture and strategy remain the responsibility of the Safran Group team in France; this role is the hands-on owner of the US environment. Key Responsibilities
Datacenter & Campus Networking
• Configure and maintain network services and assets across core, distribution, access, and DMZ layers.
• Administer enterprise firewall platforms: policy management, NAT, VPNs, and traffic segmentation across SUSA sites.
• Ensure proper network segmentation and boundary protection within datacenter and WAN environments.
• Act as the L3 escalation point for complex network and security incidents; coordinate with service providers and internal IT teams as needed.
• Maintain accurate and up-to-date network documentation: diagrams, standards, and operating procedures. Network Security & Restricted Environments
• Administer Zscaler ZIA and ZPA: maintain tunnel configurations, user traffic policies, and access rules in coordination with the Cloud & Infrastructure Manager.
• Manage Forcepoint Web Security policies for web filtering on CUI-handling endpoints.
• Administer WAF policies (F5 / Fortinet / Cloudflare): maintain and tune rules to protect SUSA-hosted applications, respond to alerts, and coordinate rule updates with application owners.
• Conduct regular firewall rule reviews; maintain documented security zone matrices and policy change records.
CMMC 2.0 Compliance Support
• Maintain accurate SUSA network diagrams and data-flow documentation for use in the System Security Plan (SSP).
• Support the CMMC compliance team on network-related controls (NIST SP 800-171 domains 3.1, 3.13); provide technical input for assessments and POA&M remediation.
• Validate that network changes do not introduce unintended CUI exposure; coordinate with the compliance team before implementing boundary modifications. Operations, Knowledge Transfer & Collaboration
• Manage hardware lifecycle and procurement; contribute network infrastructure inputs to the annual CAPEX/OPEX budget process.
• Document standard operating procedures, change records, and incident post-mortems in the ITSM platform.
• Apply Safran security and network policies and standards as directed by the Group network team.
• Coordinate technical actions with teams located at Safran headquarters (France) and in India.
• Define and organize knowledge transfer activities to L1 and L2 support teams. But what else? (advantages, specificities, etc.) Technology Stack & Platform Exposure
The following table reflects the platforms in the SUSA environment. Candidates are not expected to hold deep expertise across every row - strong routing/switching fundamentals and at least one security platform anchor are the core requirement. Other skills will be developed on the job. Routing & Switching Cisco Catalyst / Nexus | BGP / OSPF / EIGRP | VLANs / STP / QoS | L2/L3 troubleshooting | Datacenter fabric
Firewall / NGFW Palo Alto Networks (PA Series) | Fortinet FortiGate | Cisco Firepower (FTD / FMC) | Panorama | Policy & NAT management
Zero Trust / SWG Zscaler ZIA / ZPA | Forcepoint Web Security | Tunnel configuration | User traffic policies
WAF F5 / Fortinet / Cloudflare WAF | OWASP Top 10 rule tuning | Application traffic inspection | Alert response
Network Access Control Cisco ISE | 802.1X Authentication | RADIUS / TACACS+ | Posture assessment
WAN & Connectivity MPLS circuit management | Site-to-site VPN | Internet breakout | ISP coordination
Cloud Networking AWS VPC basics | Security groups | Site-to-site VPN | Hybrid connectivity
Monitoring & Tools SolarWinds NPM / NTA | NetFlow / SNMP / Syslog | Wireshark | Change & incident management Candidate skills & requirements Qualifications
Required
• 8+ years of network engineering experience with a clear focus on network security operations.
• Strong expertise in routing and switching, preferably in datacenter environments.
• Solid knowledge of TCP/IP, BGP, OSPF, VLANs, redundancy, and QoS.
• Experience administering enterprise firewalls (any major platform).
• Proven ability to troubleshoot complex L2/L3 network issues.
• Experience working in security- or compliance-driven environments. Preferred
• Cisco CCNP certification (or equivalent routing/switching depth).
• Hands-on knowledge of at least one firewall platform: Palo Alto Networks, Fortinet, or Cisco Firepower.
• Familiarity with Zscaler ZIA/ZPA, WAF platforms, or Forcepoint.
• Basic AWS networking knowledge (VPC, security groups, site-to-site VPN).
• Exposure to Python or Ansible for routine network automation tasks.
• Familiarity with CMMC, NIST 800-171, or similar regulatory frameworks.
• Background in manufacturing, aerospace, or defense-adjacent IT environments. Core Competencies
• Security-first engineering mindset - designs with defense-in-depth as the default.
• Collaborative team player - works effectively with peers in France and across SUSA IT teams.
• Operational discipline - follows change management processes and keeps documentation current.
• Problem-solving under pressure - methodical troubleshooting during network incidents.
• Ownership & accountability - drives issues to resolution without requiring escalation. Team & Reporting Context
This role reports to the Cloud & Infrastructure Manager, Safran USA IT, and works day-to-day with:
• Cloud & Infrastructure team peers (server, storage, datacenter operations)
• CMMC compliance team (network diagram and SSP support)
• End User Services / helpdesk (NAC, VPN, and wireless escalations)
• Safran IT network administrators in France and India (peer coordination on standards, cross-site connectivity, shared platform configurations, and shift-left activities)
• SUSA subsidiary IT contacts and service stakeholders Annual salary TBD Job location Job location North America, United States, Texas City (-ies) 2201 W. Royal Lane Irving, TX 75063 Irving Applicant criteria Minimum education level achieved Bachelor's Degree Minimum experience level required More than 5 years Additional Languages preferred English (Fluent) ITAR Controlled Position: Select "Yes" if role requires U.S. citizenship/permanent residency Yes
Job title Network Security Engineer Employment type Permanent Professional category Employees / Staff Part time / Full time Full-time Job description The Network Security Engineer L3 is a hands-on technical role within Safran USA's (SUSA) IT Shared Services organization. This position is responsible for the day-to-day operations, administration, and continuous improvement of the SUSA corporate network and datacenter infrastructure across all US subsidiary entities. The engineer is expected to be deeply technical - configuring, troubleshooting, and maintaining the network stack directly - working under the Cloud & Infrastructure Manager and collaborating with Safran IT network peers globally on standards alignment. Global network architecture and strategy remain the responsibility of the Safran Group team in France; this role is the hands-on owner of the US environment. Key Responsibilities
Datacenter & Campus Networking
• Configure and maintain network services and assets across core, distribution, access, and DMZ layers.
• Administer enterprise firewall platforms: policy management, NAT, VPNs, and traffic segmentation across SUSA sites.
• Ensure proper network segmentation and boundary protection within datacenter and WAN environments.
• Act as the L3 escalation point for complex network and security incidents; coordinate with service providers and internal IT teams as needed.
• Maintain accurate and up-to-date network documentation: diagrams, standards, and operating procedures. Network Security & Restricted Environments
• Administer Zscaler ZIA and ZPA: maintain tunnel configurations, user traffic policies, and access rules in coordination with the Cloud & Infrastructure Manager.
• Manage Forcepoint Web Security policies for web filtering on CUI-handling endpoints.
• Administer WAF policies (F5 / Fortinet / Cloudflare): maintain and tune rules to protect SUSA-hosted applications, respond to alerts, and coordinate rule updates with application owners.
• Conduct regular firewall rule reviews; maintain documented security zone matrices and policy change records.
CMMC 2.0 Compliance Support
• Maintain accurate SUSA network diagrams and data-flow documentation for use in the System Security Plan (SSP).
• Support the CMMC compliance team on network-related controls (NIST SP 800-171 domains 3.1, 3.13); provide technical input for assessments and POA&M remediation.
• Validate that network changes do not introduce unintended CUI exposure; coordinate with the compliance team before implementing boundary modifications. Operations, Knowledge Transfer & Collaboration
• Manage hardware lifecycle and procurement; contribute network infrastructure inputs to the annual CAPEX/OPEX budget process.
• Document standard operating procedures, change records, and incident post-mortems in the ITSM platform.
• Apply Safran security and network policies and standards as directed by the Group network team.
• Coordinate technical actions with teams located at Safran headquarters (France) and in India.
• Define and organize knowledge transfer activities to L1 and L2 support teams. But what else? (advantages, specificities, etc.) Technology Stack & Platform Exposure
The following table reflects the platforms in the SUSA environment. Candidates are not expected to hold deep expertise across every row - strong routing/switching fundamentals and at least one security platform anchor are the core requirement. Other skills will be developed on the job. Routing & Switching Cisco Catalyst / Nexus | BGP / OSPF / EIGRP | VLANs / STP / QoS | L2/L3 troubleshooting | Datacenter fabric
Firewall / NGFW Palo Alto Networks (PA Series) | Fortinet FortiGate | Cisco Firepower (FTD / FMC) | Panorama | Policy & NAT management
Zero Trust / SWG Zscaler ZIA / ZPA | Forcepoint Web Security | Tunnel configuration | User traffic policies
WAF F5 / Fortinet / Cloudflare WAF | OWASP Top 10 rule tuning | Application traffic inspection | Alert response
Network Access Control Cisco ISE | 802.1X Authentication | RADIUS / TACACS+ | Posture assessment
WAN & Connectivity MPLS circuit management | Site-to-site VPN | Internet breakout | ISP coordination
Cloud Networking AWS VPC basics | Security groups | Site-to-site VPN | Hybrid connectivity
Monitoring & Tools SolarWinds NPM / NTA | NetFlow / SNMP / Syslog | Wireshark | Change & incident management Candidate skills & requirements Qualifications
Required
• 8+ years of network engineering experience with a clear focus on network security operations.
• Strong expertise in routing and switching, preferably in datacenter environments.
• Solid knowledge of TCP/IP, BGP, OSPF, VLANs, redundancy, and QoS.
• Experience administering enterprise firewalls (any major platform).
• Proven ability to troubleshoot complex L2/L3 network issues.
• Experience working in security- or compliance-driven environments. Preferred
• Cisco CCNP certification (or equivalent routing/switching depth).
• Hands-on knowledge of at least one firewall platform: Palo Alto Networks, Fortinet, or Cisco Firepower.
• Familiarity with Zscaler ZIA/ZPA, WAF platforms, or Forcepoint.
• Basic AWS networking knowledge (VPC, security groups, site-to-site VPN).
• Exposure to Python or Ansible for routine network automation tasks.
• Familiarity with CMMC, NIST 800-171, or similar regulatory frameworks.
• Background in manufacturing, aerospace, or defense-adjacent IT environments. Core Competencies
• Security-first engineering mindset - designs with defense-in-depth as the default.
• Collaborative team player - works effectively with peers in France and across SUSA IT teams.
• Operational discipline - follows change management processes and keeps documentation current.
• Problem-solving under pressure - methodical troubleshooting during network incidents.
• Ownership & accountability - drives issues to resolution without requiring escalation. Team & Reporting Context
This role reports to the Cloud & Infrastructure Manager, Safran USA IT, and works day-to-day with:
• Cloud & Infrastructure team peers (server, storage, datacenter operations)
• CMMC compliance team (network diagram and SSP support)
• End User Services / helpdesk (NAC, VPN, and wireless escalations)
• Safran IT network administrators in France and India (peer coordination on standards, cross-site connectivity, shared platform configurations, and shift-left activities)
• SUSA subsidiary IT contacts and service stakeholders Annual salary TBD Job location Job location North America, United States, Texas City (-ies) 2201 W. Royal Lane Irving, TX 75063 Irving Applicant criteria Minimum education level achieved Bachelor's Degree Minimum experience level required More than 5 years Additional Languages preferred English (Fluent) ITAR Controlled Position: Select "Yes" if role requires U.S. citizenship/permanent residency Yes
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Network Security Engineer in Irving, TX vacancy
- ...Job Description Job Description Network Security Engineer About Us EFJohnson Technologies is a subsidiary of JVCKENWOOD Corporation, a leading provider of P25 communications solutions for first responders in public safety and public service, the federal government...SuggestedRemote work
$95k - $110k
...Network (Security) engineer Design and operate secure network architectures. Implement segmentation, firewalls, and private connectivity. Apply zero-trust networking principles. Support cloud and hybrid network security. Participate...Suggested$110k - $125k
...grade Firewall platforms (e.g., Palo Alto Networks, Check Point, Cisco ASA/FTD).... ...protocols (TCP/IP, DNS, VPNs) and network security concepts (e.g., IDS/IPS, VPN, NAT,... ...Responsibilities Network Security Engineer - Web Proxy Separation SME Overview...Suggested$120.5k - $231k
...Want in? Join the #VTeamLife. What you'll be doing... At Verizon, the Global Networks & Technology Network Security team is looking for a highly motivated and experienced Senior Engineer to join the Security Defense organization. The Defense teams are responsible for...SuggestedFull timeTemporary workPart timeWork experience placementWork at officeWork from homeShift work3 days per week- ...Security Engineer 3 – PAM /IAM Irving, TX We are seeking a Security Engineer to provide operational and engineering support for enterprise Password and Credential Management platforms, including Bravura Password Manager and related IAM/PAM technologies. This role focuses...Suggested
- ...Systems Engineer II - Security THIS ROLE WILL BE BASED ON-SITE, IN OUR IRVING, TX. OFFICE We are Lennar Lennar is one of the nation's leading homebuilders, dedicated to making an impact and creating an extraordinary experience for their Homeowners...Work experience placementLive inWork at officeLocal area
$47 - $53 per hour
...A client of Innova Solutions is immediately hiring for a PAM Security Engineer Position type: Contract (12 months) Location: Irving, TX/ Charlotte, NC/ Phoenix, AZ/ Columbus, OH Hybrid Onsite (3 days onsite, 2 days remote in a week) As a PAM Security...Hourly payContract workTemporary workWork experience placementImmediate startRemote workWorldwideFlexible hours2 days per week- ...Job Description Job Description Global Software Firm seeks a Sr Network Security Engineer. We're looking for an engineer with strong Palo Alto, F5, and WAF experience. Experience in threat hunting and pen testing would be a plus. This is a permanent direct...Permanent employmentRemote work
- ...Job Description Benefits: Work Environment & Culture CAREER & GROWTH DEVELOPMENT Opportunity for advancement Network Security Engineer DALLAS, TX LONG TERM Are you a Network Security Engineer with a passion for designing, securing, and optimizing...
- ...Job Description Job Description Benefits: Competitive salary Opportunity for advancement Network Security Engineer Location: Colorado (Onsite) Employment Type: Full-Time We are hiring a hands-on Network Security Engineer to support and strengthen...Full timeRemote work
- ...shops to the platforms that support administrative staff. Secure, reliable network and identity infrastructure enable Citadel to operate without... ...Technology, Computer Science, Cybersecurity, Network Engineering, or a related technical discipline. Equivalent professional...For contractorsWork at officeRemote workNight shift
$105.4k - $124k
...Penetration Tester (Mobile, API, and Application Security) to support the effectiveness of our... ...Qualifications Bachelor’s degree in Engineering or Science, or equivalent work... ...authorization (OAuth, JWT), and general networking concepts. Experience or familiarity...Temporary workWork experience placementLocal area3 days per week$43.59 - $51.59 per hour
...Genesis10 is currently seeking a Senior Information Security Engineer (Network Security) for a hybrid position with a Global Financial Institution located in Irving, TX or Charlotte, NC. This is an 18+ month contract opportunity. We are looking for a skilled and...Hourly payPermanent employmentContract workWork experience placement- ...improve the lives of people and animals everywhere. Apply today! Job Details Summary: The Operational Technology Network Security Engineer III is responsible for designing, implementing, maintaining, and improving security controls across operational technology...Full timeWork experience placementWork at officeLocal areaRemote work
- ...Network Security Engineer NorthMark Compute & Cloud (NMC²) is backed by dedicated leadership and investment, with a clear mission as it operates at the bleeding edge of technology. Its goal is to scale and enhance the high-performance computing (HPC) and cloud infrastructure...Temporary workFlexible hours
$100k - $140k
...Network Security Engineer Dallas, Texas Hybrid Full Time $100k - $140k We are hiring a Network & Security Engineer for a full-time opportunity supporting a large-scale industrial and enterprise environment across multiple locations including Dallas, TX; Westport...Full time- ...Network Security Engineer / Hybrid / Dallas / Phoenix A senior level network security engineering opportunity is available with a large enterprise organization supporting a modern, highly secure infrastructure. This hybrid role is based in Charlotte, NC, Dallas, TX,...Full timeTemporary workWork at officeFlexible hours
- ...identity, sexual orientation, national origin, age, disability, veteran status, or any other protected characteristic. Role :- - Network Security Imperva, Purview Location: - Dallas, TX (Onsite position) Contract:- 6+ months & Extendable Pay rate: - $42/hr-...Permanent employmentContract workLocal areaFlexible hours
- ...Network Security Engineer NorthMark Compute & Cloud (NMC²) is backed by dedicated leadership and investment, with a clear mission as it operates at the bleeding edge of technology. Its goal is to scale and enhance the high-performance computing (HPC) and cloud infrastructure...Temporary workFlexible hours
$115.5k - $135.5k
...Innova Solutions is immediately hiring a Senior Security Engineer Position type: Permanent Duration: Fulltime Location: Texas, US As a Senior Security Engineer, you will: Should have had experience in conducting thorough security assessments to identify...Permanent employmentFull timeTemporary workWork experience placementImmediate startWorldwideFlexible hours$101k - $194k
...everywhere & always. Want in? Join the #VTeamLife. What you'll be doing... The GN&T Network Security team is looking for a highly motivated and experienced Cybersecurity Engineer to join the Network Security Defense team. The Defense teams are responsible for owning...Full timeTemporary workPart timeWork experience placementWork at officeWork from homeShift work3 days per week- ...Sr. Network Security/Firewall Engineer Procom is a leading provider of professional IT services and staffing to businesses and governments in Canada. With revenues over $500 million, the Branham Group has recognized Procom as the 3rd largest professional services firm...Permanent employmentContract workFor contractorsH1bRemote work
$75k - $85k
...Junior IAM Security Engineer / Hybrid in Irving TX Irving, Texas Hybrid Full Time $75k - $85k A growing organization in the healthcare and technology space is hiring an Associate IAM & Information Security Engineer for a full-time opportunity based in Irving...Full time3 days per week- Pride Health is looking for a Network Engineer in Dallas, Texas to maintain secure network infrastructure for healthcare clients. The role includes conducting cybersecurity operations and supporting incident response initiatives. Candidates must have a bachelor's degree...Full timeMonday to Friday
- ...a national team of experts driving HVAC innovation through a network of high-performing companies. From strategy and support to systems... ...that matter—every step of the way. Job Title: Cloud Security Engineer Reports To: Director of Cybersecurity & Compliance FLSA...Work at officeRemote workWork from home
- ...Senior Application Security Engineer – Threat Modeling & AI Security Locations: Charlotte, NC (Brevard), Irving/Las Colinas, TX, or Chandler, AZ Schedule: Hybrid (3 Days Onsite / 2 Days Remote Duration: Contract Overview We are seeking a Senior Application Security...Contract workRemote work
$110k - $125k
...Key Responsibilities • Design and develop custom security controls based on threat modelling outputs • Build: o Detective... .... • Minimum of 3-5 years of experience in DevSecOps engineering with a focus on cloud environments (AWS, GCP, Azure), ideally...$50 - $60 per hour
...Job Description Job Description Job Title: Security Engineer Pay: $50-60/HR Work model: On-site in Dallas Project length: Contract to Hire Benefits: This position is eligible for Medical, Dental, Vision, 401(k) Notes: This company is experiencing...Contract workLocal area- ...Principal Security Engineer - IAM THIS ROLE WILL BE ONSITE IN OUR IRVING, TX. OR MIAMI, FL. OFFICES We are Lennar Lennar is one of the nation's leading homebuilders, dedicated to making an impact and creating an extraordinary experience for their Homeowners...Live inWork at officeLocal area
- ...Cyber Security Engineer with Checkmarx(Mandatory) Locations: AZ, CA, MN, NC, NY, NJ & TX (Hybrid), (3 days onsite/2 WFH) Duration: 12+ Months Contract Required Qualifications: Provide hands on technical support for Checkmarx and Checkmarx ONE platform...Contract workWork from home
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Network Security Engineer. Be the first to apply!
Related searches
- senior cloud security engineer Irving, TX
- senior application security engineer Irving, TX
- sr information security engineer Irving, TX
- senior security operations engineer Irving, TX
- IT security engineer Irving, TX
- information technology security engineer Irving, TX
- aws cloud security engineer Irving, TX
- network security engineer Irving, TX
- security engineer Irving, TX
- data network cabling Irving, TX


