Job Description:
We are seeking a highly skilled L2 Security Operations Engineer to provide advanced operational support for enterprise security infrastructure. The role involves handling escalated security incidents, troubleshooting complex network security issues, implementing approved security changes, and ensuring the availability, performance, and compliance of security platforms while meeting defined SLAs.
Key Responsibilities
- Handle escalations from L1 for security incidents, service degradation, and operational issues.
- Troubleshoot and resolve firewall policy, NAT, session, VPN tunnel, and connectivity issues.
- Diagnose routing and network connectivity problems affecting security devices.
- Monitor and resolve security device health, performance, and availability issues.
- Implement approved firewall policies, security configurations, and rule changes.
- Perform software patching, minor upgrades, and controlled infrastructure changes.
- Analyze security logs, events, traffic patterns, and recurring incidents to identify root causes.
- Restore P1/P2 security services within agreed SLA timelines.
- Coordinate with OEM/L3 support teams for complex incidents, defects, and product-related issues.
- Conduct Root Cause Analysis (RCA) and recommend preventive and corrective actions.
- Support security hardening, baseline compliance, configuration reviews, and cleanup activities.
- Maintain technical documentation, MOPs, SOPs, knowledge base articles, and known error databases.
- Assist with security audits, compliance reporting, and governance activities.
- Mentor L1 engineers and contribute to process improvements, runbook enhancements, and automation initiatives.
Required Skills & Qualifications
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- 3–6+ years of experience in Security Operations, Firewall Operations, or Network Security Support.
- Strong hands-on experience managing enterprise security infrastructure.
- Solid understanding of firewall technologies, VPNs, NAT, routing, and network security concepts.
- Experience with incident, problem, and change management processes.
- Ability to perform impact assessments and execute controlled production changes.
- Working knowledge of security hardening standards, baseline compliance, and configuration management.
- Strong troubleshooting, Root Cause Analysis (RCA), and analytical skills.
- Excellent communication and stakeholder management abilities.
- Experience working within SLA-driven enterprise or managed services environments.
Preferred Certifications
- Fortinet NSE / FCSS
- Palo Alto PCNSA / PCNSE
- Cisco CCNP Security
- Check Point CCSA / CCSE
- ITIL Foundation
- CompTIA Security+ (Preferred)