- Location
- Johnson Controls India COEE1
- Type
- Full-time
- Department
- Engineering
- Seniority
- Senior
- Closing date
- Today
- Source
- Workday
Description
Job Title: Senior Zero Trust Network Security Engineer
Location- Pune
What you will do:
As part of JCI’s ongoing and exciting digital transformation strategy, as a Senior Zero Trust Network Security Engineer you will act as a technical lead and subject matter expert across our global Enterprise Security estate. You will work with the wider global network and IT teams, business partners and managed service vendors to design, engineer and operate the physical and logical Enterprise Security infrastructure (Zscaler Secure Service Edge, firewalls, remote access platforms, cloud proxies, microsegmentation (Zscaler and Guardicore), cloud security & perimeter security devices etc.) portfolio in Johnson Controls. This is a senior, hands-on role with a strong emphasis on our Zscaler platform – including Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Data Loss Prevention (DLP) and Zscaler AI Security – underpinning JCI’s Zero Trust program.
Our Network infrastructure consists of a large global footprint of more than one thousand sites supporting over one hundred thousand employees ranging from datacenters, manufacturing plants, sales branches, and customer contact centers with exposure to a wide range of exciting network technologies and vendors such as Zscaler (ZIA, ZPA, DLP, AI Security and Microsegmentation), Fortinet, Zscaler ZT Branch Connector, Akamai Guardicore, Imperva WAF, Forescout, Microsoft Azure, Amazon AWS and many more partners.
The role will be working as part of a global high-performance team focused on continuous network security infrastructure delivery and upgrades, maintenance and operational activities, delivery of security configurations and services, incident and change management, network security design and compliance, equipment ordering, scheduling, security device life cycle management, operational handover, vendor management and network security infrastructure asset management.
How you will do it:
Manage and implement network security infrastructure
Serve as senior engineer and design authority for the Zscaler platform – ZIA, ZPA, Inline DLP, AI Security (Secure AI Access), Digital Experience (ZDX) and Zscaler Microsegmentation
Build and tune ZIA/ZPA access policies, SSL inspection, DLP dictionaries and AI Security controls, and lead the migration of users to full SSE capability
Firewall, IPS/IDS and remote access configuration and rule management across the Fortinet estate (FortiGate, FortiManager, FortiAnalyzer)
Cloud-based Web Application Firewall (Imperva WAF), microsegmentation and workload protection (Zscaler and Akamai Guardicore), and perimeter/geo-blocking controls
Design, build, operate and automate security solutions and processes to protect the integrity of the organization's networks, systems, applications and data.
Work closely with Security team partners/Business Relationship Managers , Field IT leadership and managed service suppliers to ensure successful identification and timely delivery of network security services to the business.
Participate and consult(in partnership with the Network lifecycle refresh team) the identification, selection and prioritization of security infrastructure refresh components to ensure alignment with risk avoidance, strategic goals and organizational priorities.
Respond to security incidents, including data breaches, and coordinate with other IT teams to mitigate the impact of any security breaches.
Conduct regular security audits to identify vulnerabilities in the network and implement measures to address them.
Partner with IT audit to remediate security gaps in a timley manner.
Drive and develop automation opportunities for the management of security infrastructure.
Manage the global Network security infrastrucutre inventory in CMDB.
Ensure timely quote turnaround for security infrastructure delivery.
Ensure all network asset data is accurate and support contracts are in place.
Provide technical leadership and mentorship to engineers and operations staff, set standards and act as an escalation point for complex incidents and designs.
Lead delivery of the Zero Trust program, including microsegmentation of crown-jewel applications with Zscaler and Guardicore, geo-blocking and reduction of the internet-facing attack surface.
What we look for:
Required
Deep, hands-on expertise with the Zscaler platform is essential – Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler DLP and Zscaler AI Security (Secure AI Access), including policy design, SSL inspection, App Connectors/Service Edges and tenant administration.
Strong network infrastructure security background across both on-prem physical components (firewalls, IDS/IPS, remote access) and cloud security services (Zscaler, Azure, AWS), plus experience with Zscaler ZDX and microsegmentation (Zscaler and/or Guardicore).
Strong knowledge of the Fortinet security suite (FortiGate, FortiManager, FortiAnalyzer) and experience testing and implementing security-related changes in a production environment.
Experience working with 3rd party vendors and managed network service providers.
Great organisational skills.
Strong experience of working on SIEM tools to analyze logs and correlate events.
Solid understanding of industry standard Cybersecurity Frameworks and compliance requirements
Experience in Enterprise level network security incidents and change Management process.
Solid technical understanding of DMZs, security policies, secure application traffic flows, WAF, DDoS protection, SSL offloading and inspection.
Strong knowledge of Zero Trust Network Architecture
Experience with private and public cloud providers is a plus, (e.g., AWS, Azure, GCP, Nutanix) particularly in connectivity, availability, resilience, and security.
Familiarity with service now Ticketing and CMDB is desirable
Demonstrated capability to take part as lead security engineer in multi-phase / multi-year network projects or programs, leading these projects to successful implementation.
Strong technical troubleshooting skill.
Strong vendor management experience.
Excellent oral and written communication skills to provide clear messages to all levels.
Demonstrated ability to effectively establish and maintain strategic working relationships with peers and constituents at all levels of the organization.
Demonstrated analysis and problem solving skills using innovative thinking.
Knowledge of ITIL based practices.
Knowledge of Python and automation skills are desirable.
Qualifications
Bachelor’s degree in Computer Science, Engineering, Information Systems, or other applicable discipline.
8+ years of proven, hands-on network security experience at global enterprise organizations, including significant experience owning and operating a Zscaler (ZIA/ZPA) environment at scale.
Network security Professional level certification preferred (e.g. Zscaler ZDTA/ZCCP/ZCCA, Fortinet NSE, Imperva, etc.); Zscaler certification strongly preferred.
CISSP, CEH, CISM or CISA certifications is a plus.
Johnson Controls International plc. is an equal employment opportunity and affirmative action employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, protected veteran status, genetic information, status as a qualified individual with a disability, or any other characteristic protected by law. For more information, please view EEO is the Law. If you are an individual with a disability and you require an accommodation during the application process, please visit www.johnsoncontrols.com/careers.