· Expert hands-on with:
o F5 BIG-IP (ASM/Advanced WAF): policy tuning, attack signatures, bot and DDoS mitigation, iRules basics.
o Palo Alto Networks: security policy design, App-ID/URL filtering, Threat Prevention/WildFire, Panorama.
o Fortinet FortiGate/FortiManager/FortiAnalyzer: NGFW policies, IPS/AV/web filter, automation, logging.
o Citrix ADC (NetScaler): L7 load balancing, SSL/TLS, content switching, AppFW exposure.
· Strong Azure and AWS networking & security: VNet/VPC, peering, routing, NSG/NACL, Azure Firewall/AWS Network Firewall, Application Gateway/ALB/WAF, PrivateLink, Transit Gateway/Virtual WAN.
· Protocol depth: TCP/IP, BGP/OSPF, NAT, DNS, TLS, HTTP/S, IPsec/SSL VPN.
· Proven experience designing for high availability, performance, and security compliance.
Good-to-Have Skills
Security first mindset with pragmatic delivery.
Ownership, attention to detail, and strong troubleshooting under pressure.
Collaboration across infra, app, SOC, and risk teams; mentoring capability.
Certifications Required
F5: 301a/b (BIG-IP LTM), 302 (ASM/Advanced WAF) or equivalent practical mastery.
· Palo Alto: PCNSE.
· Fortinet: NSE 4–7 (NSE 7 highly desirable).
· Citrix: CCA-N/CCP-N (ADC).
· Cloud: Azure Security Engineer (AZ-500), AWS Security – Specialty (or Architect certs with strong security exposure).