Requirements
The L3 Network Security Support Engineer will provide L3 support for F5 BIG-IP (LTM, ASM/Advanced WAF), Cisco Firepower/FTD, Palo Alto, and Check Point firewalls. Responsibilities include troubleshooting, design, change implementation, security policy tuning, and compliance. Requires deep hands-on expertise with F5, IPS/IDS, NGFW, solid networking foundation, SSL/TLS, PKI, SIEM integration, and packet analysis. A Bachelor's degree and 8+ years of network/security engineering experience with 3+ years at L3 level are required.
Description
Location: Dubai, Customer OnsiteMode of work: Work from office (Daily)Job SummaryThe L3 Network Security Support Engineer is the highest technical escalation point for the bank's perimeter and application-security infrastructure — F5 BIG-IP (LTM load balancing and ASM/Advanced WAF), Intrusion Prevention/Detection systems (Cisco Firepower/FTD), and Next-Generation Firewalls (Palo Alto and Check Point). The role owns complex troubleshooting and root-cause analysis, design and change implementation, performance and capacity management, security policy tuning, and audit/regulatory compliance, ensuring the availability, performance and security of business-critical and customer-facing banking services.Key ResponsibilitiesF5 — Load Balancing Web Application Firewall (WAF) Provide L3 support for F5 BIG-IP LTM — virtual servers, pools, health monitors, SSL offload, persistence and iRules — for business-critical and customer-facing applications. Administer and tune F5 ASM / Advanced WAF — create, tune and enforce WAF policies aligned to OWASP Top 10, manage attack signatures, bot defence, and false-positive reduction, and transition policies from monitoring to blocking mode safely. Manage SSL/TLS certificates, cipher/hardening standards, and PKI integration on the F5 estate. Troubleshoot latency, performance and availability issues; monitor interface/throughput utilisation; and provide capacity, upgrade and HA-design input.IPS / IDS (Intrusion Prevention Detection) Provide L3 support for the IPS/IDS platform (Cisco Firepower / FTD via FMC) — policy and signature management, tuning, and threat analysis. Optimise IPS/IDS policies, reduce false positives, and manage inline vs detection modes; validate coverage of critical assets and segments. Perform packet-level analysis and threat investigation; correlate IPS/IDS events with the SIEM for detection and response. Maintain signature/rule currency and coordinate tuning with the SOC and threat-intelligence functions.Next-Generation Firewall (NGFW) Provide L3 support for Palo Alto (PAN-OS /Panorama) and Check Point (Gaia / SmartConsole / MDS) firewalls across production and DR. Manage security policies, rule bases, NAT, App-ID/URL filtering, threat-prevention profiles, and site-to-site / remote-access VPNs (IPsec/SSL). Perform firewall hardening, HA configuration, version/patch management (N-2 compliance), and periodic rule recertification / clean-up of no-hit rules. Lead complex firewall change implementation and troubleshooting with minimal business impact.General L3/ Operational Act as the senior escalation point for P1/P2 incidents; lead root-cause analysis and problem management to prevent recurrence. Own change management (raise, review and implement CRs) in line with the bank's governance, and contribute to design / Low-Level Design (LLD) for new solutions. Support audit and regulatory compliance (e.g. SAMA / CBUAE, PCI-DSS), remediate findings, and maintain configuration backups (SolarWinds NCM) and evidence. Maintain SOPs, runbooks and topology documentation; mentor L1/L2 engineers; and coordinate with OEM/vendor TAC for escalations.Required Skills Experience Deep hands-on expertise with F5 BIG-IP — LTM and ASM/Advanced WAF, iRules, SSL/TLS. Strong expertise in IPS/IDS — Cisco Firepower/ FTD / FMC (signature tuning, policy, analysis). Strong expertise in NGFW — Palo Alto (PAN-OS/Panorama) and Check Point (R8x/Gaia). Solid networking foundation — TCP/IP, routing/switching, NAT, VPN (IPsec/SSL), DNS, and load-balancing concepts. SSL/TLS, PKI/certificate management, and security hardening standards. SIEM integration and log analysis; packet capture and analysis (Wireshark / tcpdump). Scripting/automation (Python / Bash / API) desirable for operational efficiency.Certifications (Preferred) F5 Certified — 201/301 (LTM) and ASM/Advanced WAF. Cisco CCNP Security / Firepower (SNCF). Palo Alto PCNSE. Check Point CCSA/ CCSE. CISSP / CISM desirable.Experience Qualifications Bachelor's degree in Computer Science, Engineering, Information Technology or related field. 8+ years experience in network/security engineering, with 3+ years at L3 level supporting F5, IPS/IDS and NGFW. Prior experience in a bank or large regulated enterprise, supporting business-critical and customer-facing services, strongly preferred.Behavioral / Soft Skills Strong incident-leadership and problem-solving under pressure (P1 handling). Clear written and verbal communication, including stakeholder and leadership updates. Disciplined approach to change management, documentation and audit. Collaborative team player able to mentor junior engineers and coordinate with vendors.Preferred Industry ExperienceBankingFinancial ServicesInsurance (BFSI)Large Enterprise Security Operations EnvironmentWork ModelFull-time onsite deployment at customer locationWillingness to support after-hours activities during critical incidents or planned maintenanceParticipation in on-call support rotation if required