We are seeking a highly skilled Network Security Engineer with strong expertise in Cisco Secure Access Service Edge (SASE) and Cisco SD-WAN (Viptela) technologies. The successful candidate will be responsible for designing, implementing, optimizing, and supporting secure enterprise network infrastructures across branch, cloud, and data center environments. This role requires hands-on experience with network security, WAN transformation, cloud connectivity, and Cisco security solutions.
Key Responsibilities:
Cisco SD-WAN (Viptela)
- Design, deploy, configure, and maintain Cisco SD-WAN (Viptela) solutions.
- Manage and support SD-WAN components including:
- vManage
- vSmart Controllers
- vBond Orchestrators
- WAN Edge Routers
- Implement application-aware routing, segmentation, QoS, and traffic engineering policies.
- Perform network troubleshooting, root cause analysis, and performance optimization.
- Support WAN migration projects from traditional MPLS to SD-WAN architectures.
- Develop and maintain SD-WAN operational documentation and standard operating procedures.
Cisco SASE
- Implement and manage Cisco SASE solutions, including:
- Cisco Secure Access
- Umbrella
- Secure Web Gateway (SWG)
- Cloud Access Security Broker (CASB)
- Zero Trust Network Access (ZTNA)
- Data Loss Prevention (DLP)
- Configure security policies and access controls based on Zero Trust principles.
- Integrate SASE services with enterprise identity providers such as Azure AD and Okta.
- Monitor and improve security posture across cloud and hybrid environments.
- Support remote workforce security and secure application access initiatives.
Network & Security Operations
- Collaborate with security, cloud, and infrastructure teams to ensure secure network architecture.
- Perform incident response and remediation for network and security-related issues.
- Analyze network traffic and security logs to identify threats and vulnerabilities.
- Ensure compliance with security standards and organizational policies.
- Participate in network design reviews and architecture planning sessions.
Required Qualifications:
Education
- Bachelor's Degree in Computer Science, Information Technology, Network Engineering, or related field.
Experience
- 5+ years of experience in enterprise networking and network security.
- 3+ years of hands-on experience with Cisco SD-WAN (Viptela).
- 2+ years of experience with Cisco SASE technologies.
- Experience supporting large-scale enterprise WAN environments.
Technical Skills
- Cisco SD-WAN (Viptela)
- Cisco Secure Access
- Cisco Umbrella
- Routing Protocols (BGP, OSPF, EIGRP)
- VPN Technologies (IPSec, DMVPN, SSL VPN)
- Network Segmentation and Security Policies
- Cloud Networking (AWS, Azure, GCP)
- Firewalls and Secure Access Solutions
- DNS Security
- Zero Trust Architecture
- Network Monitoring and Troubleshooting Tools
- TCP/IP, LAN/WAN Technologies
Preferred Qualifications
- Experience with Cisco Catalyst SD-WAN.
- Experience integrating SASE with cloud platforms.
- Knowledge of automation tools such as Python, Ansible, or Terraform.
- Exposure to network observability and analytics tools.
- Experience working in a multi-vendor enterprise environment.
Certifications (Preferred)
- Cisco CCNP Enterprise
- Cisco CCNP Security
- Cisco Certified Specialist – Enterprise SD-WAN Implementation
- Cisco Certified Specialist – Security Solutions
- CCIE Enterprise Infrastructure (Preferred)
- CCIE Security (Preferred)
- CISSP or equivalent cybersecurity certification
Key Competencies
- Strong analytical and troubleshooting skills
- Excellent communication and stakeholder management
- Ability to work independently and collaboratively
- Customer-focused mindset
- Strong documentation and presentation skills
- Problem-solving and decision-making capabilities
Others:
- Only those applicants who already have the right to live and work in the Philippines are eligible to apply for this role.