We are looking for an IP Security Engineer to join our Network Security team and contribute to securing, operating, and continuously improving network security across our enterprise and cloud infrastructure. The role involves working closely with network, cloud, and infrastructure teams to protect services while maintaining availability and performance.
Key Responsibilities
Configure and maintain firewalls, security policies, NAT, VPNs, and high-availability deployments.
Secure Internet-facing services using DMZ architecture, reverse proxies, WAF, load balancers, and DDoS protection.
Implement network segmentation, access controls, and secure connectivity between users, infrastructure, and customer environments.
Review access requests and infrastructure changes, assess security implications, and validate implementation.
Regularly review firewall rules and VPN configurations to remove unnecessary access and enforce least privilege.
Troubleshoot connectivity, routing, VPN, TLS, and firewall issues using logs and packet captures.
Manage TLS certificates on security gateways, proxies, and published services, including renewal and certificate-chain validation.
Apply configuration hardening, maintain backups, and support upgrades, failover testing, and recovery.
Coordinate with Cybersecurity on incident investigation and remediation within the network security scope.
Maintain network diagrams, configuration records, operating procedures, and change documentation.
Required Qualifications
Practical experience in network security engineering or administration.
Strong understanding of TCP/IP, subnetting, VLANs, routing, DNS, HTTP/HTTPS, and TLS.
Hands-on experience with enterprise firewalls, preferably Fortinet FortiGate.
Experience configuring and troubleshooting IPsec and remote-access VPNs.
Understanding of stateful inspection, NAT, segmentation, high availability, and asymmetric routing.
Ability to analyze traffic using Wireshark, tcpdump, and device diagnostic tools.
Familiarity with Linux networking and virtualized environments.
Strong troubleshooting, documentation, communication, and change-management skills.
Preferred Qualifications
Experience with Cisco or Huawei networking and cloud environments.
Familiarity with pfSense, HAProxy, WAF, load balancing, and DDoS mitigation.
Experience securing multi-tenant infrastructure and isolating customer networks.
Familiarity with NAC, 802.1X, and Cisco ISE.
Python, Ansible, or API experience for configuration automation and validation.
Relevant Fortinet, Cisco, or Palo Alto certifications.
شرکت فناپ در سال ۱۳۸۴ با سرمایهگذاری گروه مالی پاسارگاد و جمعی از متخصصان و کارآفرینان حوزه فناوری اطلاعات و ارتباطات تاسیس شد. ماموریت اولیه آن، ارائه خدمات نرمافزاری و سختافزاری و مدیریت پروژههای فناورانه برای اعضای گروه مالی پاسارگاد بود.
فناپ در آغاز با تمرکز بر نرمافزارهای بانکی فعالیت خود را شروع کرد. اما امروز دامنه خدمات آن فراتر رفته و بانکها، موسسات مالی و اعتباری و شرکتهای بزرگ کشور را نیز در بر میگیرد. این شرکت اکنون در حوزههای متنوعی همچون مالی، بانکی و بیمهای، ارتباطات و مخابرات، حملونقل هوشمند، سلامت هوشمند، مدیریت منابع سازمانی، زیرساخت ابری و مراکز داده، امنیت و هوشمندسازی فرآیندها فعال است.
فناپ با ارائه راهحلهای نوآورانه و مطمئن، به یکی از بازیگران اصلی و اثرگذار صنعت فناوری اطلاعات و ارتباطات در کشور تبدیل شده است.