Network Security Specialist - Firewall

Montreal Qc, CA

Apply now Apply later

Led by Rodolphe Saadé, the CMA CGM Group, a global leader in shipping and logistics, serves more than 420 ports around the world on five continents. With its subsidiary CEVA Logistics, a world leader in logistics, and its air freight division CMA CGM AIR CARGO, the CMA CGM Group is continually innovating to offer its customers a complete and increasingly efficient range of new shipping, land, air and logistics solutions.

Committed to the energy transition in shipping, and a pioneer in the use of alternative fuels, the CMA CGM Group has set a target to become Net Zero Carbon by 2050.
Through the CMA CGM Foundation, the Group acts in humanitarian crises that require an emergency response by mobilizing the Group’s shipping and logistics expertise to bring humanitarian supplies around the world.

Present in 160 countries through its network of more than 400 offices and 750 warehouses, the Group employs more than 155,000 people worldwide, including 4,000 in Marseilles where its head office is located.

 

** ALL CANDIDATES MUST BE LEGALLY AUTHORISED TO WORK IN CANADA** 

 

 

POSITION SUMMARY

 

As a Network Security Specialist, you are responsible for all solutions that are owned by Network Security, performing operational tasks and following best industry practice.

 

 

KEY RESPONSIBILITIES

  • Configuration and maintenance of firewall platforms (Cisco ASA, Palo Alto, Checkpoint, Fortinet). The tasks include but not limited to:
  • Creation/Modification of firewall objects and policies.
  • Establishing secured external connectivity with VPN technologies.
  • Configuration and operation of firewall auxiliaries such as Panorama, User-ID agents, etc.
  • Configuration and maintenance of load balancers (Citrix ADC formerly known as Netscaler).
  • The tasks include but not limited to:
  • Creation/Modification and health checks of load balanced services, monitors, virtual servers, content switching, and ADC gateways.
  • Defining rewrites and responders.
  • SSL certificate installations and maintenance.
  • Configuration and maintenance of proxy solutions (local open source - Squid, SOCKS, FTP proxy; cloud - Zscaler). The tasks include but not limited to:
  • Creation/Modification of security policies (firewall and web-content filtering)
  • Whitelisting/blacklisting URL and IP addresses.
  • Maintenance of user internet access policies and troubleshooting proxy-related internet connectivity issues.
  • Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) operations and producing web usage reports.
  • DNS management (zones, records, GeoDNS, etc.)
  • PKI / SSL certificates administration.
  • Distributed Denial of Service Protection (DDoS) management
  • Keeping up to date with information regarding firmware security vulnerabilities and bugs and ensuring firmware of security devices are secured and updated.
  • Working side by side with Cybersecurity to help with incidents.
  • Involvements in projects outside of daily operations to help with developments on technological solutions.
  • Log investigation, debugging, and packet captures.
  • Producing capacity planning reports.
  • Daily health checks for devices and services.
  • Making sure device inventory is updated and within standards.
  • Creating documents such as SOP or basic network diagram and ability to suggest improvements in the policies and processes.
  • License renewals and hardware refresh or replacements of devices.
  • Other responsibilities as required

 

 

QUALIFICATIONS

 

Education:  

Bachelor's degree in IT, Computer Science, Computer Engineering, or related field.

 

Knowledge & Experience: 

  • At least 3-5 years of related experience.
  • Strong knowledge and experience on the FF technologies:
  • Firewalls (Cisco ASA, Palo Alto, Checkpoint)
  • VPN Technologies (IPSEC S2S/Client SSL)
  • Load balancers (F5 or Citrix ADC)
  • Proxies (open source such as Squid, SOCKS, and FTP proxies; Cloud based proxy solutions – Zscaler ZIA)
  • Zero Trust Network Access (ZTNA – Zscaler ZPA)
  • Strong foundation on Networking (routing and switching).
  • Basic knowledge and experience on DNS administration and PKI.
  • Basic knowledge of Distributed Denial of Service (DDoS) Protection
  • Preferred but not required:
  • Security management tools such as Firemon, AlgoSec, Tuffin, or Red Seal.
  • Linux administration.
  • Scripting tools such as shell or Python.
  • Relevant certifications (CCNP Sec, PCNSE, etc.)
  • Knowledge in NAC appliances (Cisco ISE)

 

Other:

  • Strong work ethic, professional integrity and the ability to apply the appropriate level of judgement and maturity.
  • Excellent interpersonal skills, and a strong ability to communicate, team player, and result oriented.
  • Willing to work on shifting schedule.
  • Fluent in English & French.

Come along on CMA CGM’s adventure !

Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  1  0  0
Category: NetSec Jobs

Tags: CCNP Citrix Cloud Computer Science DDoS DNS Firewalls Linux Network security Open Source PKI Python Scripting VPN Vulnerabilities Zero Trust ZTNA

Region: North America
Country: Canada

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.