Enter a job title or keyword

Lead Network & Cyber Security Engineer-L3

Hirestar Job Bank


Job Location:

Kochi - India

Monthly Salary: Not provided by the employer
Posted: 5 September 2026 (Yesterday)
Application Deadline: 3 December 2026
Vacancies: 1 Vacancy

Job Summary

Position: Lead Network & Cyber Security Engineer (L3) – Team Lead Department: Projects Delivery & Professional Services

Employment Type: Full-Time Reporting To: Department Head

1. Company Overview

Hilal Technology is a leading Systems Integrator (SI) specializing in delivering turnkey IT infrastructure network and cybersecurity solutions to enterprise clients. We bridge the gap between complex vendor technologies (networking security and unified communications) and business operational needs. We are seeking a highly skilled L3 Team Lead to lead our combined network and security implementation pod ensuring that our clients receive robust scalable and seamlessly integrated infrastructure and security architectures.

2. Role Summary

This is a client-facing hands-on technical leadership role. As the L3 Team Lead you will be the highest technical authority for Network Architecture Routing & Switching Network Security Cyber Security and Unified Communications deployments for Hilal Technology's client base. Your primary mandate is to design implement migrate and troubleshoot network and security solutions leading a team of deployment engineers and working closely with the Project Manager and Technical Manager to ensure that what is sold is delivered to the highest standard.

Important Note: This is a Project Delivery & Engineering role. The engineer must be available to resolve and support the team upon request & urgency.

3. Key Responsibilities

A. Network Engineering (Routing & Switching)

.

Core Infrastructure: Design configure and troubleshoot complex enterprise LAN/WAN environments across Cisco (Catalyst/Nexus) Aruba (CX/Switches) Dell (PowerSwitch DS Series) and Huawei (Cloud Engine/S-series) switches.

.

Advanced Routing: Implement and optimize dynamic routing protocols (OSPF BGP EIGRP IS-IS) across multi-vendor routers and firewalls.

.

Wireless: Oversee deployment of enterprise wireless networks specifically Cisco Meraki Aruba Wireless (Controllers Access Points Central/ArubaOS) and Huawei WLAN solutions.

.

Network Automation & Management: Deploy and manage Cisco DNA Centre (Catalyst Centre) and Huawei iMaster NCE to automate provisioning monitor network health and enforce policy-based networking.

B. Network & Cyber Security Engineering (Hands-On L3)

.

Multi-Vendor Firewall Expertise: Act as the L3 Subject Matter Expert / technical authority for deployment migration and tuning of Next-Gen Firewalls across Palo Alto Check Point Cisco (FTD/ASA) Fortinet (FortiGate) Juniper (SRX) and Huawei (USG/Firepower).

.

Execute complex firewall/security migrations (e.g. Check Point to Palo Alto Cisco to Fortinet Legacy Cisco to Palo Alto Juniper to Fortinet) with minimal downtime using automation tools.

.

Configure advanced features including BGP/OSPF routing SSL Decryption App-ID User-ID Threat Prevention and Site-to-Site/Remote Access VPNs (Route-based Hub-and-Spoke and SD-WAN integrations).

.

Network Access Control (NAC): Design and implement 802.1X and MAB solutions (e.g. Cisco ISE FortiNAC Aruba ClearPass) to secure wired wireless and VPN access integrated with enterprise wireless and switching infrastructure.

.

Identity & Access Management (MFA): Design and integrate Multi-Factor Authentication solutions specifically Cisco Duo and FortiAuthenticator for remote VPN and admin access.

.

Privileged Access Management (PAM): Deploy PAM solutions (e.g. CyberArk Wallix BeyondTrust) including vaulting session isolation and integration with client Active Directories.

.

Endpoint Security (EDR/XDR): Lead large-scale agent deployment projects (CrowdStrike SentinelOne Cortex XDR Defender) across client environments ensuring policy tuning and false-positive resolution before handover.

.

Web Application Firewall (WAF): Deploy and tune WAF policies (e.g. F5 Imperva FortiWeb Cloudflare) in front of client web applications balancing strict OWASP security with application availability without disrupting business logic.

.

Remote Access & SASE: Design and maintain enterprise VPN solutions (GlobalProtect AnyConnect FortiClient) and integrate with Zero Trust Network Access (ZTNA) principles.

C. Unified Communications & Collaboration (Voice)

.

IP Telephony & Video: Lead the deployment migration and troubleshooting of enterprise voice environments including:

.

Cisco Collaboration: CUCM (Call Manager) Unity Connection Expressway and WebEx Calling integration.

.

Avaya Collaboration: Aura Communication Manager Session Manager and IP Office.

.

Session Border Controllers (SBC): Configure and manage Ribbon SBC & AudioCodes for SIP trunking VoIP security and interoperability between carrier networks and enterprise voice.

D. Team Leadership & Project Management

.

Team Supervision: Lead mentor and assign daily tasks to a team of L1/L2 Network and Security implementation engineers. Review technical changes conduct performance reviews and drive internal cross-training and mentoring for career growth.

.

Project Delivery: Own the "Technical Implementation Plan." Work with the PMO to ensure deployments are completed on time within scope and within budget.

.

Client Handover: Create "As-Built" documentation (LLDs) and conduct training sessions for clients before transitioning them to Hilal Technology's Managed Services or SOC teams.

.

Escalation Point: Serve as the final P1/P2 technical escalation point during project hyper-care resolving complex multi-vendor (Network/Security/Voice) routing stability integration or connectivity issues.

4. Required Skills & Qualifications

Experience

.

Minimum 8-10 years in Network & Cyber Security Engineering with at least 3 years in a Systems Integrator (SI) or Professional Services environment.

.

Proven track record of managing simultaneous projects and team workloads for multiple clients.

Vendor & Technology Expertise (Mandatory)

.

Networking: Hands-on command of Cisco IOS/IOS-XE Aruba CX/OS Huawei VRP and Dell OS10/OS9 (Enterprise SONiC OS is a plus).

.

Firewalls: Strong hands-on expertise in at least three of the following: Palo Alto Strata Check Point Quantum Cisco Firepower Fortinet FortiGate Juniper SRX Huawei.

.

Deep Domain Knowledge: NAC (Cisco ISE / Aruba ClearPass / FortiNAC) EDR/XDR WAF and PAM.

.

Collaboration: Deep understanding of SIP protocol dial plans and troubleshooting tools (Translations Trace routes Wireshark). Must have deployed either Cisco or Avaya IPT solutions.

.

SBC: Working knowledge of Ribbon SBC configurations for SIP trunks.

.

Authentication: Hands-on experience with Cisco Duo and FortiAuthenticator.

Networking Knowledge

.

CCNP/CCIE level understanding of Routing & Switching (BGP OSPF EIGRP IS-IS VLANs Spanning Tree VRF VXLAN TCP/IP DNS DHCP).

.

Ability to use Wireshark/tcpdump to read packet captures and prove network issues are not the firewall's fault resolving connectivity voice quality (VoIP) latency or network bottleneck issues.

Soft Skills

.

Communication: Excellent written and verbal communication in English. Ability to explain complex technical issues and present solutions to client stakeholders and C-level executives.

.

Leadership: Proven ability to motivate a technical team and enforce engineering standards.

.

Documentation: High proficiency in creating High-Level Designs (HLDs) Low-Level Designs (LLDs) Migration Runbooks and Network Diagrams (Visio PowerPoint & other tools).

Certifications (Preferred)

.

Networking: CCNP Enterprise CCIE (R&S/Enterprise/Security) Aruba ACSP/ACMP or Huawei HCIP/HCIE.

.

Security: PCNSE (Palo Alto) NSE 7/8 (Fortinet) CCSE (Check Point) JNCIE-SEC or CISSP.