Engineer III, Systems Network

American Bureau of Shipping (ABS)
  • Houston, Texas
    3 days ago

    Job Description

    The Systems Network Engineer III leads the design, standardization, and continuous improvement of network security infrastructure across ABS's global hybrid-cloud environment. This role bridges engineering execution with strategic architecture, developing network security best practices using industry frameworks, driving automation, and establishing governance processes that strengthen the organization's infrastructure posture. The Engineer III, Network Security provides technical leadership to the engineering team through documentation, standards development, and architectural oversight, while advancing Zero Trust initiatives including identity-based access controls, firewall policy lifecycle management, and infrastructure-as-code adoption.

    What You Will Do:
    • Define and maintain the enterprise network security infrastructure roadmap, ensuring alignment with Zero Trust principles, NIST 800-171/CMMC compliance frameworks, and business objectives.
    • Design secure, scalable, high-availability network architectures across on-premises, Azure, Oracle Cloud, and multi-cloud environments.
    • Develop network security best practices using industry frameworks and translate security policy requirements into infrastructure designs that enforce them.
    • Evaluate emerging technologies and provide architectural recommendations to IT leadership.
    • Serve as the technical authority on firewall, segmentation, VPN, and remote access infrastructure decisions.
    • Develop and maintain reference architectures, design patterns, and standards for network security infrastructure.
    • Evaluate and integrate technologies that provide comprehensive user-to-resource mapping across on-premises, cloud, and remote access environments.
    • Develop infrastructure standards for identity-based policy enforcement that reduce the attack surface and support Zero Trust maturity across the organization.
    • Design and implement a firewall policy cleanup and ownership workflow, establishing clear rule ownership, periodic review cadences, and decommission processes.
    • Lead firewall rulebase optimization efforts, identifying unused, shadowed, overly permissive, and redundant rules across security and NAT policies.
    • Identify repeatable, manual engineering workflows and lead the effort to standardize and automate them, reducing human error and improving deployment consistency.
    • Establish documentation standards and templates for the engineering team to follow, ensuring knowledge is captured and transferable.
    • Provide architectural guidance and mentorship to network and firewall engineers, ensuring engineering execution aligns with architectural standards.
    • Lead cross-functional collaboration with security operations, cloud engineering, identity/access management, and application teams.
    • Partner with the security team to understand policy requirements and translate them into infrastructure designs and configurations.
    • Serve as subject matter expert and escalation point for complex firewall, VPN, routing, and multi-cloud connectivity issues.
    • Support security audits, compliance assessments, and incident response with architectural context and technical expertise.
    What You Will Need:

    Education and Experience
    • 8+ years of progressive experience in network security engineering, with at least 3 years in an senior engineer or technical lead capacity. Must include 5+ years of hands-on experience with Palo Alto NGFW and Panorama in a global enterprise environment with hybrid-cloud infrastructure.
    • Typically requires a college degree or recognized equivalent, preferably in Computer Science, Computer Engineering, or related field, from an accredited university or comparable on-the-job experience. Technical certifications are a plus.
    • Palo Alto PCNSA / PCNSE
    • Cisco CCNP (Security or Enterprise)
    • Cloud certifications (Azure, OCI, GCP)
    • NIST / CMMC related certifications
    • Cloudflare ASE/ACE, Zscaler ZDTA,ZDTE,ZDXA
    Knowledge, Skills and Abilities
    • Deep expertise in designing enterprise-grade network security infrastructure across hybrid-cloud environments (on-prem, Azure, OCI, GCP).
    • Advanced knowledge of Palo Alto NGFW, Panorama (device groups, templates, template stacks, variables), App-ID, Threat Prevention, GlobalProtect, and Security Zone design.
    • Proven experience redesigning and optimizing large-scale firewall rulebases (1000+ rules) with a focus on segmentation, least privilege, and policy lifecycle governance.
    • Strong command of BGP, OSPF, EIGRP, VPC, HSRP, VLAN design, SD-WAN, and DMVPN architectures.
    • Extensive experience with IPSec VPN (site-to-site and third-party), GlobalProt

    Numbers & Facts

    LocationHouston, Texas

    Skills

    • ASEunmatched
    • Access Controlunmatched
    • Architectural Designunmatched
    • Architectural Servicesunmatched
    • Automationunmatched
    • BGPunmatched
    • Best Practicesunmatched
    • Bridge Buildingunmatched
    • CCNP - Cisco Certified Network Professionalunmatched
    • Civil Engineeringunmatched
    • Cloud Computingunmatched
    • Computer Engineeringunmatched
    • Computer Scienceunmatched
    • Continuous Improvementunmatched
    • Cross-Functionalunmatched
    • Design Patterns Programming Methodologiesunmatched
    • Documentation Standardsunmatched
    • EIGRP (Enhanced IGRP)unmatched
    • Emerging Technologyunmatched
    • Enterprise Protectionunmatched
    • Firewallsunmatched
    • GCP (Good Clinical Practices)unmatched
    • HSRP (Hot Standby Router Protocol)unmatched
    • High Availabilityunmatched
    • Hybrid Cloudunmatched
    • IPsec (IP Security)unmatched
    • Identity Data Managementunmatched
    • Incident Responseunmatched
    • Mentoringunmatched
    • Microsoft Windows Azureunmatched
    • NAT (Network Address Translation)unmatched
    • Network Administration/Managementunmatched
    • Network Architecture/Engineeringunmatched
    • Network Securityunmatched
    • Open Shortest Path First Protocol (OSPF)unmatched
    • Oracleunmatched
    • Policy Implementationunmatched
    • Process Developmentunmatched
    • Remote Accessunmatched
    • Security Auditingunmatched
    • Security Designunmatched
    • Security Infrastructureunmatched
    • Security Policyunmatched
    • Software Engineeringunmatched
    • Standards Developmentunmatched
    • Systems Engineeringunmatched
    • Technical Leadershipunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • VLAN (Virtual Local Area Network)unmatched
    • VPN (Virtual Private Network)unmatched
    • Wide Area Network (WAN)unmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder