Senior Network Security Engineer

Employer Direct Healthcare
  • Dallas, TX
    12 days ago

    Job Description

    Lantern is looking for a Sr. Network Security Engineer to join our fast-growing team. You will design, implement, and defend the network security architecture protecting our members' healthcare data across on-premises, Azure, and edge environments. As the senior network security engineer on the Security Engineering & Operations team, you will own our Fortinet security fabric and Zero Trust network access architecture, drive automation of network security operations, and provide technical leadership across firewall, VPN, segmentation, and cloud network security domains. This role operates in a HIPAA, HITRUST CSF, and SOC 2 regulated environment and requires deep hands-on expertise, strong judgment, and effective collaboration with IT, cloud, and GRC partners.

    Location: Hybrid - at least 3 days/wk in our Dallas office located at 2100 Ross Avenue, Dallas, Texas 75201

    Responsibilities:

    • Design, implement, and manage secure network infrastructure across on-prem and Azure hybrid environments, including routing, switching, firewalls, VPN, and network segmentation.
    • Own and operate the Fortinet security fabric: FortiGate firewalls, FortiManager, FortiAnalyzer, FortiClient EMS, FortiSwitch/FortiAP, and SD-WAN, including lifecycle upgrades and vulnerability remediation against CISA KEV and vendor advisories.
    • Advance our Zero Trust architecture: design and operate ZTNA/SASE controls, identity-aware access policies, and micro segmentation to reduce reliance on perimeter and legacy VPN access.
    • Maintain and continuously optimize firewall rule sets, NAT policies, IPS/IDS, and IPsec/SSL VPN configurations through regular audits, rule hygiene, and hardening against benchmark baselines.
    • Engineer Azure network security controls: NSGs, Azure Firewall, VPN/ExpressRoute gateways.
    • Automate network security operations using infrastructure-as-code and scripting (Terraform, Ansible, Python, PowerShell, REST APIs) to eliminate manual, error-prone changes.
    • Monitor network traffic and detections (NDR, SIEM), tune signals and IOCs with a metrics-driven mindset, and lead network-layer incident response and root-cause analysis.
    • Secure emerging traffic patterns, including AI agent and API traffic, in partnership with our AI governance and threat detection programs.
    • Partner with IT, cloud, and platform teams on secure-by-design integration of network and system components; support audit and compliance evidence requests (HIPAA, HITRUST CSF, SOC 2).
    • Produce and maintain high-quality documentation: network diagrams, configuration standards, and standard operating procedures.
    • Mentor engineers on the team and contribute to on-call and change management processes.

    Requirements:

    • 7+ years in network and/or security engineering roles with increasing scope and ownership.
    • 5+ years of hands-on experience with Fortinet solutions (FortiGate, FortiManager, FortiAnalyzer, EMS, SD-WAN) and FortiCloud services.
    • 5+ years of Azure networking and security experience in hybrid environments.
    • Practical experience designing or operating Zero Trust / ZTNA / SASE architectures (e.g., Cloudflare Zero Trust, Zscaler, or equivalent).
    • Experience with an NDR platform (e.g., Darktrace, ExtraHop) and integrating network telemetry into a SIEM.
    • Strong scripting and automation skills: Python and/or PowerShell, REST APIs, and version-controlled change workflows; infrastructure-as-code experience (Terraform, Ansible) strongly preferred.
    • Deep knowledge of network protocols and services (TCP/IP, DNS, BGP/OSPF, TLS), security architecture, policy development, and incident response.
    • Excellent communication skills with technical and non-technical stakeholders, and a track record of delivering engineering projects in complex, fast-changing environments.

    Strong Candidates Will:

    • 7+ years in network and/or security engineering roles with increasing scope and ownership.
    • 5+ years of hands-on experience with Fortinet solutions (FortiGate, FortiManager, FortiAnalyzer, EMS, SD-WAN) and FortiCloud services.
    • 5+ years of Azure networking and security experience in hybrid environments.
    • Practical experience designing or operating Zero Trust / ZTNA / SASE architectures (e.g., Fortinet ZTNA, Cloudflare Zero Trust or equivalent).
    • Experience with an NDR platform (e.g., Darktrace, ExtraHop) and integrating network telemetry into a SIEM.
    • Strong scripting and automation skills: Python and/or PowerShell, REST APIs, and version-controlled change workflows; infrastructure-as-code experience (Terraform, Ansible) strongly preferred.
    • Deep knowledge of network protocols and services (TCP/IP, DNS, BGP/OSPF, TLS), security architecture, policy development, and incident response.
    • Excellent communication skills with technical and non-technical stakeholders, and a track record of delivering engineering projects in complex, fast-changing environments.

    Benefits

    • Medical Insurance
    • Dental Insurance
    • Vision Insurance
    • Short & Long Term Disability
    • Life Insurance
    • 401k with company match
    • Flexible Time Off
    • Paid Parental Leave

    Numbers & Facts

    LocationDallas, TX

    More jobs like this

    See more jobs

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.