Role Summary
KalSoft is seeking a highly experienced Senior Network Security Engineer to join their team onsite in Oman. This is a full-time contractual position reserved exclusively for Omani nationals with a minimum of 5+ years of professional experience in network security engineering. The role focuses on designing, implementing, and maintaining robust network security architectures to protect critical infrastructure and data assets.
Key Responsibilities
- Design, deploy, and manage enterprise-grade network security solutions including firewalls, intrusion detection/prevention systems (IDS/IPS), VPNs, and secure access controls
- Conduct regular vulnerability assessments and penetration testing on network infrastructure to identify and remediate security gaps
- Develop and enforce network security policies, standards, and procedures aligned with industry best practices and compliance requirements
- Monitor and analyze security event logs and SIEM alerts to detect, investigate, and respond to network-based threats and anomalies
- Lead incident response activities for network security breaches, including forensic analysis and post-incident reporting
- Collaborate with cross-functional IT teams to integrate security controls into network architecture and cloud environments
- Perform security audits and compliance checks against frameworks such as ISO 27001, NIST, and local regulatory standards
- Provide technical guidance and mentorship to junior security engineers and network administrators
- Evaluate and recommend emerging network security technologies to enhance defensive capabilities
- Maintain documentation of network security architecture, configurations, and standard operating procedures
Required Qualifications
- 5+ years of hands-on experience in network security engineering within enterprise environments
- Bachelor's degree in Computer Science, Information Security, Network Engineering, or related field
- Professional certifications such as CCNP Security, CISSP, CISM, Palo Alto PCNSE, Fortinet NSE 4/7, or equivalent
- Deep expertise with next-generation firewalls (Palo Alto, Fortinet, Check Point, Cisco Firepower)
- Strong knowledge of network protocols (TCP/IP, BGP, OSPF, VLANs, VPN technologies including IPsec, SSL/TLS)
- Experience with SIEM platforms (Splunk, QRadar, LogRhythm, Microsoft Sentinel) and log correlation
- Proven track record in zero trust architecture, micro-segmentation, and software-defined perimeter implementations
- Must be an Omani national eligible for onsite work in Oman
Core Technical Skills
- Network Security: Firewall management, IDS/IPS tuning, DDoS mitigation, NAC, proxy and web filtering
- Cloud Security: AWS/Azure/GCP network security controls, security groups, transit gateways, cloud-native firewalls
- Automation & Scripting: Python, Ansible, Terraform for security policy automation and infrastructure as code
- Threat Intelligence: IOC analysis, threat hunting, MITRE ATT&CK framework mapping
- Compliance & Governance: Risk assessment, policy development, audit readiness, regulatory compliance
- Communication: Technical reporting, stakeholder presentations, cross-team collaboration