Envision Technology Solutions

Network Security Architect / Firewall Consultant

Cincinnati, OH • Posted 2 days ago
Remote Full Time IT Services and IT Consulting

Role: Network Security Architect


• Proven experience defining enterprise network-security architectures across data centers, colocation facilities, points of presence, cloud, branch, third-party, internet edge, and industrial or manufacturing environments.

• Architecture experience across Check Point and Palo Alto firewalls, LAN switching, load balancing, WAF, secure remote access, Zero Trust/Zscaler, cloud ingress and egress, and OT network segmentation.

• Ability to lead discovery, current-state assessment, architecture-gap analysis, target-state design, design reviews, deployment governance, validation, stabilization, and handover to operations.

• Experience developing and approving HLDs, LLDs, network and security diagrams, traffic and data-flow diagrams, bills of materials, implementation roadmaps, migration strategies, architecture standards, and decision records.

• Strong knowledge of network segmentation, zones, routing, BGP/OSPF, NAT, VPN/IPsec, high availability, resilient design, secure management, DNS, certificates, reverse proxies, and application-delivery dependencies.

• Experience designing security patterns for Site Vault, firewall build and operations, third-party connectivity, Zero Trust, internet ingress/egress, WAF, cloud security, and Secure Connected Shops.

• Experience defining policy governance, firewall-rule assurance, access-control standards, configuration baselines, RBAC, least privilege, segregation of duties, and compliance boundaries.

• Experience reviewing architecture and changes for operational risk, availability, resilience, performance, implementation dependencies, testing, rollback, outage, and maintenance-window requirements.

• Knowledge of AWS and Azure network-security services, load balancers, edge controls, infrastructure as code, SIEM/logging, ServiceNow, CMDB, monitoring, and automation integration.

• Experience supporting incident, problem, vulnerability, change, lifecycle refresh, platform optimization, reliability, and continuous-improvement activities from an architecture perspective.

• Working knowledge of ITAR/export-control, CUI or EC environments, FedRAMP, China data-residency separation, secure administration, audit evidence, and regulated delivery models.

• Relevant certifications such as CISSP, CCNP Security/CCIE Security, PCNSE, Check Point CCSE/CCSM, Zscaler, AWS/Azure Security, TOGAF, or SABSA are preferred.


Role: Network Security Firewall Consultant


• Hands-on experience designing, building, configuring, migrating, and supporting Check Point and Palo Alto firewalls across enterprise, data center, colocation, cloud, third-party, and industrial site environments.

• Experience assessing as-is physical and logical networks, identifying deployment gaps, and producing low-level designs, bills of materials, migration plans, implementation runbooks, test plans, and rollback plans.

• Strong knowledge of firewall policies, objects, NAT, zones, routing, BGP/OSPF, VPN/IPsec, high availability, clustering, segmentation, threat prevention, logging, and secure third-party connectivity.

• Experience deploying and operating centralized firewall management platforms, including installation, onboarding, maintenance, upgrades, backup, recovery, and administrative access.

• Experience with lifecycle management covering deployment, consolidation, hardware/software refresh, migration, decommissioning, and license or hardware coordination.

• Ability to perform policy configuration, approval coordination, recertification, rule cleanup, optimization, duplicate/shadow rule analysis, and configuration-drift remediation.

• Experience troubleshooting connectivity and firewall issues using packet captures, traffic logs, routing tables, session analysis, and vendor diagnostic tools.

• Working knowledge of incident, request, problem, change, CAB, and configuration-management processes, preferably using ServiceNow.

• Experience coordinating rack-and-stack or remote hands, go-live, migration, UAT, cutover, stabilization, knowledge transfer, and handover to operations.

• Knowledge of secure segmentation, least privilege, ITAR/export-control requirements, and regulated delivery. Check Point CCSA/CCSE and Palo Alto PCNSA/PCNSE are preferred.

• Good to have: AlgoSec, Panorama, SmartConsole, Cisco networking, Zscaler, AWS/Azure firewalls, load balancers, WAF, Nozomi, Splunk, and automation/scripting.


Network Security Architect / Firewall Consultant in Cincinnati at Envision Technology Solutions

This position is listed as full time and able to be worked remotely. It was posted 2 days ago.

See all Envision Technology Solutions jobs on LocalWork →

Back to Job Search