Security Managed Services Practitioner
Accenture India Private LimitedJob Description
Security Managed Services Practitioner
Project Role : Security Managed Services PractitionerProject Role Description : Deliver and manage security services across client environments to ensure protection, compliance, and operational resilience.
Must have skills : Network Security Operations, Zscaler Architecture, Cisco Identity Services Engine (ISE)
Good to have skills : NA
Minimum 5 year(s) of experience is required
Educational Qualification : 15 years full time education
Summary:
A typical day of a subject matter expert and as an accomplished Network Security / Firewall Engineer Team lead, your role demands to broad and deep expertise spanning next-generation firewall (NGFW) platforms, Web Application Firewall (WAF) technologies, and Zscaler cloud security services — unified under a cohesive Zero Trust security strategy.
As a Level 3 engineer, you will lead architectural decisions, drive security policy governance, own escalation for complex incidents, and mentor junior engineers. You will partner with application, cloud, and SOC teams to design and enforce security controls that protect the organization's network perimeter, web-facing applications, and distributed workforce — across on-premises, multi-cloud, and hybrid environments.
Roles & Responsibilities:
- Expected to be an SME, collaborate and manage the team to perform.
- Design, deploy, and manage enterprise NGFW platforms including Palo Alto Networks (PA-Series, VM-Series, Panorama), Fortinet FortiGate (FortiManager, FortiAnalyzer), Cisco ASA/FTD/Firepower, and/or Check Point Security Gateways.
- Develop, review, and enforce firewall security policies — access control rules, NAT, application-layer filtering (App-ID), User-ID, and content inspection.
- Deploy and administer enterprise WAF solutions including F5 BIG-IP ASM/AWAF, Imperva SecureSphere/Cloud WAF, AWS WAF, Azure Application Gateway WAF, and/or Cloudflare WAF.
- Develop and maintain WAF security policies to protect web applications against OWASP Top 10 threats: SQL injection, XSS, CSRF, RFI/LFI, command injection, and bot attacks.
- Lead the deployment and management of Zscaler Internet Access (ZIA) — including secure web gateway (SWG), SSL/TLS inspection, CASB, cloud sandbox, DLP, and advanced threat protection.
- Administer Zscaler Private Access (ZPA) for zero-trust application access, replacing legacy VPN with identity-aware, least-privilege connectivity to internal and SaaS applications.
- Manage ZPA App Connectors, App Segments, Connector Groups, and Broker-Based Access architecture for secure internal application publishing.
- Configure and maintain Zscaler Digital Experience (ZDX) for end-user experience monitoring, application performance visibility, a- nd network path diagnostics.
- Own the long-term security architecture roadmap for firewall, WAF, and cloud security platforms aligned with Zero Trust Network Access (ZTNA) principles.
- Design integrated security architectures that unify perimeter NGFW enforcement, WAF application protection, and Zscaler cloud-based inspection in a cohesive layered model.
- Lead network security design reviews for new projects, cloud migrations, and application deployments — ensuring security is embedded from inception.
- Serve as the Level 3 escalation point for firewall, WAF, and Zscaler security incidents, policy violations, and network-layer attacks.
- Investigate and respond to threats including DDoS attacks, web application exploitation, network intrusions, lateral movement, and data exfiltration attempts.
- Analyze firewall traffic logs, WAF event logs, and Zscaler threat intelligence to identify attack campaigns and anomalous behavior.
- Perform root cause analysis (RCA) for security incidents and produce actionable post-incident reports with remediation recommendations.
- Serve as the Level 3 escalat- ion point for firewall, WAF, and Zscaler security incidents, policy violations, and network-layer attacks.
- Investigate and respond to threats including DDoS attacks, web application exploitation, network intrusions, lateral movement, and data exfiltration attempts.
- Analyze firewall traffic logs, WAF event logs, and Zscaler threat intelligence to identify attack campaigns and anomalous behavior.
- Perform root cause analysis (RCA) for security incidents and produce actionable post-incident reports with remediation recommendations.
Professional & Technical Skills:
- Must To Have Skills: Proficiency in A&D Aftermarket.
- 8+ years in network security or infrastructure security, with at least 4–5 years as a lead/senior NGFW engineer.
- 3+ years of hands-on WAF administration (F5, Imperva, AWS WAF, Azure WAF, or equivalent).
- 2+ years of hands-on Zscaler ZIA and ZPA administration in enterprise environments.
- Demonstrated experience leading security operations or serving as a technical SME/escalation point.
- Expert-level proficiency in at least two major NGFW platforms: Palo Alto Networks (PAN-OS, Panorama), Fortinet FortiGate (FortiOS, FortiManager), Cisco ASA/FTD, or Check Point.
- Deep knowledge of firewall policy design: security zones, NAT, application control, User-ID, URL filtering, and HA configurations.
- Hands-on experience administering WAF platforms: F5 BIG-IP ASM/AWAF, Imperva, AWS WAF, Azure Application Gateway WAF, and/or Cloudflare.
- Strong understanding of OWASP Top 10, web application attack vectors, and WAF detection/prevention techniques.
- Proficiency in Zscaler Admin Portal — ZIA and ZPA policy configuration, user/group management, and reporting.
- Experience configuring GRE/IPsec tunnels, PAC files, and Zscaler Client Connector deployments.
- Familiarity with ZPA App Connectors, Connector Groups, and zero-trust application access architecture.
- Strong networking fundamentals: TCP/IP, BGP/OSPF, VLANs, spanning tree, DNS, HTTP/S, and TLS.
- Scripting/automation skills: Python, PowerShell, Bash, or Ansible for firewall/WAF/API automation.
- Familiarity with cloud security: AWS Security Groups/NACLs, Azure NSGs, GCP firewall rules, and cloud-native WAF services.
Additional Information:
- The candidate should have minimum 5 years of experience in A&D Aftermarket.
- This position is based at our BDC7A - SEZ office.
- A 15 years full time education is required.
- Palo Alto Networks certifications: PCNSE (Palo Alto Networks Certified Network Security Engineer).
- Fortinet certifications: NSE 7 or NSE 8 (Network Security Expert).
- Check Point certifications: CCSE (Check Point Certified Security Expert).
- Zscaler certifications: Zscaler Certified Professional (ZCP) — ZIA and/or ZPA tracks.
- F5 certifications: F5-CSE (Certified Solution Expert) or equivalent.
Job role
Job requirements
About company
Similar jobs you can apply for
Accounts / Finance
Laptop Hardware Technician
Jaya Surya Computers
Maintenance Engineer
Mythri Metallizing Private Limited
Installation Engineer
Neo San
Field Service Engineer
M Intergraph Systems Private Limited
Field Desktop Support Engineer
Crown Technologies
IT Sales Executive
Solasta Ayer Pvt. Ltd.You can expect a minimum salary of 0 INR. The salary offered will depend on your skills, experience and performance in the interview.
The candidate should have completed the required education and people who have 5 to 10 years are eligible to apply for this job. You can apply for more jobs in Bengaluru/Bangalore to get hired quickly.
The candidate should have sound communication skills and sound communication skills for this job.
Both Male and Female candidates can apply for this job.
No, it's not a work from home job and can't be done online. You can explore and apply for other work from home jobs in Bengaluru/Bangalore at apna.
No work-related deposit needs to be made during your employment with the company.
Go to the apna app and apply for this job. Click on the apply button and call HR directly to schedule your interview.
The last date to apply for this job is . For more details, download apna app and find Full Time jobs in Bengaluru/Bangalore . Through apna, you can find jobs in 64 cities across India. Join NOW!