Leads the architecture and design of network security subsystems, including firewall, IDS/IPS, and IPsec VPN.
Key Responsibilities
- Architect network security subsystems (stateful firewall, IDS/IPS, IPsec VPN, DDoS mitigation) compliant with IETF/ISO standards
- Design and implement stateful firewall with zone-based policy, connection tracking, NAT/PAT, and ALGs
- Design and implement IKEv1/IKEv2 and IPsec (ESP/AH, tunnel/transport modes, AES-GCM/ChaCha20-Poly1305)
- Design and implement IDS/IPS with signature and anomaly-based detection, and DDoS mitigation for SYN/UDP/ICMP flood and amplification attacks
- Implement the AAA framework (RADIUS, TACACS+, 802.1X) for authentication, authorization, and accounting
- Design for high-throughput security processing with hardware acceleration, and mentor engineers on threat mitigation best practices
Requirements
- 10+ years in software engineering, with 5+ years focused on network security systems development
- Expert knowledge of stateful firewall architecture, IPsec (RFC 4301/4303) and IKE (RFC 7296) with hands-on implementation experience
- Deep understanding of IDS/IPS technologies (Snort, Suricata) and DDoS attack vectors and mitigation techniques
- Deep understanding of cryptography and PKI — AES-GCM, RSA/ECDSA, TLS 1.2/1.3, X.509 certificate validation
Nice to Have
- Experience with enterprise firewall, NGFW, or UTM platform development
- Experience with security compliance frameworks (PCI-DSS, HIPAA, ISO 27001)
- Multi-vendor security platform development experience