Network Security Engineer
Job Title: Network Security Lead engineerLocation: Remote - New York/ New Jersey(Local Candidates only)Job Type: ContractJob Description:Designs and owns enterprise network security architecture across cloud, on-premise, and hybrid environmentsDefines standards for firewalls, VPNs, zero-trust, network segmentation, and perimeter controlsConducts threat modelling, architecture reviews, and risk assessments to identify and remediate security gapsEvaluates and selects network security technologies including SASE, SD-WAN, IDS/IPS, and NAC solutionsEmbeds security into infrastructure and cloud design from the outset through cross-functional collaborationEnsures compliance with ISO 27001, SOC 2, HIPAA, NIST, and applicable regulatory frameworksProvides technical governance and mentors junior security engineers across network security projects8+ years of hands-on experience with Cisco, Palo Alto, Zscaler, or equivalent platformsStrong knowledge of TCP/IP, BGP, routing protocols, and cloud networking (AWS / Azure)Associated certifications preferred.About the RoleThis role combines hands-on cloud networking with architecture and documentation ownership: you will design secure connectivity across AWS, Azure, and Snowflake, and produce the architecture, data flow, and process flow documentation that business, compliance, and audit stakeholders depend on. All work is performed under HIPAA, with PHI protection treated as a first-order design constraint.Key ResponsibilitiesArchitecture & GovernanceDesign and own enterprise network security architecture across cloud, on-premise, and hybrid environmentsDefine standards for firewalls, VPNs, zero-trust, network segmentation, and perimeter controlsConduct threat modeling, architecture reviews, and risk assessments to identify and remediate security gapsEvaluate and select network security technologies including SASE, SD-WAN, IDS/IPS, and NACEmbed security into infrastructure and cloud design from the outset through cross-functional collaborationProvide technical governance and mentor junior security engineers across network security projectsDocumentation & BlueprintsReview, validate, and recreate business blueprint documentation where source material is outdated or incompleteProduce secure architecture diagrams covering topology, segmentation, trust boundaries, and control pointsDevelop end-to-end data flow diagrams tracing PHI movement across systems and organizational boundaries, including encryption state at each hopCreate process flow diagrams for operational and integration workflows, and keep all documentation synchronized with the deployed environmentCloud & Connectivity EngineeringDesign, configure, and troubleshoot IPsec site-to-site VPN tunnels, AWS Transit Gateway, Azure Virtual WAN, VPC/VNet peering, and private connectivity (AWS PrivateLink, Azure Private Link, Snowflake PrivateLink)Secure data ingress/egress paths into Snowflake, including network policies and storage integrationsSupport hybrid connectivity between on-premise data centers and cloud (Direct Connect, ExpressRoute, VPN)Design and support secure file transfer using SFTP, FTPS, and HTTPS/TLS, including certificate and key lifecycle managementComplianceEnsure compliance with ISO 27001, SOC 2, HIPAA, NIST, and applicable regulatory frameworksPartner with Security, Privacy, and Compliance teams on control mapping and audit evidenceEnforce encryption in transit and at rest across all PHI-bearing data pathsRequired Qualifications8+ years of hands-on experience with Cisco, Palo Alto, Zscaler, or equivalent platformsStrong knowledge of TCP/IP, BGP, routing protocols, and cloud networking (AWS / Azure)Production experience designing and troubleshooting VPN tunnels, including IPsec/IKEv2 and BGP routingPractical experience with secure transmission protocols: SFTP, FTPS, HTTPS/TLS, mTLS, SSH key and certificate managementProven track record producing architecture, data flow, and process flow diagrams for technical and compliance audiencesWorking knowledge of HIPAA and HITECH, particularly the Security Rule's transmission security and access control provisionsHealthcare domain experience — payer, provider, HIE, or health tech — with familiarity handling PHIExcellent written communication; documentation that stands up to audit scrutinyPreferred QualificationsAssociated certifications: CISSP, AWS Advanced Networking – Specialty, AZ-700, CCNP/CCIE Security, PCNSEHealthcare data standards: HL7 v2, FHIR R4, X12 EDI (837, 835, 834, 270/271, 278)Familiarity with CMS interoperability regulations (CMS-9115-F, CMS-0057-F)Infrastructure as Code: Terraform, CloudFormation, or BicepHITRUST or NIST 800-53 control framework experienceDiagramming and modeling tools: Lucidchart, Visio, draw.io, C4/ArchiMate