
Senior Network Security Engineer
- Network Security
- Palo Alto Networks
- Fortinet
- NAT
- DNS
- AI
- SIEM
- SSL
- AIOps
- Incident Management
- TCP/IP
- DHCP
- TLS
- Change Management
- Windows
- Incident Response
- PCNSE
- Vulnerability Management
- EDR
- Azure
- AWS Cloud
- Equity
Job Overview
We are seeking a hands-on Network Security Engineer with deep experience in NexGen firewalls such as Palo Alto Networks, Checkpoint and Fortinet technologies to help operate, secure, and continuously improve Arrowstreet’s network security environment. This role will focus on the administration, tuning, troubleshooting, and lifecycle management of NexGen firewalls and NexGen VPN security policies, threat prevention profiles, URL filtering, VPN connectivity, and related network security controls.
The successful candidate will have strong practical knowledge of enterprise networking, firewall policy management, packet-level troubleshooting, secure remote access, segmentation, logging, monitoring, and incident support.
This role requires someone who can work independently, partner effectively with infrastructure and security teams, and apply sound judgment when supporting production network security infrastructure.
Responsibilities
Administer, maintain, and improve NexGen firewall infrastructure, including policy rules, NAT, security profiles, zones, interfaces, objects, and routing configurations.
Manage management portal configuration, templates, device groups, policy pushes, configuration backups, and rule-base hygiene across the environment.
Configure and tune threat prevention, antivirus, anti-spyware, vulnerability protection, URL filtering, DNS security, sandboxing, decryption, and logging profiles.
Support remote connectivity operations, including authentication flows, client connectivity, portal and gateway configuration, troubleshooting, and user-impacting incidents.
Leverage advanced AI modeling within our SIEM platform to monitor firewall logs, traffic patterns, system health, policy hits, blocked activity, and IPS security events. Use AI to associate and contextualize threats detected by these alerts, uncover attack patterns, prioritize incidents based on risk, and identify policy gaps—enabling proactive tuning and continuous improvement of our security posture.
Troubleshoot network security issues across Layer 3 through Layer 7, including routing, NAT, VPN, application identification, SSL decryption, asymmetric traffic, and policy-matching behavior.
Perform packet captures, traffic analysis, and root-cause investigations using vendor tools, CLI diagnostics, logging platforms, and network troubleshooting utilities.
Participate in firewall rule reviews, access request evaluations, segmentation efforts, cleanup activities, and control validation exercises.
Expand the development and integration of advanced AI-powered features within AI Operations (AIOps) service platforms to proactively detect, diagnose, and remediate network and security issues. Drive this innovation by integrating AIOps solutions to strengthen incident management, optimize firewall performance, and enhance user experience across network capacity and routing.
Plan and execute routine maintenance, including content updates, firmware upgrades, high-availability validation, license checks, and capacity monitoring.
Partner with network engineering, infrastructure, cloud, identity, endpoint, and application teams to ensure security controls are integrated cleanly into enterprise technology changes.
Maintain accurate operational documentation, diagrams, procedures, support runbooks, change records, and evidence for audit or control review purposes.
Qualifications
Five or more years of hands-on experience in network security, firewall administration, security operations engineering, network engineering, or a closely related technical role.
Strong working knowledge of NexGen firewall technologies, including next-generation firewalls, management portals, NexGen VPN, L7 application, User based ID's, security profiles, and logging.
Solid understanding of networking fundamentals, including TCP/IP, subnetting, routing, switching, DNS, DHCP, NAT, VPN, TLS, HTTP/S, and common enterprise network architectures.
Experience implementing and troubleshooting firewall policies, traffic flows, application identification, URL filtering, threat prevention, decryption, and remote access controls.
Experience supporting production change management, maintenance windows, firewall upgrades, rule-base changes, and operational troubleshooting in a business-critical environment.
Strong documentation skills, including the ability to maintain clear runbooks, diagrams, implementation notes, incident summaries, and control evidence.
Ability to communicate effectively with technical teams, service owners, end users, vendors, and security stakeholders.
Self-motivated, detail-oriented, and able to take ownership of issues through investigation, escalation, resolution, and follow-up.
Willingness to support scheduled after-hours maintenance and participate in incident response activities when required.
Familiarity with security frameworks, audit expectations, change management, incident response processes, and enterprise control documentation.
Understanding of AI concepts and their applications in network and firewall security is a plus.
NexGen Palo Alto Networks, Checkpoint and Fortinet technologies certifications such as PCNSA or PCNSE or equivalent are a plus.
Experience with VPN, cloud network security, SIEM integrations, vulnerability management, EDR/XDR platforms, or Microsoft 365 security telemetry is an asset.
Experience in financial services, asset management, banking, insurance, or another regulated industry is valuable.
Azure/AWS Cloud experience is a plus.
IaaS and automation experiences are a plus.
The base salary range for this position is $110,000 - $315,000 per year.
Arrowstreet Capital operates a robust talent acquisition program, and we also seek to compensate and reward our employees competitively within our industry and in line with our merit-based culture. Our approach to total compensation includes base salaries and annual discretionary bonuses, as well as a robust benefits package. The determination of a successful candidate’s base salary placement within the listed range will vary based on the candidate’s relevant experience and qualifications (which may also include relevant certifications, credentials and other education), the job responsibilities and scope, the commensurate resulting level of the position and other relevant factors. The listed range is also an estimate, and additional information regarding base salary and other elements of total compensation offered by Arrowstreet Capital to successful applicants will be communicated during the recruitment process. Â
Arrowstreet Capital is a Boston-based systematic investment firm that manages global equity portfolios for institutional investors around the world.Â
All qualified applicants will receive consideration for employment without regard to sex, race, color, religion, national origin, ancestry, genetic information, age, pregnancy, medical condition, disability, veteran or military status, marital status or any other characteristic protected by federal, state, or local law.
Arrowstreet Capital is committed to working with and providing reasonable accommodations for qualified individuals with disabilities and disabled veterans. If you need a reasonable accommodation for any part of the employment process due to a disability,contact us to discuss the nature of your request and contact information.
Senior Network Security Engineer · Arrowstreet Capital, Limited Partnership