

DMZ - Network Security Engineer (L3)
Our client runs a Romania-based network & security hub supporting sensitive, defense-grade programs in a NATO context. The team designs and operates on-prem infrastructure for internet-facing services (DMZ), working closely with European stakeholders.
The role
We’re hiring an experienced L3 DMZ Network Security Engineer to administer, support, and continuously improve the DMZ perimeter. You’ll handle post-escalation incidents and complex changes, coach L2 admins, and collaborate with engineering on safe rollouts.
You will contribute to change governance (CAB), keep SOPs and the knowledge base current, maintain testbeds, and ensure patch testing and audit readiness for a highly secure environment.
Key responsibilities:
Provide Level-3 support for DMZ infrastructure, owning high-severity incidents through resolution and driving permanent fixes;
Plan and implement change requests; participate in CAB; keep deployment procedures and documentation up to date:
Coach and mentor L2 administrators; enforce quality on ticket fulfillment and operational hygiene.
Operate and improve security tooling and SOPs; manage lab/testbed environments; support audits and compliance checks.
To thrive in this role, you will:
Bring deep hands-on expertise in DMZ operations, Cisco administration, L2/L3 networking (VLANs), ACL/prefix-lists, and routing (BGP/OSPF/MPLS);
Be fluent with firewalls (Palo Alto; Panorama), IDS/IPS, IPsec, log monitoring, and packet analysis (Wireshark);
Automate and script where useful (Python/Bash); follow ITIL practices across Incident/Change/Problem and related processes;
Communicate clearly in English; able to collaborate with teams in France/Belgium and travel between the two as needed;
Hold (or be eligible for) Romanian and NATO security clearance; background checks apply;
Certifications such as ITIL v4 Foundation and CCNA are highly appreciated.
Onsite, Romania


