Role Overview
You will lead the end‑to‑end deployment of a next‑generation firewall infrastructure that enforces zero‑trust policies across our network. Day to day, your work involves architecting high‑availability configurations, migrating security rules from legacy systems, and integrating advanced threat detection with centralized cloud management. This role is critical because the firewall is the backbone of our identity‑aware access control and multi‑site protection, directly enabling secure remote connectivity and regulatory compliance.
Key Responsibilities
- Design and implement enterprise‑grade next‑generation firewall appliances in active‑active or active‑passive high‑availability pairs for both primary and disaster recovery sites.
- Configure identity‑aware access policies, SSL/TLS inspection, intrusion prevention, and advanced malware sandboxing to inspect all traffic at Layer 7.
- Build zero‑trust network access controls, including device posture assessment, endpoint telemetry integration, and micro‑segmentation across internal segments.
- Deploy and fine‑tune SD‑WAN configurations to optimise traffic routing between sites while maintaining policy synchronisation via a centralised cloud management platform.
- Migrate existing firewall rules and security policies to the new platform, validating that all business‑critical flows remain uninterrupted during cutover.
- Create detailed security policy documentation, SD‑WAN configuration guides, and acceptance test reports that demonstrate compliance with organisational security standards.
- Deliver hands‑on training to administrators and produce knowledge‑transfer materials so the internal team can operate and maintain the solution after handover.
- Coordinate with vendors to ensure timely delivery, firmware updates, and 24/7 support coverage, including escalation procedures for critical incidents.
Requirements & Qualifications
- Five or more years of experience deploying, configuring, and supporting enterprise‑grade next‑generation firewalls in multi‑site, high‑availability environments.
- Deep understanding of zero‑trust architecture principles and hands‑on experience with device posture checks, micro‑segmentation, and identity‑based policy engines.
- Proven track record of leading at least three similar firewall replacement or greenfield implementation projects within the past five years, from design through production acceptance.
- Industry certifications such as CISSP, CCNP Security, or vendor‑specific NGFW certifications (e.g., from Palo Alto Networks, Fortinet, or Cisco).
- Strong ability to write clear technical documentation, including migration plans, policy rule sets, and post‑implementation reports.
- Experience administering centralized cloud‑based management platforms and synchronising policies across geographically separated firewalls.
- Familiarity with recognised cybersecurity frameworks (ISO 27001, NIST Cybersecurity Framework, CIS Controls) and how firewall controls map to compliance requirements.
- Bachelor’s degree in computer science, information security, or a related field; equivalent experience may substitute.
What We Offer / Why Join
This engagement is a fixed‑term project role with the opportunity to demonstrate strategic security architecture that directly reduces organisational risk. You will work with a modern stack of security technologies and have autonomy to define the migration approach. The role includes comprehensive support from internal stakeholders and manufacturer‑backed resources where applicable.
497 open positions on Semasocial right now
· 8134 open positions in Nairobi County, Kenya
· 30 posted in the last 7 days
Contact Information