Cybersecurity Network Engineer
Application Security
Azure
Azure Networking
Casb
Cloud
Cloud Platform
Cloud Platforms
Cloud Security
Data Loss Prevention
Data Security
Ddos Mitigation
Endpoint Security
Engineer
Identity and Access Management
Incident Response
Information Security
InfoSec
Microsegmentation
Network Security
Security
Security Automation
Security Operations
Ssl/tls Inspection
Web Application Firewall
Web Gateway
Zero Trust Architecture
Job Description
Seminole Hard Rock Support Services is seeking a hands-on Cybersecurity Network Engineer to build, operate, and continuously enhance enterprise network security controls across on-premises and cloud environments. In this role, you will turn network architecture and security policy into measurable, automated defenses, with Microsoft Azure as the primary cloud and additional coverage spanning AWS and Google Cloud. The work focuses on deploying and tuning secure access, edge, and segmentation controls while instrumenting telemetry for detection, triage, and response.
What you will do
- Deploy, configure, and tune secure-access service edge controls including secure web gateway, cloud firewall, CASB, and DLP policies, maintaining coverage and current policy alignment.
- Operate zero-trust network access for workforce and third parties, moving away from legacy VPN patterns toward identity-aware, least-privilege application access.
- Operate an enterprise browser to enforce least-privilege isolated access to sensitive applications from both managed and unmanaged endpoints.
- Tune SSL/TLS inspection, tenant restrictions, and egress policy to balance security, privacy, and application compatibility, including traffic sensitive to interception such as NTLM, Kerberos, and certificate-pinned traffic.
- Manage traffic steering, forwarding, and PAC configurations so users route through the correct control path from any worldwide location.
- Administer edge and perimeter defenses such as WAF rules, DDoS mitigation, bot management, and CDN and DNS policies for internet-facing properties.
- Operate API security posture and runtime protection by discovering shadow APIs and closing authentication and data-exposure gaps.
- Administer next-generation firewall policy, NAT, and rule lifecycle across data center and property perimeters, supporting rule hygiene and least-privilege access.
- Harden DNS, certificate, and TLS posture at the edge in partnership with PKI and infrastructure teams.
- Coordinate perimeter changes with franchise, property, and vendor networks so remote sites integrate securely without breaking authentication or application flows.
- Deploy and tune network detection and response, triaging anomalous east-west and north-south activity and delivering high-fidelity findings to the SOC.
- Engineer network telemetry pipelines (flow data, DNS logs, proxy logs, firewall logs, packet metadata) to route, shape, and enrich data for cost-effective analysis.
- Develop and tune network-focused detections and SIEM content, mapping coverage to attacker techniques.
- Investigate network-layer incidents end-to-end by correlating packet capture, flow, proxy, and firewall logs to isolate root cause under time pressure.
- Maintain authoritative visibility of network assets and attack surface by continuously reconciling what is connected against what is inventoried.
- Apply zero-trust segmentation and least-privilege access across campus, data center, gaming, and hospitality network estates.
- Design and enforce microsegmentation and network policy for sensitive zones including payment, gaming, surveillance, and OT/IoT environments, in partnership with infrastructure and compliance teams.
- Implement cloud network security guardrails across Azure (primary), AWS, and Google Cloud, including virtual network design, firewalling, private connectivity, and logging baselines such as Azure Firewall, NSGs, and Private Link.
- Remediate cloud network misconfigurations and exposure paths identified by posture management to prevent long-term drift.
- Integrate network security checks into infrastructure-as-code and deployment workflows so network changes are secure by default.
- Build and maintain network security automations, integrations, and response playbooks across the stack using APIs and SOAR.
- Leverage AI/ML and large language models to analyze network telemetry at scale, accelerate alert triage and enrichment, surface anomalies, and automate reporting and documentation.
- Develop production-grade scripts, services, and tooling (including Python, PowerShell, and Go) to operationalize network controls and reduce repetitive manual work.
- Automate firewall rule reviews, policy validation, and configuration compliance checks so drift is caught by pipelines rather than manual review.
- Instrument metrics and dashboards that measure network control coverage, detection efficacy, and remediation timeliness.
- Partner with Cybersecurity Architecture, IAM, infrastructure, application, and SOC/MSSP teams to deploy network controls consistently and resolve issues quickly.
- Support Cybersecurity Strategy & Governance, audit, and privacy programs by automating evidence collection and continuous control monitoring for network controls.
- Document standards, runbooks, integration designs, and operating procedures to keep network controls repeatable and supportable.
- Research, prototype, and pilot emerging network security tools and AI-driven capabilities that improve detection, automation, and analyst efficiency.
- Participate in an on-call rotation and incident response for a 24/7 gaming and hospitality environment.
Experience and skills
- 5–7+ years of combined experience in network engineering, network security engineering, or cloud networking, with at least 4+ years hands-on focused on enterprise network security engineering.
- Strong enterprise network engineering fundamentals, including hands-on design, operation, and troubleshooting of routing and switching, firewalls, proxies, VPN/ZTNA, load balancing, DNS, and TLS/PKI.
- Practical automation capability with hands-on experience in Python, PowerShell, Go or similar languages, including building custom network security tooling and integrations.
- Experience applying AI/ML or large language models to network data analysis, detection, triage, or automation.
- Working knowledge of SASE/SSE platforms including SWG, ZTNA, CASB, and DLP, plus WAF and DDoS mitigation, NDR, and API security.
- Hands-on cloud network security experience on Microsoft Azure (required), plus working experience in AWS and/or Google Cloud involving virtual network design, cloud firewalls, private connectivity, and network security posture management.
- Deep networking knowledge including TCP/IP, BGP/OSPF, DNS, DHCP, TLS/PKI, NAT, IPv6, packet analysis, segmentation, and zero-trust access models.
- Experience integrating network security tools and data sources via API, familiarity with SOAR playbook development, and SIEM content engineering.
- Familiarity with relevant gaming and hospitality compliance frameworks such as PCI-DSS, SOX, tribal gaming regulations, and GLBA is preferred but not required.
- Certifications preferred: Cisco CCNP Security, vendor certifications in next-generation firewalls and SASE/SSE platforms, Microsoft AZ-700 or AZ-500, AWS Advanced Networking Specialty, and GIAC (GCIA, GDSA, GCLD) or equivalent; CISSP is a plus.
Technologies you will work with
- Cloud and networking: Microsoft Azure, AWS, Google Cloud, SASE, SWG, ZTNA, CASB, DLP, Azure Firewall, NSGs, Private Link, microsegmentation, zero-trust access, NAT, PKI, infrastructure-as-code
- Security controls and telemetry: SSL/TLS inspection, NTLM, Kerberos, WAF, DDoS mitigation, bot management, CDN, DNS, API security, SIEM, SOAR, telemetry pipeline, packet metadata
- Languages and automation: Python, PowerShell, Go
- Compliance frameworks and certifications (as applicable): SOX, PCI-DSS, GLBA, Cisco CCNP Security, Microsoft AZ-700, Microsoft AZ-500, AWS Advanced Networking Specialty, GIAC (GCIA, GDSA, GCLD), CISSP
Benefits
- Comprehensive benefits package supporting health and well-being, planning for the future, and maintaining a healthy work-life balance.
- Benefits may vary with employment status.