American Bureau of Shipping
Engineer III, Systems Network
Houston, Texas · Hybrid · Posted today
Opens hbbq.fa.us2.oraclecloud.com
Get a version of your resume written for this job.
- Salary
- Not listed
- Job type
- Full-time
- Work mode
- Hybrid
- Source
- Oracle (employer's hiring system)
Skills mentioned
Azure, Zero Trust, GCP, Python, Bash, Incident Response
About the role
The Systems Network Engineer III leads the design, standardization, and continuous improvement of network security infrastructure across ABS’s global hybrid-cloud environment. This role bridges engineering execution with strategic architecture, developing network security best practices using industry frameworks, driving automation, and establishing governance processes that strengthen the organization’s infrastructure posture. The Engineer III, Network Security provides technical leadership to the engineering team through documentation, standards development, and architectural oversight, while advancing Zero Trust initiatives including identity-based access controls, firewall policy lifecycle management, and infrastructure-as-code adoption.
What You Will Do:
- Define and maintain the enterprise network security infrastructure roadmap, ensuring alignment with Zero Trust principles, NIST 800-171/CMMC compliance frameworks, and business objectives.
- Design secure, scalable, high-availability network architectures across on-premises, Azure, Oracle Cloud, and multi-cloud environments.
- Develop network security best practices using industry frameworks and translate security policy requirements into infrastructure designs that enforce them.
- Evaluate emerging technologies and provide architectural recommendations to IT leadership.
- Serve as the technical authority on firewall, segmentation, VPN, and remote access infrastructure decisions.
- Develop and maintain reference architectures, design patterns, and standards for network security infrastructure.
- Evaluate and integrate technologies that provide comprehensive user-to-resource mapping across on-premises, cloud, and remote access environments.
- Develop infrastructure standards for identity-based policy enforcement that reduce the attack surface and support Zero Trust maturity across the organization.
- Design and implement a firewall policy cleanup and ownership workflow, establishing clear rule ownership, periodic review cadences, and decommission processes.
- Lead firewall rulebase optimization efforts, identifying unused, shadowed, overly permissive, and redundant rules across security and NAT policies.
- Identify repeatable, manual engineering workflows and lead the effort to standardize and automate them, reducing human error and improving deployment consistency.
- Establish documentation standards and templates for the engineering team to follow, ensuring knowledge is captured and transferable.
- Provide architectural guidance and mentorship to network and firewall engineers, ensuring engineering execution aligns with architectural standards.
- Lead cross-functional collaboration with security operations, cloud engineering, identity/access management, and application teams.
- Partner with the security team to understand policy requirements and translate them into infrastructure designs and configurations.
- Serve as subject matter expert and escalation point for complex firewall, VPN, routing, and multi-cloud connectivity issues.
- Support security audits, compliance assessments, and incident response with architectural context and technical expertise.
What You Will Need:
Education and Experience
- 8+ years of progressive experience in network security engineering, with at least 3 years in an senior engineer or technical lead capacity. Must include 5+ years of hands-on experience with Palo Alto NGFW and Panorama in a global enterprise environment with hybrid-cloud infrastructure.
- Typically requires a college degree or recognized equivalent, preferably in Computer Science, Computer Engineering, or related field, from an accredited university or comparable on-the-job experience. Technical certifications are a plus.
- Palo Alto PCNSA / PCNSE
- Cisco CCNP (Security or Enterprise)
- Cloud certifications (Azure, OCI, GCP)
- NIST / CMMC related certifications
- Cloudflare ASE/ACE, Zscaler ZDTA,ZDTE,ZDXA
Knowledge, Skills and Abilities
- Deep expertise in designing enterprise-grade network security infrastructure across hybrid-cloud environments (on-prem, Azure, OCI, GCP).
- Advanced knowledge of Palo Alto NGFW, Panorama (device groups, templates, template stacks, variables), App-ID, Threat Prevention, GlobalProtect, and Security Zone design.
- Proven experience redesigning and optimizing large-scale firewall rulebases (1000+ rules) with a focus on segmentation, least privilege, and policy lifecycle governance.
- Strong command of BGP, OSPF, EIGRP, VPC, HSRP, VLAN design, SD-WAN, and DMVPN architectures.
- Extensive experience with IPSec VPN (site-to-site and third-party), GlobalProtect, SSL VPNs, SAML/MFA integration, and failover design.
- Hands-on experience with Azure VNet, NSG, Azure Firewall, OCI VCN/DRG, and cloud interconnects (Megaport, ExpressRoute).
- Working knowledge of Zero Trust architecture principles, microsegmentation strategies, NIST 800-171, NIST 800-53, and CMMC frameworks.
- Demonstrated ability to produce clear, actionable technical documentation including runbooks, SOPs, design documents, and training materials.
- Ability to articulate architectural decisions to both technical and non-technical stakeholders; experience mentoring engineers and leading technical initiatives.
- Experience evaluating and implementing automation tools and frameworks for network infrastructure provisioning, configuration management, and policy deployment is a plus.
- F5 LTM/GTM, A10, and/or Azure Application Gateway experience is a plus.
- A10 WAF, Azure WAF, and OWASP Top-10 policy enforcement familiarity is a plus.
- Cloudflare/Zscaler experience is a plus.
- SolarWinds NPM, HPNA, or equivalent network monitoring/management platform experience is a plus.
- Familiarity with Python, Bash, or similar scripting for ad-hoc automation and tooling is a plus.
- Understanding of ITAR compliance requirements and their impact on infrastructure design.
- Working knowledge of the ABS Health, Safety, Quality and Environmental Management System.
Reporting Relationships:
The incumbent reports directly to IMS Management, as appropriate. Direct reports may include outside contractors.
Notice:
This position requires access to information that is subject to control by the Export Administration Regulations and/or the International Traffic in Arms Regulations. Any offer of employment shall be contingent upon the Company’s verification that the candidate is a “U.S. Person” or upon the receipt of all necessary export licenses or authorizations that may be required by U.S. export control laws. “U.S. Persons” are defined as U.S. citizens, U.S. lawful permanent residents (i.e., “green card” holders), or any individual granted protected status under the Immigration and Nationality Act (8 U.S.C. § 1324b(a)(3)), including asylees and refugees. In the event a candidate refuses or cannot otherwise provide the necessary information for the Company to determine whether such licenses may be required, or for the Company to obtain any required licenses, the Company shall maintain the exclusive right to discontinue the application process and/or withdraw any contingent offer that has been made.
Job ID or-hbbq-fa-us2-oraclecloud-com-cx-1-4896 · Original posting ↗
Visa sponsorship history
- 6 H-1B petitions approved for AMERICAN BUREAU OF SHIPPING in fiscal year 2023 (USCIS).
From public government data. It shows this employer has sponsored workers before, not that this job offers sponsorship: check the job ad or ask the employer. More visa-friendly jobs
Similar jobs
Network Engineer (Journeyman) – Colorado Springs, CONewCNF Technologies CorpColorado Springs, Colorado
Software Engineer II, Developer Portal (New Grad / Early Career)NewID.meMountain View, California
- DWM Telecom Engineer I - Senior Cloud Communication (AIM)NewAtlanta, Georgia
- DWM Telecom Engineer I - Senior Cloud Communication (AIM)NewAtlanta, Georgia
- Lead Software EngineerNewJP Morgan ChaseSeattle, Washington