1. Home
  2. Jobs
  3. Synkcode Fzco
  4. Senior Network, Security & Platform Architect/Engineer
Cybersecurity

Senior Network, Security & Platform Architect/Engineer

Synkcode Fzco
Dubai, UAE Listed 1 month ago via Naukrigulf
kubernetes linux nginx cybersecurity siem security

Job Overview

Company Industry DefenceMilitaryGovernment
Department / Functional Area IT Hardware SupportIT Hardware Repair & Maintenance
Keywords AutomationInfrastructure As CodeDisaster RecoveryDirector Of Network EngineeringCybersecurityPrincipal Network EngineerSenior Systems ArchitectDevOps

Network Architecture and Design Develop high-level and low-level network designs for segmented enterprise platforms. Design inbound and outbound DMZs, trusted application zones, and management, operations, backup, and data networks. Define VLANs, subnets, gateways, route tables, firewall boundaries, NAT, DNS, and IP-address allocations. Apply default-deny segmentation and permit only approved source, destination, protocol, and port combinations. Prepare architecture diagrams, traffic flows, communication matrices, allocation registers, and implementation records. RHEL and KVM Virtualization Design and administer RHEL-based KVM environments, Open vSwitch or Linux bridges, and VLAN-backed virtual interfaces. Create isolated hypervisor-only networks and map VM interfaces to approved bridges, VLANs, and port groups. Implement virtual firewall and Layer 3 routing services while separating management from application traffic. Kubernetes Network and Security Engineering Design separate public-facing and private Kubernetes worker groups and enforce appropriate workload placement. Implement default-deny NetworkPolicies, namespace isolation, controlled service/DNS exposure, and explicit ingress and egress. Protect control-plane and node-management interfaces and prevent workloads from bypassing approved gateways and firewalls. API Gateway and Proxy Engineering Design and operate APISIX gateways for inbound, internal, and outbound API traffic. Configure authentication, authorization, mTLS, request validation, rate limits, allowlists, routing policies, tracing, and audit logs. Configure NGINX reverse and egress proxies with approved upstreams, methods, paths, headers, and external destinations.

Desired Candidate Profile

Network and Platform Security Implement layered controls across WAF, firewalls, APISIX, NGINX, Kubernetes, NAT, and DNS. Prevent direct internet access to Kubernetes nodes, private services, databases, and management interfaces. Enforce destination, FQDN, IP, protocol, and port allowlists; permit only stateful return traffic for approved outbound sessions. Apply TLS/mTLS, manage certificate trust and renewal requirements, and protect credentials in approved secrets stores. Participate in cybersecurity reviews, threat assessments, risk evaluations, and architecture approvals. Firewall, Routing, NAT, and DNS Define complete firewall rules, route tables, next hops, subnet associations, routing priorities, and approval records. Configure NAT policies and pools, capacity monitoring, controlled DNS forwarding, domain allowlists, and event logging. Review physical trunks and virtual networks to exclude unapproved VLANs, routes, and unintended transit paths. Monitoring and Operational Readiness Integrate WAF, firewall, APISIX, NGINX, Kubernetes, NAT, and DNS events with centralized logging or SIEM. Monitor availability, latency, error rates, rejected requests, firewall denies, DNS failures, NAT utilization, policy violations, and certificate expiry. Configure health checks, synchronized time, end-to-end correlation IDs, alerts, escalation paths, and support ownership. Maintain backup, recovery, troubleshooting, and operational runbooks for gateways, proxies, certificates, and policies. Implementation, Validation, and Governance Prepare deployment sequences and coordinate switching, KVM networking, firewalls, Kubernetes, and platform services. Execute positive and negative connectivity tests, security validation, failover tests, and control-bypass checks. Collect firewall, route, gateway, proxy, Kubernetes, NAT, DNS, and SIEM evidence for approval and handover. Maintain version-controlled configurations and comply with change, risk, configuration, and approval processes. Identify availability risks and recomm Employment Type Full-time

Ready to apply?

You are viewing this role on JobSphere AI. Applications are completed on the original employer / source website.

Apply Now

Opens the employer's site in a new tab

  • CompanySynkcode Fzco
  • LocationDubai, UAE
  • CategoryCybersecurity
  • SourceNaukrigulf
  • Listed1 month ago

Related Cybersecurity jobs

More Cybersecurity