Practice / DomainCyber Security – Telco Cloud & Network SecurityExperience Range5 – 12 YearsSupport Model24x7 Operations (Telco-grade SLA-driven environment)
Practice / DomainPractice / DomainPractice / Domain
Practice / DomainCyber Security – Telco Cloud & Network SecurityCyber Security – Telco Cloud & Network SecurityCyber Security – Telco Cloud & Network SecurityExperience RangeExperience RangeExperience Range
Experience Range5 – 12 Years5 – 12 Years5 – 12 YearsSupport ModelSupport ModelSupport Model
Support Model24x7 Operations (Telco-grade SLA-driven environment)24x7 Operations (Telco-grade SLA-driven environment)24x7 Operations (Telco-grade SLA-driven environment)Role SummaryRole SummaryRole Summary
Role SummaryThe Network Security Engineer is responsible for design, deployment, and operations of Telco-grade Virtual Firewalls (vFW) using Palo Alto technologies within Telco cloud (NFV/SDN) environments.The Network Security Engineer is responsible for design, deployment, and operations of Telco-grade Virtual Firewalls (vFW) using Palo Alto technologies within Telco cloud (NFV/SDN) environments.The Network Security Engineer is responsible for design, deployment, and operations of Telco-grade Virtual Firewalls (vFW) using Palo Alto technologies within Telco cloud (NFV/SDN) environments.
design, deployment, and operations of Telco-grade Virtual Firewalls (vFW) using Palo Alto technologiesTelco cloud (NFV/SDN) environmentsThis role ensures secure traffic segmentation, high availability, and scalable firewall deployments supporting carrier-grade networks, VNF architectures, and multi-tenant Telco environments.This role ensures secure traffic segmentation, high availability, and scalable firewall deployments supporting carrier-grade networks, VNF architectures, and multi-tenant Telco environments.This role ensures secure traffic segmentation, high availability, and scalable firewall deployments supporting carrier-grade networks, VNF architectures, and multi-tenant Telco environments.
secure traffic segmentation, high availability, and scalable firewall deploymentscarrier-grade networks, VNF architectures, and multi-tenant Telco environmentsKey ResponsibilitiesKey ResponsibilitiesKey Responsibilities
Key Responsibilities1. Telco Virtual Firewall (Palo Alto) Operations1. Telco Virtual Firewall (Palo Alto) Operations1. Telco Virtual Firewall (Palo Alto) Operations
1. Telco Virtual Firewall (Palo Alto) Operations- Deploy, configure, and manage Palo Alto Virtual Firewalls (VM-Series / CN-Series) in Telco cloud
Deploy, configure, and manage Palo Alto Virtual Firewalls (VM-Series / CN-Series) in Telco cloudDeploy, configure, and manage Palo Alto Virtual Firewalls (VM-Series / CN-Series) in Telco cloudDeploy, configure, and manage Palo Alto Virtual Firewalls (VM-Series / CN-Series) in Telco cloudDeploy, configure, and manage Palo Alto Virtual Firewalls (VM-Series / CN-Series) in Telco cloud
Palo Alto Virtual Firewalls (VM-Series / CN-Series)- Configure: Security policies (App-ID, URL filtering, NAT, segmentation)Threat prevention (IPS, Anti-malware, WildFire)
Configure:Configure:Configure:Configure:
- Security policies (App-ID, URL filtering, NAT, segmentation)
Security policies (App-ID, URL filtering, NAT, segmentation)Security policies (App-ID, URL filtering, NAT, segmentation)Security policies (App-ID, URL filtering, NAT, segmentation)Security policies (App-ID, URL filtering, NAT, segmentation)
- Threat prevention (IPS, Anti-malware, WildFire)
Threat prevention (IPS, Anti-malware, WildFire)Threat prevention (IPS, Anti-malware, WildFire)Threat prevention (IPS, Anti-malware, WildFire)Threat prevention (IPS, Anti-malware, WildFire)
- Perform log analysis, traffic inspection, and threat detection
Perform log analysis, traffic inspection, and threat detectionPerform log analysis, traffic inspection, and threat detectionPerform log analysis, traffic inspection, and threat detectionPerform log analysis, traffic inspection, and threat detection
log analysis, traffic inspection, and threat detection- Ensure policy enforcement across Telco network segments and trust zones
Ensure policy enforcement across Telco network segments and trust zonesEnsure policy enforcement across Telco network segments and trust zonesEnsure policy enforcement across Telco network segments and trust zonesEnsure policy enforcement across Telco network segments and trust zones
Telco network segments and trust zones2. Telco Cloud / NFV Security Implementation2. Telco Cloud / NFV Security Implementation2. Telco Cloud / NFV Security Implementation
2. Telco Cloud / NFV Security Implementation- Deploy firewalls as Virtual Network Functions (VNFs) in Telco cloud environments
Deploy firewalls as Virtual Network Functions (VNFs) in Telco cloud environmentsDeploy firewalls as Virtual Network Functions (VNFs) in Telco cloud environmentsDeploy firewalls as Virtual Network Functions (VNFs) in Telco cloud environmentsDeploy firewalls as Virtual Network Functions (VNFs) in Telco cloud environments
Virtual Network Functions (VNFs)- Integrate with: NFV orchestrators / SDN controllersTelco cloud platforms (OpenStack / Kubernetes)
Integrate with:Integrate with:Integrate with:Integrate with:
- NFV orchestrators / SDN controllers
NFV orchestrators / SDN controllersNFV orchestrators / SDN controllersNFV orchestrators / SDN controllersNFV orchestrators / SDN controllers
- Telco cloud platforms (OpenStack / Kubernetes)
Telco cloud platforms (OpenStack / Kubernetes)Telco cloud platforms (OpenStack / Kubernetes)Telco cloud platforms (OpenStack / Kubernetes)Telco cloud platforms (OpenStack / Kubernetes)
- Ensure: Secure communication between VNFsControlled access using IP/Port/Application-level filtering
Ensure:Ensure:Ensure:Ensure:
- Secure communication between VNFs
Secure communication between VNFsSecure communication between VNFsSecure communication between VNFsSecure communication between VNFs
- Controlled access using IP/Port/Application-level filtering
Controlled access using IP/Port/Application-level filteringControlled access using IP/Port/Application-level filteringControlled access using IP/Port/Application-level filteringControlled access using IP/Port/Application-level filtering3. Traffic Engineering & Connectivity Security3. Traffic Engineering & Connectivity Security3. Traffic Engineering & Connectivity Security
3. Traffic Engineering & Connectivity Security- Configure and manage: Routing protocols (BGP, static routing)VPNs (IPSec, site-to-site connectivity)
Configure and manage:Configure and manage:Configure and manage:Configure and manage:
- Routing protocols (BGP, static routing)
Routing protocols (BGP, static routing)Routing protocols (BGP, static routing)Routing protocols (BGP, static routing)Routing protocols (BGP, static routing)
- VPNs (IPSec, site-to-site connectivity)
VPNs (IPSec, site-to-site connectivity)VPNs (IPSec, site-to-site connectivity)VPNs (IPSec, site-to-site connectivity)VPNs (IPSec, site-to-site connectivity)
- Perform deep packet inspection (DPI) and traffic flow analysis
Perform deep packet inspection (DPI) and traffic flow analysisPerform deep packet inspection (DPI) and traffic flow analysisPerform deep packet inspection (DPI) and traffic flow analysisPerform deep packet inspection (DPI) and traffic flow analysis
deep packet inspection (DPI)- Secure north-south and east-west traffic flows in Telco networks
Secure north-south and east-west traffic flows in Telco networksSecure north-south and east-west traffic flows in Telco networksSecure north-south and east-west traffic flows in Telco networksSecure north-south and east-west traffic flows in Telco networks
north-south and east-west traffic flows4. High Availability & Carrier-Grade Design4. High Availability & Carrier-Grade Design4. High Availability & Carrier-Grade Design
4. High Availability & Carrier-Grade Design- Implement HA (active-active / active-passive) setups for virtual firewalls
Implement HA (active-active / active-passive) setups for virtual firewallsImplement HA (active-active / active-passive) setups for virtual firewallsImplement HA (active-active / active-passive) setups for virtual firewallsImplement HA (active-active / active-passive) setups for virtual firewalls
HA (active-active / active-passive) setups for virtual firewalls- Support: Geo-redundant deploymentsFault-tolerant designs aligned to Telco standards
Support:Support:Support:Support:
- Geo-redundant deployments
Geo-redundant deploymentsGeo-redundant deploymentsGeo-redundant deploymentsGeo-redundant deployments
- Fault-tolerant designs aligned to Telco standards
Fault-tolerant designs aligned to Telco standardsFault-tolerant designs aligned to Telco standardsFault-tolerant designs aligned to Telco standardsFault-tolerant designs aligned to Telco standards
- Ensure no service impact from VNF/node/site failures
Ensure no service impact from VNF/node/site failuresEnsure no service impact from VNF/node/site failuresEnsure no service impact from VNF/node/site failuresEnsure no service impact from VNF/node/site failures
no service impact from VNF/node/site failures5. Monitoring, Incident & Change Management5. Monitoring, Incident & Change Management5. Monitoring, Incident & Change Management
5. Monitoring, Incident & Change Management- Monitor firewall health, logs, and alerts
Monitor firewall health, logs, and alertsMonitor firewall health, logs, and alertsMonitor firewall health, logs, and alertsMonitor firewall health, logs, and alerts
- Perform L2/L3 troubleshooting for high-severity incidents
Perform L2/L3 troubleshooting for high-severity incidentsPerform L2/L3 troubleshooting for high-severity incidentsPerform L2/L3 troubleshooting for high-severity incidentsPerform L2/L3 troubleshooting for high-severity incidents
L2/L3 troubleshooting for high-severity incidents- Execute change, incident, and problem management (ITIL aligned)
Execute change, incident, and problem management (ITIL aligned)Execute change, incident, and problem management (ITIL aligned)Execute change, incident, and problem management (ITIL aligned)Execute change, incident, and problem management (ITIL aligned)
change, incident, and problem management (ITIL aligned)- Collaborate with NOC, SOC, and Telco operations teams
Collaborate with NOC, SOC, and Telco operations teamsCollaborate with NOC, SOC, and Telco operations teamsCollaborate with NOC, SOC, and Telco operations teamsCollaborate with NOC, SOC, and Telco operations teams
NOC, SOC, and Telco operations teams6. Governance, Compliance & Security Assurance6. Governance, Compliance & Security Assurance6. Governance, Compliance & Security Assurance
6. Governance, Compliance & Security Assurance- Ensure firewall configurations meet: Telco security standards (ETSI / NFV guidelines)Enterprise compliance requirements
Ensure firewall configurations meet:Ensure firewall configurations meet:Ensure firewall configurations meet:Ensure firewall configurations meet:
- Telco security standards (ETSI / NFV guidelines)
Telco security standards (ETSI / NFV guidelines)Telco security standards (ETSI / NFV guidelines)Telco security standards (ETSI / NFV guidelines)Telco security standards (ETSI / NFV guidelines)
- Enterprise compliance requirements
Enterprise compliance requirementsEnterprise compliance requirementsEnterprise compliance requirementsEnterprise compliance requirements
- Support audits with logs, reports, and evidence
Support audits with logs, reports, and evidenceSupport audits with logs, reports, and evidenceSupport audits with logs, reports, and evidenceSupport audits with logs, reports, and evidence
- Perform policy optimization, cleanup, and compliance validation
Perform policy optimization, cleanup, and compliance validationPerform policy optimization, cleanup, and compliance validationPerform policy optimization, cleanup, and compliance validationPerform policy optimization, cleanup, and compliance validation
policy optimization, cleanup, and compliance validationMandatory SkillsMandatory SkillsMandatory Skills
Mandatory SkillsCore Technical SkillsCore Technical SkillsCore Technical Skills
Core Technical Skills- Hands-on experience with: Palo Alto Virtual Firewalls (VM-Series / CN-Series)Panorama for centralized firewall management
Hands-on experience with:Hands-on experience with:Hands-on experience with:Hands-on experience with:
- Palo Alto Virtual Firewalls (VM-Series / CN-Series)
Palo Alto Virtual Firewalls (VM-Series / CN-Series)Palo Alto Virtual Firewalls (VM-Series / CN-Series)Palo Alto Virtual Firewalls (VM-Series / CN-Series)Palo Alto Virtual Firewalls (VM-Series / CN-Series)
Palo Alto Virtual Firewalls (VM-Series / CN-Series)- Panorama for centralized firewall management
Panorama for centralized firewall managementPanorama for centralized firewall managementPanorama for centralized firewall managementPanorama for centralized firewall management
Panorama for centralized firewall management- Strong knowledge of: NGFW features (App-ID, User-ID, Content-ID, IPS)Firewall policy design and segmentation
Strong knowledge of:Strong knowledge of:Strong knowledge of:Strong knowledge of:
- NGFW features (App-ID, User-ID, Content-ID, IPS)
NGFW features (App-ID, User-ID, Content-ID, IPS)NGFW features (App-ID, User-ID, Content-ID, IPS)NGFW features (App-ID, User-ID, Content-ID, IPS)NGFW features (App-ID, User-ID, Content-ID, IPS)
- Firewall policy design and segmentation
Firewall policy design and segmentationFirewall policy design and segmentationFirewall policy design and segmentationFirewall policy design and segmentationTelco / Cloud ExposureTelco / Cloud ExposureTelco / Cloud Exposure
Telco / Cloud Exposure- Experience in: Telco cloud / NFV environmentsVirtual firewall deployments at scale
Experience in:Experience in:Experience in:Experience in:
- Telco cloud / NFV environments
Telco cloud / NFV environmentsTelco cloud / NFV environmentsTelco cloud / NFV environmentsTelco cloud / NFV environments
Telco cloud / NFV environments- Virtual firewall deployments at scale
Virtual firewall deployments at scaleVirtual firewall deployments at scaleVirtual firewall deployments at scaleVirtual firewall deployments at scale
- Understanding of: VNF lifecycle and orchestrationSDN-based network security
Understanding of:Understanding of:Understanding of:Understanding of:
- VNF lifecycle and orchestration
VNF lifecycle and orchestrationVNF lifecycle and orchestrationVNF lifecycle and orchestrationVNF lifecycle and orchestration
- SDN-based network security
SDN-based network securitySDN-based network securitySDN-based network securitySDN-based network securityNetworking FundamentalsNetworking FundamentalsNetworking Fundamentals
Networking Fundamentals- Strong understanding of: TCP/IP, BGP, routing, NATNetwork segmentation and Zero Trust
Strong understanding of:Strong understanding of:Strong understanding of:Strong understanding of:
- TCP/IP, BGP, routing, NAT
TCP/IP, BGP, routing, NATTCP/IP, BGP, routing, NATTCP/IP, BGP, routing, NATTCP/IP, BGP, routing, NAT
- Network segmentation and Zero Trust
Network segmentation and Zero TrustNetwork segmentation and Zero TrustNetwork segmentation and Zero TrustNetwork segmentation and Zero Trust
- Experience with: VPNs (IPSec, SSL VPN)Traffic analysis and debugging
Experience with:Experience with:Experience with:Experience with:
VPNs (IPSec, SSL VPN)VPNs (IPSec, SSL VPN)VPNs (IPSec, SSL VPN)VPNs (IPSec, SSL VPN)
- Traffic analysis and debugging
Traffic analysis and debuggingTraffic analysis and debuggingTraffic analysis and debuggingTraffic analysis and debuggingDesired / Good-to-Have SkillsDesired / Good-to-Have SkillsDesired / Good-to-Have Skills
Desired / Good-to-Have Skills- Experience with: Multi-vendor Telco firewallsKubernetes / container security (CN-Series)
Experience with:Experience with:Experience with:Experience with:
- Multi-vendor Telco firewalls
Multi-vendor Telco firewallsMulti-vendor Telco firewallsMulti-vendor Telco firewallsMulti-vendor Telco firewalls
- Kubernetes / container security (CN-Series)
Kubernetes / container security (CN-Series)Kubernetes / container security (CN-Series)Kubernetes / container security (CN-Series)Kubernetes / container security (CN-Series)
- Automation: Python / Ansible / REST APIs
Automation:Automation:Automation:Automation:
- Python / Ansible / REST APIs
Python / Ansible / REST APIsPython / Ansible / REST APIsPython / Ansible / REST APIsPython / Ansible / REST APIs
- Exposure to: 5G / LTE network securityCloud-native security controls
Exposure to:Exposure to:Exposure to:Exposure to:
- 5G / LTE network security
5G / LTE network security5G / LTE network security5G / LTE network security5G / LTE network security
- Cloud-native security controls
Cloud-native security controlsCloud-native security controlsCloud-native security controlsCloud-native security controlsCertifications (Preferred)Certifications (Preferred)Certifications (Preferred)
Certifications (Preferred)Palo Alto:Palo Alto:Palo Alto:Palo Alto:
PCNSE / PCNSAPCNSE / PCNSAPCNSE / PCNSAPCNSE / PCNSA
- Network / Telco: CCNP / CCIE (Security or Service Provider)
Network / Telco:Network / Telco:Network / Telco:Network / Telco:
- CCNP / CCIE (Security or Service Provider)
CCNP / CCIE (Security or Service Provider)CCNP / CCIE (Security or Service Provider)CCNP / CCIE (Security or Service Provider)CCNP / CCIE (Security or Service Provider)
- Cloud / Telco: NFV / Telco cloud certifications (optional)
Cloud / Telco:Cloud / Telco:Cloud / Telco:Cloud / Telco:
- NFV / Telco cloud certifications (optional)
NFV / Telco cloud certifications (optional)NFV / Telco cloud certifications (optional)NFV / Telco cloud certifications (optional)NFV / Telco cloud certifications (optional)Soft SkillsSoft SkillsSoft Skills
Soft Skills- Strong troubleshooting and analytical skills
Strong troubleshooting and analytical skillsStrong troubleshooting and analytical skillsStrong troubleshooting and analytical skillsStrong troubleshooting and analytical skills
- Ability to operate in high pressure, carrier-grade environments
Ability to operate in high pressure, carrier-grade environmentsAbility to operate in high pressure, carrier-grade environmentsAbility to operate in high pressure, carrier-grade environmentsAbility to operate in high pressure, carrier-grade environments
high pressure, carrier-grade environments- Effective collaboration across global teams (NOC, SOC, Engineering)
Effective collaboration across global teams (NOC, SOC, Engineering)Effective collaboration across global teams (NOC, SOC, Engineering)Effective collaboration across global teams (NOC, SOC, Engineering)Effective collaboration across global teams (NOC, SOC, Engineering)
- Strong communication for client and stakeholder engagement
Strong communication for client and stakeholder engagementStrong communication for client and stakeholder engagementStrong communication for client and stakeholder engagementStrong communication for client and stakeholder engagementKey Outcomes / Success MetricsKey Outcomes / Success MetricsKey Outcomes / Success Metrics
Key Outcomes / Success Metrics- High availability of Telco firewall services (carrier-grade SLAs)
High availability of Telco firewall services (carrier-grade SLAs)High availability of Telco firewall services (carrier-grade SLAs)High availability of Telco firewall services (carrier-grade SLAs)High availability of Telco firewall services (carrier-grade SLAs)
- Secure segmentation and traffic isolation across VNFs
Secure segmentation and traffic isolation across VNFsSecure segmentation and traffic isolation across VNFsSecure segmentation and traffic isolation across VNFsSecure segmentation and traffic isolation across VNFs
- Reduction in security incidents and faster RCA
Reduction in security incidents and faster RCAReduction in security incidents and faster RCAReduction in security incidents and faster RCAReduction in security incidents and faster RCA
- Improved policy compliance and audit readiness
Improved policy compliance and audit readinessImproved policy compliance and audit readinessImproved policy compliance and audit readinessImproved policy compliance and audit readinessAbout Infosys Infosys is a global leader in next-generation digital services and consulting. We enable clients in 59 countries to navigate their digital transformation.With over four decades of experience in managing the systems and workings of global enterprises, we expertly steer clients, in 59 countries, as they navigate their digital transformation powered by cloud and AI. We enable them with an AI-first core, empower the business with agile digital at scale and drive continuous improvement with always-on learning through the transfer of digital skills, expertise, and ideas from our innovation ecosystem. We are deeply committed to being a well-governed, environmentally sustainable organization where diverse talent thrives in an inclusive workplace.
About Infosys