About this role
*Role description:*(Please include a brief outline of the impact this role will have, including overview of customer industry and projects, access to cutting-edge technology etc.)
The Network Security Engineer (Firewall Security) is responsible for managing and securing large-scale, multi-vendor firewall environments. The role focuses on firewall administration, policy governance, network segmentation, VPN security, risk reduction, and ensuring effective network access controls across the enterprise. The engineer works closely with network, security, and application teams to maintain a secure and compliant network infrastructure
*Key responsibilities:*(Up to 10, Avoid repetition)
- Administer and manage enterprise firewall platforms, including:
- Palo Alto Networks
- Fortinet
- Cisco ASA / Firepower
- Check Point
- Design, implement, and support firewall security policies and rule sets.
- Perform firewall rule reviews, cleanup activities, and recertification exercises.
- Optimize firewall policies to improve security posture and operational efficiency.
- Manage and troubleshoot NAT configurations and VPN technologies.
- Implement and maintain network segmentation and micro-segmentation controls.
- Conduct risk assessments and drive firewall risk reduction initiatives.
- Support security incidents involving network and firewall technologies.
- Manage and monitor network access controls and security enforcement mechanisms.
- Collaborate with audit, compliance, and security teams to ensure adherence to organizational standards.
- Provide technical support for IDS, IPS, DDoS protection, and Secure Web Gateway solutions.
*Key skills/knowledge/experience:*(Up to 10, Avoid repetition)
Technical Skills
- Strong hands-on experience with:
- Palo Alto Networks Firewalls
- Fortinet Firewalls
- Cisco ASA / Firepower
- Check Point Firewalls
- Firewall architecture and policy administration.
- Network Address Translation (NAT).
- Site-to-Site and Remote Access VPN technologies.
- Network segmentation and micro-segmentation.
- Firewall rule analysis, recertification, and optimization.
- Intrusion Prevention Systems (IPS).
- Intrusion Detection Systems (IDS).
- DDoS protection technologies.
- Secure Web Gateway (SWG) solutions.
- Network Access Control (NAC).
- Network security monitoring and troubleshooting.
- Risk assessment and security governance.
Functional Skills
- Security policy management.
- Compliance and audit support.
- Incident investigation and resolution.
- Risk management and mitigation.
- Analytical and problem-solving skills.
- Stakeholder communication and collaboration
Person specification:**I.e., negotiating, client facing, communication, assertive, team leading/team member skills, supportive.
Additional Professional Competencies
- Strong stakeholder management and relationship-building skills across technical and executive audiences.
- Ability to influence and drive security improvements across infrastructure, cloud, engineering, and operational teams.
- Strong analytical approach to risk identification, remediation, and operational optimisation.
- Excellent written and verbal communication skills with the ability to present complex technical issues in a clear and concise manner.
- Demonstrated ability to balance security, operational resilience, regulatory obligations, and business requirements.
Additional Desirable Skills & Experience
- Experience implementing enterprise firewall governance programmes using AlgoSec or equivalent policy management platforms.
- Experience with Zero Trust Network Architecture (ZTNA), SASE, and Security Service Edge (SSE) technologies.
- Experience within large-scale financial services, banking, or other highly regulated environments.
- Knowledge of regulatory frameworks including PCI-DSS, ISO27001, NIST Cyber Security Framework, CIS Controls, and relevant financial industry regulations.
- Experience supporting network security transformation, cloud migration, and hybrid networking programmes.
- Familiarity with software-defined networking (SDN), network segmentation strategies, and modern secure connectivity solutions.
Professional Certifications (Desired)
- CISSP (Certified Information Systems Security Professional)
- CCNP Security / CCIE Security
- Palo Alto PCNSE
- Check Point CCSA / CCSE
- Azure Security Engineer Associate (AZ-500)
- AWS Security Specialty
- Certified Cloud Security Professional (CCSP)
- GIAC Security Certifications (GCIA, GCIH, GMON or equivalent)
About cyber security & digital forensics roles for ex-police
Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.
See all cyber security & digital forensics jobs in Manchester →Why this fits a police background
- Investigative casework
- Risk & threat assessment
- Working to legislation & regulation
- Security operations
What cyber security & digital forensics roles pay ex-police
Advertised UK ranges, editorial estimates reviewed July 2026
| Digital forensics analyst | £32,000–£45,000 |
| DFIR consultant | £45,000–£65,000 |
| Senior forensics / IR specialist | £60,000–£80,000 |
| Threat-intelligence specialist | £55,000–£80,000 |