Wallex is a FinTech company providing a secure cryptocurrency exchange platform and digital asset payment solutions.
With a vision to become a leading global FinTech enterprise, Wallex is recognized as one of the largest cryptocurrency exchange platforms in Iran, supporting the online trading of over 130 cryptocurrencies.
We are looking for a skilled and motivated Network Security Engineer to join our Infrastructure team.
This is a hands-on engineering and operational role focused on the design, implementation, operation, and continuous improvement of our network security infrastructure. You will work with enterprise-grade network and security technologies to protect critical infrastructure and services while ensuring secure, reliable, and scalable connectivity across the organization.
The role requires strong hands-on experience with network security, firewalls, routing and switching, network segmentation, secure connectivity, monitoring, and troubleshooting. You will collaborate closely with Infrastructure, DevOps, Security, and other engineering teams to maintain and continuously improve our network security posture.
Responsibilities:
- Design, implement, operate, and maintain enterprise network security infrastructure.
- Configure, manage, troubleshoot, and optimize firewalls and network security policies.
- Design and implement network segmentation and access-control policies based on security requirements and best practices.
- Configure and troubleshoot NAT, ACLs, routing, Site-to-Site and Remote Access VPNs, and secure network connectivity.
- Configure and maintain security controls such as IPS/IDS, application control, traffic inspection, and threat-prevention policies.
- Perform security hardening and periodic configuration reviews of network and security devices.
- Troubleshoot complex network and security issues across Layer 2 through Layer 7.
- Analyze network traffic, packet captures, firewall logs, and traffic flows to identify connectivity issues, misconfigurations, anomalies, and potential security threats.
- Monitor network security infrastructure, traffic, logs, availability, and performance using monitoring and logging platforms.
- Participate in network and security incident response, root cause analysis, and preventive action planning.
- Plan and execute network security changes, upgrades, migrations, and maintenance activities following established change-management practices.
- Collaborate with Infrastructure, DevOps, Security, and other engineering teams to design and implement secure connectivity and network architectures.
- Maintain accurate technical documentation, including network and security diagrams, firewall policies, configurations, operational procedures, and change records.
- Regularly review existing security policies and configurations to identify unnecessary access, misconfigurations, and opportunities for improvement.
- Evaluate and test new network security technologies and solutions.
- Contribute to the automation of network and security operations, configuration management, and repetitive operational tasks.
- Contribute to improving the availability, scalability, resilience, and security of network infrastructure.
Requirements:
- Minimum 0 years of relevant hands-on experience in Network Security or Network Engineering.
- Strong understanding of TCP/IP and Layer 2/Layer 3 networking fundamentals.
- Strong understanding of enterprise routing and switching technologies, including BGP, OSPF, VLAN, STP/RSTP, LACP, NAT, and ACL.
- Solid understanding of datacenter networking concepts, including VXLAN, EVPN, and Overlay/Underlay architectures.
- Hands-on experience with Cisco Catalyst and Cisco Nexus switches.
- Strong hands-on experience with enterprise Next-Generation Firewalls (NGFW), including secure policy design, traffic inspection, VPN technologies, high availability, threat prevention, logging, and advanced troubleshooting.
- Strong understanding of network security principles, including network segmentation, least privilege, access control, secure network architecture, firewall policy design, network device hardening, IDS/IPS, and VPN security.
- Strong troubleshooting skills across Layer 2 through Layer 7, with the ability to diagnose complex connectivity, routing, performance, and security issues.
- Hands-on experience with packet capture and traffic analysis and the ability to analyze network flows and firewall logs.
- Hands-on experience with infrastructure monitoring, alerting, and logging platforms.
- Basic operational knowledge of Linux and common network troubleshooting tools.
- Good understanding of High Availability and redundancy concepts in network and security infrastructure.
- Strong problem-solving and analytical skills, particularly in production environments.
- Strong documentation and change-management practices.
- Strong communication and collaboration skills.
Nice to Have:
- Experience working in high-availability and mission-critical environments.
- Familiarity with Web Application Firewall (WAF) technologies, OWASP Top 10, and common Layer 7 security threats.
- Familiarity with AAA and Network Access Control (NAC) technologies and concepts such as RADIUS, TACACS+, and Cisco ISE.
- Familiarity with SIEM and centralized log-management platforms for security monitoring and incident investigation.
- Familiarity with SDN and SD-WAN concepts and architectures.
- Familiarity with backup, recovery, and Disaster Recovery strategies for network and security infrastructure.
- Familiarity with Infrastructure as Code (IaC), network automation, and configuration management concepts.
- Experience with automation technologies such as Python, Ansible, and APIs.
- Familiarity with Git and version-controlled infrastructure workflows.
- Familiarity with capacity planning and infrastructure scalability concepts.
- Familiarity with Kubernetes networking and network security concepts, including CNI, Ingress, NetworkPolicy, and service communication.
- Relevant networking or security certifications such as CCNP Enterprise, CCNP Security, or Fortinet certifications.
We build, not watch — This is where you belong!