1,059,896open jobs
62,082companies
176,030added this week
Browse all
Salary
≈ $108k – $212k per year (Estimated)
Location
In office (Atlanta)
Seniority
Senior · 5+ years exp

Confirmed on the employer's own hiring board on Oct 2, 2026. First seen by Alion on Oct 1, 2026.

Overview
Company
Impact
Profile match
Newell Brands is a consumer products company headquartered in Atlanta, Georgia, whose portfolio includes Rubbermaid, Sharpie, Coleman, Graco, Oster, Yankee Candle, Crock-Pot, Paper Mate, Elmer's, Contigo and Calphalon. The company traces its history to the Newell Manufacturing Company founded by Edgar Newell in 1903, is listed on Nasdaq, and reports about 24,000 employees worldwide with manufacturing and distribution sites in the US, Mexico, Brazil and Poland. It hires Yankee Candle retail and seasonal sales associates, manufacturing operators, distribution center staff, maintenance technicians, quality and product development engineers, and finance and sales operations staff.

Job ID: 18359

Alternate Locations:

Newell Brands is a leading consumer products company with a portfolio of iconic brands like Graco®, Coleman®, Oster®, Rubbermaid®, Sharpie® and Yankee Candle® - and 24,000 talented teammates around the world. Our culture is built on values in action: Integrity, Teamwork, Passion for Winning, Ownership, and Leadership. We work together to win, grow, and make a real impact-supported by a high-performing, inclusive, and collaborative environment where you can be your best, every day.

Job Summary:

The Senior Network Security Engineer provides dedicated engineering capacity to accelerate Newell Brands network segmentation buildout and materially reduce lateral movement risk across the enterprise. This role is the hands-on technical lead for network segmentation architecture and enforcement of network security controls across IT, OT, and cloud environments within Newell’s global multi-site footprint. The engineer does not just design; they design, validate, and partner across infrastructure and business stakeholders to drive adoption of controls that reduce real-world attack surface.

Key Responsibilities:

  • Own and drive execution of the network segmentation roadmap, translating architecture designs into firewall rule requirements, validated post-implementation with the network team
  • Architect and support network zone boundaries, trust relationships, and inter-zone communication rules aligned to Zero Trust principles
  • Drive the strategic shift from port/protocol-based to App-ID and User-ID driven segmentation, integrating identity-based access controls across sites
  • Lead microsegmentation design for high-risk environments including manufacturing OT, data center, cloud connected, and retail POS segments
  • Architect and specify cloud network security controls - network segmentation, cloud firewall policy, and secure cloud-to-on-prem connectivity
  • Partner with the OT Security Specialist to design and support IT/OT demilitarized zone architecture and manage converged traffic flow design safely
  • Conduct and document network architecture reviews to identify trust boundary gaps, flat network zones, and legacy segment exposure
  • Specify and validate firewall rules against segmentation design and security baselines across IT and OT environments
  • Drive firewall rule lifecycle reviews: review and tune rule sets, identify unused or overly permissive rules, and coordinate remediation with the network team
  • Review and approve firewall change requests for security impact, and verify post-implementation rule accuracy
  • Build and maintain network security engineering runbooks and configuration baselines for the Security Engineering team
  • Leverage AI-assisted tools and automation to accelerate firewall policy analysis, segmentation validation, and engineering documentation

Required Qualifications:

  • 5+ years of hands-on network security engineering experience: firewall policy, segmentation design, and enterprise network architecture • Demonstrated experience designing and validating network segmentation in a complex, multi-site environment
  • Working knowledge of Zero Trust Network Access (ZTNA) concepts and practical application to enterprise segmentation
  • Working knowledge of cloud network security controls and architecture in at least one major cloud platform (Azure, AWS, or GCP) • Familiarity with enterprise firewall policy management and rule lifecycle tooling (e.g., policy orchestration and change management platforms)
  • Understanding of OT/ICS network environments and IT/OT segmentation best practices (Purdue Model, IEC 62443)
  • Strong documentation skills: ability to produce architecture diagrams, configuration runbooks, and network design documentation
  • Bachelor's degree in Computer Science, Network Engineering, Information Security, or equivalent practical experience

Preferred Qualifications:

  • Experience with SASE or cloud-delivered network security platforms
  • Demonstrated experience securing hybrid cloud environments, including cloud-to-on-prem network segmentation and enforcement (Azure, AWS, or GCP)
  • Cloud security certifications (e.g., AZ-500, AWS Security Specialty, CCSP)
  • Experience in a manufacturing, consumer goods, or retail environment with distributed site and OT/IT network challenges
  • Experience with SD-WAN architecture and security policy enforcement across distributed sites
  • Industry certifications in network security (e.g., PCNSE, CCNP Security, GIAC GAWN, or equivalent)

Newell Brands (NASDAQ: NWL) is a leading global consumer goods company with a strong portfolio of well-known brands, including Rubbermaid, Sharpie, Graco, Coleman, Rubbermaid Commercial Products, Yankee Candle, Paper Mate, FoodSaver, Dymo, EXPO, Elmer’s, Oster, NUK, Spontex and Campingaz. We are focused on delighting consumers by lighting up everyday moments. Newell Brands and its subsidiaries are Equal Opportunity Employers and comply with applicable employment laws. EOE/M/F/Vet/Disabled are encouraged to apply.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,059,896 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Atlanta
$159k – $179k per year • In office • Full-Time • 3+ years exp • Bachelor's Degree • Houston
Cybersecurity
Microsoft Defender for Cloud
Microsoft Entra ID
SIEM
Apply
≈ $115k – $209k per year (Estimated) • Remote (United States) • Full-Time • 8+ years exp
Python
DevOps
Splunk
Azure
AWS
Cybersecurity
Microsoft Sentinel
MISP
MITRE ATT&CK
PCI DSS
Diamond Model
Recorded Future
SIEM
Apply
≈ $106k – $208k per year (Estimated) • Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • Little Rock
DevOps
Splunk
GCP
Azure
CI/CD
AWS
Kubernetes
IAM
Cybersecurity
Microsoft Sentinel
NIST CSF
SIEM
Apply
≈ $148k – $263k per year (Estimated) • Remote (United States) • 10+ years exp • Bachelor's Degree
DevOps
Azure
AWS
Cybersecurity
Zero Trust
Apply
≈ $108k – $211k per year (Estimated) • In office • Full-Time • 8+ years exp • Bachelor's Degree • Tampa
Cybersecurity
ISO 27001
PCI DSS
GDPR
HIPAA
Management
ITIL
Apply
≈ $22k – $44k per year (Estimated) • In office • Bengaluru
Python
Rust
SQL
C#
DevOps
GCP
Azure
CI/CD
AWS
Analytics
ETL/ELT
Apply
In office • Contractor • Bengaluru
DevOps
Terraform
Ansible
GCP
Azure
AWS
Kubernetes
DNS
BGP
Apply
≈ $70k – $181k per year (Estimated) • In office • Full-Time • Bachelor's Degree • London
DevOps
GCP
Azure
AWS
Apply
In office • Full-Time • Tokyo
Python
JavaScript
Ruby
PowerShell
Node JS
DevOps
Terraform
Ansible
Chef
AWS
IAM
Cybersecurity
PCI DSS
Zero Trust
SIEM
Apply
In office • Full-Time • 4+ years exp • Bachelor's Degree • Bengaluru
Python
JavaScript
TypeScript
SQL
Python
Flask
Django
Databases
PostgreSQL
DynamoDB
Amazon Aurora
Frontend
Zustand
Redux
React.js
Mobile
State Management
DevOps
Terraform
GitHub Actions
AWS CDK
CI/CD
Jenkins
Git
AWS
Docker
AWS Lambda
Amazon EC2
GitHub
Amazon S3
API Gateway
Apply
≈ $105k – $207k per year (Estimated) • In office • 6+ years exp • Atlanta
DevOps
Azure
Cybersecurity
MITRE ATT&CK
Cyber Kill Chain
Diamond Model
DLP
Apply
$136k – $187k per year • In office • 5+ years exp • Bachelor's Degree • Atlanta
DevOps
Terraform
GCP
Azure
Windows Server
AWS
Bicep
IAM
Cybersecurity
CyberArk
Microsoft Entra ID
Active Directory
Apply
$136k – $187k per year • In office • Atlanta
DevOps
Azure
CI/CD
IAM
Cybersecurity
Okta
CyberArk
Microsoft Entra ID
Ping Identity
SIEM
Apply
$136k – $187k per year • In office • 5+ years exp • Atlanta
Python
PowerShell
AI/ML
Model Context Protocol
AI Agents
LLM
DevOps
Terraform
GCP
Azure
AWS
Platform Engineering
IAM
Cybersecurity
HashiCorp Vault
Zero Trust
Least Privilege
Cryptography
Vault
Apply
≈ $106k – $208k per year (Estimated) • In office • 10+ years exp • Bachelor's Degree • Atlanta
Python
JavaScript
PowerShell
Node JS
Node JS
Commander.js
DevOps
Azure
Cybersecurity
Cortex XSOAR
SIEM
Apply
$108k – $162k per year • Equity • In office • Full-Time • 2+ years exp • Bachelor's Degree • Atlanta
Java
Scala
AI/ML
Recommender Systems
Machine Learning
DevOps
Git
Management
Agile
Apply
$48k per year • In office • Atlanta
AI/ML
Supervision
Analytics
Microsoft Excel
Apply
≈ $38k – $89k per year (Estimated) • In office • PhD • Atlanta
Apply
$68k – $90k per year • In office • 7+ years exp • High School Diploma • Atlanta
Apply
≈ $81k – $175k per year (Estimated) • In office • Full-Time • Atlanta
Apply
See all jobs
This is one of many
1,059,896 more open roles from verified company boards, updated every day.