368,530open jobs
9,432companies
50,439added this week
Browse all
Location
In office
Seniority
Senior · 8+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Paramount Computer Systems is a Dubai-based cybersecurity solutions provider that specializes in safeguarding critical digital infrastructure across the Middle East and GCC region. Established in 1992, the company offers an end-to-end service suite encompassing governance, risk, and compliance (GRC), network security, identity management, and managed threat protection. Serving major enterprises in banking, government, energy, and telecommunications, it helps organizations build resilient digital environments through advanced security technology and strategic consulting.
Position TitleSenior Network Security Engineer / Consultant - Check Point FirewallFunctionNetwork Security Delivery / Professional ServicesReports ToProject Manager / Practice Lead - Network SecurityLocationWork location : Dubai, UAE - Travel to other region as project required. Engagement TypeFull TimeExperience Required8+ years in network security, with a minimum of 5 years hands-on Check Point deliveryPositions Open2

1. Role Overview

We are seeking an accomplished Check Point firewall specialist to join the delivery team for a large-scale, multi-vendor security transformation programme. The engagement involves migrating an existing mixed firewall estatecomprising Juniper, Huawei and Cisco platforms onto a new Check Point Quantum Force high-end appliance estate across different locations, deployed as high-availability clusters and managed through a Multi-Domain Smart-1 architecture.

The successful candidate will take a lead technical role across the full delivery lifecycle: source estate discovery and policy audit, target architecture and low-level design, policy conversion and rationalization, staging and commissioning, migration cutover under strict change control, and post-implementation support. This is a hands-on senior position requiring both design authority and the operational discipline to execute cutovers on a live carrier network where the tolerance for service impact is effectively zero.

2. Key Responsibilities

Design & Architecture

  • Produce high-level and low-level designs for Check Point gateway clusters, covering ClusterXL high-availability design, interface and bonding architecture, VLAN and addressing plans, and routing integration with the carrier core.
  • Design the multi-domain management and logging architecture, including domain structure, global policy layers, administrator models, log retention and event correlation.
  • Define the target security policy architecture ordered and inline policy layers, object standards, NAT design and VPN topologies and establish the standards that operational teams will work to thereafter.
  • Design Threat Prevention and sandboxing profiles, including IPS, Anti-Virus and Anti-Bot baselines and a staged detect-to-prevent rollout strategy appropriate to high-throughput carrier traffic.
  • Develop migration architecture: parallel installation approach, traffic-swing methodology, soak criteria and technically credible rollback design.

Implementation & Migration

  • Lead policy conversion from Juniper, Huawei and Cisco source platforms using Check Point SmartMove and scripted or manual conversion methodologies, followed by manual review, rule rationalization and object normalization.
  • Build and commission high-end Check Point appliances: OS installation and hardening, cluster formation, interface and bonding configuration, SIC establishment and onboarding to the correct management domain.
  • Configure and validate high-speed interfaces in line cards, including optics validation and link aggregation at scale.
  • Build the Smart-1 management and logging infrastructure, including Multi-Domain Server deployment, SmartEvent configuration and SIEM log forwarding.
  • Author detailed cutover method statements and execute migrations within approved change windows, including on-site presence, live traffic verification and rollback execution where triggers are met.

Testing, Support & Handover

  • Develop and execute acceptance test plans covering high-availability failover, routing convergence, policy parity against the legacy estate, throughput validation and Threat Prevention behaviour.
  • Provide post-migration hypercare support: incident diagnosis, policy and Threat Prevention tuning, performance optimisation and vendor TAC escalation management.
  • Perform advanced troubleshooting using packet-level and kernel-level diagnostics, cluster state analysis and acceleration path investigation.
  • Produce as-built documentation and operational runbooks, and deliver structured knowledge transfer to customer network operations and security operations teams.

Programme & Stakeholder Engagement

  • Represent the delivery organisation in customer design reviews, technical workshops, change advisory boards and acceptance sign-off sessions.
  • Work within a phased, wave-based rollout model, meeting entry and exit gate criteria per wave and maintaining delivery quality across parallel site activity.
  • Mentor junior engineers and contribute to the internal Check Point practice through reusable design patterns, conversion tooling and lessons learned.

3. Essential Skills & Experience

  • Minimum 5 years of hands-on experience designing, implementing and supporting Check Point security gateways, including at least two enterprise or carrier-scale deployments or migrations.
  • Deep expertise across the Check Point portfolio: Gaia OS, SmartConsole, Security Management and Multi-Domain Management (MDS/MLM), ClusterXL, Management API, SecureXL and CoreXL acceleration.
  • Demonstrable experience with high-end Check Point appliances and high-throughput deploymentsmulti-hundred-gigabit or terabit-class environments, high-density line cards and performance tuning under sustained load.
  • Proven policy migration experience from third-party firewall vendors like Cisco, Juniper or ScreenOS, Huawei, Fortinet including practical use of SmartMove and post-conversion validation.
  • Strong command of Threat Prevention blades and sandboxing: IPS, Anti-Virus, Anti-Bot, Threat Emulation and Threat Extraction, including profile design and false-positive management.
  • Solid networking foundation: TCP/IP, routing protocols (OSPF, BGP), VLANs and trunking, link aggregation, NAT, IPSec VPN and high-availability design principles.
  • Advanced troubleshooting capability using fw monitor, tcpdump, kernel debug, cpview, cphaprob and related diagnostic tooling.
  • Experience executing changes on production networks under formal change management, including method statement authorship, risk assessment and rollback planning.
  • Strong documentation and communication skills, with the ability to present and defend technical designs to senior customer stakeholders.

4. Certification Requirements

A valid, current certification is mandatory for this role. Candidates without an active certification at the required level will not be considered.

Mandatory

  • Check Point Certified Security Expert (CCSE) must be valid and current on a supported software release.

Highly Desirable

  • Check Point Certified Security Master (CCSM) or CCSM Elite.
  • Check Point Certified Multi-Domain Security Management Specialist.
  • Check Point Certified Troubleshooting Expert (CCTE) or Automation Specialist (CCAS).
  • Complementary networking or security certification: CCNP/CCIE Security, JNCIP/JNCIE-SEC, HCIP/HCIE-Security

5. Preferred - Telecommunications Domain Experience

Candidates with service provider or telecommunications experience will be given clear preference. The following are considered significant advantages:

  • Prior delivery experience with a telecom operator, mobile network operator or internet service provider, particularly in a mobile packet core, MPBN or carrier backbone environment.
  • Understanding of telecom network architecture and the security demarcation between the transport layer and the security layer - including Gi/SGi firewall, roaming and peering security concepts.
  • Familiarity with modern carrier transport technologies: EVPN, Segment Routing (SR-MPLS) and SRv6, and how firewall clusters attach to and interoperate with such fabrics.
  • Experience operating within carrier-grade service level commitments, restricted maintenance windows and formal telecom change governance.
  • Exposure to carrier-scale traffic profiles and the performance engineering considerations that accompany them, including asymmetric routing and high session-rate environments.
  • Experience with regulatory, lawful intercept or telecom-specific compliance requirements as they affect security infrastructure design.

6. Personal Attributes

  • Composure and sound judgement when executing high-risk changes on live production networks during constrained maintenance windows.
  • Methodical and evidence-driven approach to diagnosis, with the discipline to document decisions and follow agreed process.
  • Ability to work independently on customer sites while maintaining alignment with programme governance and reporting.
  • Willingness to travel to customer locations as required and to work extended or night-time maintenance windows during cutover phases.
  • Collaborative approach with customer teams, with the credibility to advise and, where necessary, respectfully challenge on technical risk.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,530 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$28k per year (gross) • Remote/Hybrid • Full-Time • Moscow
C#
PowerShell
Python
SQL
C#
.NET
Databases
MS SQL
PostgreSQL
DevOps
Nginx
Cybersecurity
Tcpdump
Wireshark
QA
Postman
SoapUI
Apply
VoIP-инженер 10 hours ago
$28k per year (net) • Remote • Full-Time • Moscow
SQL
Databases
MySQL
MS SQL
DevOps
Alertmanager
Debian
Grafana
WebRTC
Zabbix
Prometheus
Cybersecurity
Tcpdump
Wireshark
Apply
$23k – $41k per year (Estimated) • Remote • 3+ years exp • Yekaterinburg
Python
C++
C++
CMake
Databases
ClickHouse
DevOps
eBPF
Cybersecurity
Suricata
Tcpdump
Wireshark
Cryptography
OpenSSL
StrongSwan
Apply
$15k – $34k per year (Estimated) • Remote/Hybrid • Full-Time • 3+ years exp • Novosibirsk
Databases
Apache Kafka
MySQL
Redis
DevOps
Grafana
Nginx
Zabbix
Cybersecurity
Tcpdump
Wireshark
Cryptography
StrongSwan
Apply
In office • Bachelor's Degree
C++
Python
Cybersecurity
Tcpdump
Wireshark
Apply
In office • Full-Time • 5+ years exp • Bachelor's Degree
DevOps
IAM
Cybersecurity
BeyondTrust
CyberArk
Microsoft Entra ID
Okta
Ping Identity
Zero Trust
Apply
In office • Full-Time • 10+ years exp • Doha
Apply
In office • Full-Time • 10+ years exp • Bachelor's Degree
DevOps
Amazon EC2
Amazon EKS
Ansible
AWS
Azure
Azure AKS
Azure DevOps
Bicep
CI/CD
CloudFormation
GitHub Actions
Incident Management
SLI/SLO/SLA
Splunk
Terraform
Windows Server
Kubernetes
Amazon CloudWatch
Amazon S3
GitHub
IAM
Cybersecurity
ISO 27001
Least Privilege
Zero Trust
Apply
$38k – $48k per year • In office • Full-Time • 3+ years exp • Bachelor's Degree • Khobar
DevOps
AWS
Azure
GCP
IAM
Cybersecurity
GDPR
HIPAA
ISO 27001
MITRE ATT&CK
NIST CSF
PCI DSS
SOC 2
Threat Modeling
Zero Trust
Apply
In office • Full-Time • 2+ years exp • Bachelor's Degree • Riyadh
Apply
See all jobs
This is one of many
368,530 more open roles from verified company boards, updated every day.