background

Network & Infrastructure Security Engineer

https://rapifuzz.in/career/network-infrastructure-security-engineer Copy Job Link
Gurugram, Haryana
Posted 3 days ago
Experience
Minimum 6-8 Year
Work Level
Senior Level
Job Type
Full Time
Offer Salary
Not Disclosed
Overview

At RapiFuzz®, we're dedicated to our mission of “Making Security Simple™” and empowering organizations against the ever-evolving landscape of digital threats. 

Our core motivation revolves around securing digital environments and safeguarding sensitive data. Upholding values of integrity, innovation, collaboration, and customer-centricity, we strive to offer unparalleled cybersecurity solutions tailored to the unique needs of our clients. 

Who We Are 

As an innovator in the cybersecurity domain, RapiFuzz® takes pride in its diverse portfolio of next-generation cybersecurity products and services designed to address a wide range of security challenges. 

Our team comprises cybersecurity professionals, researchers and engineers with extensive industry experience and deep technical expertise. We build and deploy security technologies that help organizations discover, protect, test, monitor and respond to cyber threats. 

Position Overview 

We are looking for a hands-on Network & Infrastructure Security Engineer responsible for designing, deploying, configuring, securing, monitoring and troubleshooting enterprise network and IT infrastructure.

The ideal candidate should have strong practical experience with Cisco routers and switches, FortiGate firewalls, Wireless Access Points, Linux/Ubuntu, Windows Server, Active Directory, Microsoft 365, Azure, virtualization, SIEM and SOAR platforms. 

The candidate will also be responsible for deploying and maintaining open-source solutions around firewall, SIEM, SOAR etc., integrating security telemetry from network, endpoint, server and cloud environments, and implementing security controls across infrastructure. 

This is a hands-on engineering role. The candidate should be comfortable installing systems from scratch, configuring network and security devices, troubleshooting production issues, implementing security rules and documenting the complete environment.

Key Responsibilities

1.Network Infrastructure 

  • Configure, administer and troubleshoot Cisco routers and Layer-2/Layer-3 switches. 
  • Configure and manage: 
    • VLANs 
    • Trunking 
    • Access ports 
    • Inter-VLAN routing 
    • STP/RSTP 
    • EtherChannel/LACP 
    • DHCP 
    • DNS 
    • NAT 
    • ACLs 
    • Routing protocols such as OSPF, EIGRP and BGP. 
  • Troubleshoot network connectivity, latency, packet loss, routing and switching issues. 
  • Configure and manage network segmentation and secure network architecture. 
  • Configure and troubleshoot TCP/IP, IPv4/IPv6, DNS, DHCP, HTTP/HTTPS, SSH, SNMP, NTP and other common network protocols. 
  • Perform network performance monitoring and capacity planning. 
  • Maintain network diagrams, IP addressing schemes, VLAN documentation and configuration backups.
  • Implement network redundancy and high-availability configurations. 

2.Firewall & Network Security 

  • Install, configure and administer FortiGate firewalls. 
  • Create and manage:
    • Firewall policies
    • NAT policies 
    • VIPs 
    • Security policies 
    • Web filtering 
    • Application control 
    • IPS 
    • Antivirus 
    • SSL inspection
    • DNS filtering 
    • VPN policies. 
  • Configure IPSec and SSL VPNs. 
  • Configure site-to-site and remote-access VPN connectivity. 
  • Implement firewall rules based on least-privilege principles. 
  • Review and optimize existing firewall policies. 
  • Troubleshoot firewall connectivity and security-policy issues. 
  • Configure HA/firewall clustering where required. 
  • Monitor firewall logs and security events. 
  • Integrate firewalls with SIEM platforms. 
  • Perform firewall hardening and configuration audits. 

3.Wireless Infrastructure 

  • Install, configure and troubleshoot enterprise Wireless Access Points. 
  • Configure SSIDs, VLAN mapping and authentication. 
  • Configure WPA2/WPA3 and enterprise authentication. 
  • Troubleshoot wireless connectivity and performance. 
  • Configure guest and corporate wireless networks. 
  • Implement wireless network segmentation. 
  • Integrate wireless infrastructure with enterprise security controls  

4.Linux / Ubuntu Administration 

  • Install, configure and administer Linux/Ubuntu servers. 
  • Perform server hardening and security configuration. 
  • Manage: 
    • Users and groups 
    • SSH 
    • File permissions 
    • Services 
    • Systems 
    • Cron 
    • Networking 
    • Storage 
    • LVM 
    • RAID 
    • Package management. 
  • Troubleshoot Linux performance, networking, storage and application issues. 
  • Configure and maintain Linux-based security infrastructure. 
  • Write basic Bash/Shell scripts for automation. 
  • Manage Linux services and troubleshoot system logs. 
  • Configure secure remote administration using SSH. 
  • Apply OS security updates and patches. 

5.Windows Server Administration 

  • Install, configure and administer Windows Server environments. 
  • Manage: 
    • Active Directory 
    • Domain Controllers 
    • DNS 
    • DHCP 
    • Group Policy 
    • File and Print Services 
    • Windows Server roles and features. 
  • Create and manage users, groups, OUs and security policies. 
  • Configure and troubleshoot Group Policies. 
  • Perform Windows Server hardening. 
  • Manage Windows updates, patches and security configurations. 
  • Troubleshoot authentication, domain, DNS and network issues. 
  • Configure Windows event logging and forwarding to SIEM platforms. 
  • Integrate Windows infrastructure with security monitoring solutions. 

6.Active Directory & Microsoft 365 

  • Install, configure and administer Microsoft Active Directory. 
  • Manage AD users, groups, computers, OUs and Group Policies. 
  • Configure authentication and access-control policies. 
  • Troubleshoot AD replication and authentication issues. 
  • Configure and administer Microsoft 365 environments. 
  • Manage Microsoft 365 users, groups, permissions and security settings. 
  • Understand Microsoft Entra ID / Azure AD concepts. 
  • Configure identity synchronization between on-premise Active Directory and Microsoft cloud environments. 
  • Assist with Microsoft 365 security, MFA and conditional access configurations. 
  • Troubleshoot Microsoft 365 connectivity and authentication issues. 

The following below are Good to Have 

7.Azure Cloud Administration 

  • Configure and administer Microsoft Azure infrastructure. 
  • Deploy and manage: 
    • Azure Virtual Machines 
    • Virtual Networks 
    • Subnets 
    • Network Security Groups 
    • Azure Firewall 
    • VPN Gateway 
    • Load Balancers 
    • Storage 
    • Azure Monitor 
    • Entra ID. 
  • Configure secure connectivity between on-premise infrastructure and Azure. 
  • Configure VPN and hybrid-cloud environments. 
  • Implement network segmentation and security controls in Azure. 
  • Configure cloud security logging and monitoring. 
  • Integrate Azure security logs with SIEM platforms. 
  • Apply Azure security best practices and hardening. 
  • Understand Azure resource management, RBAC and identity concepts. 

8.Wazuh, SIEM & SOAR 

  • Install, configure and administer Wazuh in standalone and distributed environments. 
  • Deploy Wazuh agents across: 
    • Windows 
    • Linux 
    • Servers 
    • Cloud workloads 
    • Endpoints. 
  • Configure: 
    • Log collection 
    • Security monitoring 
    • File Integrity Monitoring 
    • Vulnerability detection 
    • Security policies 
    • Compliance monitoring 
    • Active response 
    • Detection rules 
    • Custom decoders and rules. 
  • Configure integrations between Wazuh and network/security devices. 
  • Install, configure and maintain open-source SIEM platforms. 
  • Experience with platforms such as: 
    • Wazuh 
    • ELK / Elastic Stack 
    • OpenSearch 
    • Graylog 
    • Security Onion 
    • OSSIM or equivalent platforms. 
  • Configure log ingestion from firewalls, routers, switches, servers, endpoints and applications.
  • Develop and tune detection rules and alerts. 
  • Configure dashboards, correlation and security monitoring. 
  • Install and configure open-source SOAR platforms. 
  • Develop basic automated incident-response workflows/playbooks. 
  • Integrate SIEM/SOAR with: 
    • Firewalls 
    • EDR 
    • Threat intelligence 
    • Email 
    • Ticketing systems 
    • APIs 
    • Security tools. 
  • Troubleshoot SIEM data ingestion, parsing, indexing and alerting issues. 

9.VMware / Virtualization 

  • Install, configure and administer VMware vSphere/ESXi environments. 
  • Configure and manage: 
    • ESXi 
    • vCenter 
    • Virtual Machines 
    • Virtual Networks 
    • Datastores 
    • HA 
    • DRS 
    • vMotion. 
  • Troubleshoot virtualization and VM performance issues. 
  • Configure secure virtualization environments. 
  • Perform VM deployment, migration, backup and recovery. 
  • Understand virtualization networking and storage concepts. 

10.OpenStack / Private Cloud 

  • Install, configure and support OpenStack-based private cloud environments. 
  • Experience with OpenStack components and services is highly desirable. 
  • Configure compute, networking, storage and identity services. 
  • Support self-service provisioning of virtual machines and cloud resources. 
  • Configure cloud monitoring and operational dashboards. 
  • Troubleshoot OpenStack networking, compute and storage issues. 
  • Integrate OpenStack with enterprise networking and security infrastructure. 

11.Data Centre Infrastructure 

  • Support network and security infrastructure within data-centre environments. 
  • Configure and manage high-availability infrastructure. 
  • Support server virtualization and clustered environments. 
  • Configure infrastructure using SAN/NAS storage. 
  • Support backup, replication and disaster-recovery mechanisms. 
  • Assist with deployment of local and remote-site replication. 
  • Configure and troubleshoot load-balancing environments. 
  • Support infrastructure monitoring and capacity management. 
  • Implement security hardening across servers, network devices and security appliances. 

12.Security Operations & Monitoring 

  • Monitor network, server and security infrastructure. 
  • Investigate security alerts and infrastructure incidents. 
  • Perform first-level security event analysis and troubleshooting. 
  • Coordinate with SOC, CERT/CSIRT, OEMs, SI partners and internal technical teams. 
  • Support incident response and containment activities. 
  • Perform vulnerability remediation on network and server infrastructure. 
  • Ensure security configurations comply with organizational policies. 
  • Maintain security and infrastructure documentation. 
  • Participate in security audits and technical assessments. 

13.OEM / SI / Customer Coordination 

  • Coordinate with OEMs, system integrators and technology partners. 
  • Work with customer IT and security teams for deployment and troubleshooting. 
  • Participate in technical discussions and solution deployment. 
  • Prepare installation and configuration documentation. 
  • Maintain configuration baselines and implementation records. 
  • Provide technical support during POCs, pilots and production deployments. 
  • Assist pre-sales and engineering teams with technical demonstrations where required. 

14.Automation & Scripting 

The candidate should have basic automation capabilities and should be able to automate repetitive infrastructure and security tasks.

Experience with any of the following is desirable: 

  • Python 
  • PowerShell 
  • Bash 
  • REST APIs 
  • Ansible 
  • Git 
  • YAML/JSON. 

Examples include:

  • Automated firewall configuration checks 
  • Server health checks 
  • Log collection 
  • User provisioning 
  • Security configuration validation 
  • SIEM integrations 
  • API-based infrastructure management. 

Required Technical Skills

Networking

  • Cisco Routers 
  • Cisco L2/L3 Switches 
  • VLAN 
  • Routing 
  • Switching 
  • OSPF 
  • BGP 
  • STP 
  • ACL 
  • NAT 
  • DHCP 
  • DNS 
  • TCP/IP 
  • IPv4/IPv6 
  • VPN 

Firewall 

  • FortiGate 
  • Firewall Policies 
  • NAT 
  • IPS 
  • Web Filtering 
  • Application Control 
  • SSL Inspection 
  • IPsec VPN 
  • SSL VPN 
  • HA 

SIEM / SOAR 

  • Wazuh 
  • ELK / Elastic 
  • OpenSearch 
  • Graylog / Security Onion / equivalent 
  • SIEM log collection 
  • Detection rules 
  • Correlation 
  • Alert management 
  • SOAR 
  • Security automation 
  • API integration 

Operating Systems 

  • Ubuntu/Linux 
  • Windows Server 
  • Windows administration 
  • Linux administration 
  • System hardening 

Identity

  • Active Directory 
  • DNS 
  • DHCP 
  • Group Policy 
  • Microsoft 365 
  • Microsoft Entra ID / Azure AD 
  • MFA 
  • RBAC 

Cloud 

  • Microsoft Azure 
  • Azure Networking 
  • Azure VM 
  • Azure VNet 
  • NSG 
  • Azure Firewall 
  • VPN Gateway 
  • Azure Monitor 
  • Cloud security 

Virtualization & Cloud Infrastructure 

  • VMware ESXi 
  • vCenter 
  • HA 
  • DRS 
  • vMotion 
  • OpenStack 
  • SAN/NAS 
  • Clustering 
  • Load balancing 
  • Backup and replication 

Wireless

  • Enterprise Access Points 
  • SSID 
  • VLAN 
  • WPA2/WPA3 
  • Enterprise authentication 

Educational Qualifications 

  • Bachelor's / Master's degree in Computer Science, Information Technology, Electronics, Engineering or equivalent. 
  • CCNA / CCNA Security – Mandatory or equivalent networking certification. 

Preferred Certifications 

At least one of the following certifications is highly desirable:

  • CCNP Enterprise / Security 
  • Fortinet NSE / FCP / equivalent Fortinet certification 
  • CompTIA Security+ 
  • CompTIA Server+ 
  • Certified Ethical Hacker (CEH) 
  • VMware Certified Professional (VCP) 
  • Microsoft Certified: Windows Server / Azure Administrator 
  • RHCSA / RHCE 
  • ECSA 
  • SSCP 
  • CCSP 
  • AZ-104 – Azure Administrator Associate 
  • Other relevant cybersecurity, networking or cloud certifications. 

Experience

Minimum 4 years of relevant experience in network, infrastructure and/or cybersecurity engineering. 

The candidate should have demonstrable hands-on experience in: 

  • Cisco networking 
  • FortiGate firewall administration 
  • Linux/Ubuntu 
  • Windows Server 
  • Active Directory 
  • Wazuh/SIEM 
  • Microsoft 365 
  • Azure 
  • Virtualization 
  • Network security 
  • Infrastructure troubleshooting. 

Candidates with 6–8+ years of experience and strong exposure to enterprise infrastructure, data centres, SIEM/SOAR and cloud security will be considered for a senior position. 

Key Competencies 

  • Strong troubleshooting and analytical skills 
  • Hands-on problem-solving ability 
  • Good understanding of cybersecurity principles 
  • Ability to work independently 
  • Ability to work under pressure during incidents 
  • Strong documentation skills 
  • Customer-facing communication skills 
  • Ability to coordinate with OEMs and system integrators 
  • Strong learning and research orientation 
  • Ability to understand new open-source security technologies quickly 
  • Willingness to work on deployment and support assignments at customer locations when required. 

What We Expect From You 

At RapiFuzz®, we are looking for engineers who build and troubleshoot rather than just operate tools. 

You should be comfortable taking an environment from: 

“Nothing is installed” → Installation → Configuration → Integration → Hardening → Monitoring → Troubleshooting → Documentation. 

The ideal engineer should be capable of setting up a complete secure infrastructure comprising: 

Cisco Network → FortiGate Firewall → Windows/Linux Servers → Active Directory → VMware/OpenStack → Azure → Wazuh/SIEM → SOAR → Security Monitoring. 

You should also have the curiosity to research new technologies, experiment with open-source cybersecurity tools and continuously improve the security and reliability of the infrastructure. 

Why Join RapiFuzz®? 

 

  • Work on next-generation cybersecurity products and platforms. 
  • Gain exposure to enterprise cybersecurity, networking, cloud and infrastructure. 
  • Work with open-source and commercial security technologies. 
  • Work closely with cybersecurity researchers and product engineers. 
  • Opportunity to work on challenging customer deployments and security architectures. 
  • Exposure to SIEM, SOAR, API Security, Cyber Range, Incident Management and Threat Intelligence technologies. 
  • Strong emphasis on continuous technical learning and innovation. 

Our Mission 

Making Security Simple™ 

47 Network & Infrastructure Security Engineer Apply Now
Explore BITS Cybersecurity Program