Network Security Engineer
Added: 21.07.2026
Multiple locations
Region: Europe
Your responsibilities:
Edge Architecture & Engineering
- Perimeter Defense Mastery: Lead the end-to-end deployment, configuration, and maintenance of Next-Generation Firewalls (Palo Alto, Fortinet), ensuring high availability (Active/Active & Active/Passive) and optimal inspection performance across global entry points.
Zero Trust Transition: Architect and implement ZTNA solutions to move beyond legacy VPNs, focusing on granular, application-level access and identity-aware security policies. - Multi-Cloud Network Security: Engineer and manage cloud-native security controls within AWS, Azure, and GCP, ensuring consistent security posture across hybrid and multi-cloud environments.
- DDoS & Threat Mitigation: Design and refine DDoS protection strategies and automated threat prevention policies (SSL decryption, IPS/IDS) to shield critical infrastructure from sophisticated external attacks.
Product Lifecycle & Evolution
- Lifecycle Governance: Oversee the delivery of Edge solutions from initial design through build, global rollout, and continuous optimization, ensuring that all security controls are reliable, scalable, and documented.
- Edge Innovation: Proactively identify emerging trends in Edge computing and SASE (Secure Access Service Edge) to inform the product roadmap and maintain a competitive advantage in network defense.
Operational Excellence & Visibility
- Technical Subject Matter Expertise: Serve as the lead engineer for complex network security escalations, performing deep-packet analysis and root-cause investigations to implement long-term architectural fixes.
- Security Observability: Develop advanced monitoring dashboards and telemetry to provide real-time visibility into edge traffic patterns, attack surfaces, and the health of the security stack.
- Automation & Orchestration: Manage security policies as code while continuously improving automation workflows and cross-platform orchestration to eliminate manual friction, reduce operational overhead, and ensure consistent, high-speed security enforcement.
- Self-Service & Enablement: Build and maintain automate
We are looking for you, if you have:
Education / Experience
- Educational Background: Bachelor’s degree in Computer Science, Software Engineering, Information Security, or a related technical field.
- Perimeter Security Mastery: 5+ years of hands-on experience in designing and managing enterprise-grade Firewall environments (specifically Palo Alto and/or Fortinet).
- Cloud Security Expertise: Proven track record of implementing network security controls in at least two major cloud providers (AWS, Azure, or GCP).
- Perimeter & Inspection Expertise: Proven track record in configuring and maintaining Palo Alto Next-Generation Firewalls (NGFW), including TLS inspection, User identification, WildFire, Threat Prevention, URL Filtering and GlobalProtect.
- Automation Engineering: Proven experience using Ansible, Terraform, or Python to manage network security infrastructure at scale.
- Large-Scale Infrastructure: Experience managing security controls in complex, global environments involving thousands of diverse device profiles (IoT, Medical, Corporate).
- Regulated Industry: Experience working in highly regulated environments (e.g., Pharmaceuticals, Healthcare, or Finance) is a significant plus.
Technical Skills
- NGFW Expert: Expert-level knowledge of Palo Alto and/or Fortinet platforms, including advanced threat prevention, SSL decryption, and high-availability design.
- DDoS Mitigation: Experience managing specialized DDoS protection services (e.g., Akamai, Cloudflare, or F5).
- ZTNA & Remote Access: Proficiency in modern Zero Trust architectures and SASE frameworks (e.g., Zscaler, Prisma Access).
- Multi-Cloud Networking: Strong understanding of cloud networking components (VPCs, VNETs, Transit Gateways, Cloud Firewalls).
- Network Foundations: Deep understanding of core protocols (BGP, OSPF, DNS, TLS/SSL) and how they intersect with security enforcement.
Skills below will be considered a plus:
- Vendor certifications: Fortinet NSE or Palo Alto Networks PCNSA PCNSE or Cisco CCNP Security
- Cybersecurity certification: CISSP
- Infrastructure as Code (IaC): Proficiency in Terraform and GitHub to maintain version-controlled, reproducible security configurations.
- Scripting & Integration: Strong skills in Python or Go to build custom API integrations between security platforms and internal orchestration tools.
- DDoS Mitigation: Experience managing specialized DDoS protection services (e.g., Akamai, Cloudflare, or F5).
- Governance Frameworks: Familiarity with NIST, ISO 27001, and FAIR data principles.
Leadership Skills
- Communication: Strong ability to build trust with network and infrastructure experts and explain complex security policy concepts to non-technical stakeholders.
- Innovation & Curiosity: A relentless passion for staying ahead of threat actors by researching emerging network security trends and automated enforcement techniques.
- Thriving in Ambiguity: Ability to navigate global complexity and drive clarity when translating high-level security requirements into functional network policies.
- Self-Starter: Proven ability to manage technical workstreams from concept to production with minimal supervision, taking full ownership of the Edge Defense product lifecycle.
Additional Qualifications
- Demonstrated ability to mentor colleagues with less experience and provide guidance on cybersecurity best practices and analysis techniques
- Strong facilitation, communication, and conflict resolution skills to ensure alignment across multiple product squads and complex stakeholder networks
- Demonstrated interpersonal, collaborative and commitment to operational excellence skills.
We offer:
- Participation in interesting and demanding projects.
- Flexible working hours.
- A great, non-corporate atmosphere.
- Possibility to work remote or hybrid (2 days per week from the office).
- Opportunities for development and promotion.
- Attractive package of benefits.
We reserve the right to contact the selected candidates.
Why is it worth joining TTMS?
Flexible working hours
Not everyone feels comfortable working the standard 9 a.m. to 5 p.m. hours. We have been successfully running projects for many years despite diversified work patterns.
Possibility of hybrid work
At TTMS, desk-to-desk work is what drives us, but we understand if someone prefers a hybrid model. We are equipped with all the necessary tools to work in a hybrid model.
Great, non-corporate atmosphere
Professionalism, attention to the quality of work and a friendly, informal atmosphere are not mutually exclusive. A flat structure and natural, friendly relationships create the basis for creativity and innovation.
Interesting, international projects
We create solutions for medium and large companies, we are present in Poland, Malaysia, Denmark, the UK, Switzerland, and India – the effects of your work will travel around the world. In TTMS you have an influence on the company’s success.
Together towards climate neutrality
We select subcontractors to minimize the carbon footprint, organize bush plantings, save peat bogs – all to achieve climate neutrality in 2025. We are glad that we are attracting more and more people who also care about sustainable development and environmental protection.
Friendly offices
Our offices are modern spaces that inspire employees and are environmentally friendly. Białystok is the kingdom of Marvel superheroes, Krakow is a soothing tropical forest, Wrocław is an art gallery, and the Lublin branch is a rock u0022hall of fameu0022.
Would you like to work for us?
Sending CV
Include information about technical skills, knowledge of programming languages and IT tools, and possibly experience in projects.
Phone Screening
The interview is aimed at assessing the candidate’s suitability for the position and verifying basic information from the CV. It is also an opportunity to discuss the candidate’s expectations and briefly present the job description and working conditions.
HR + technical meeting
We talk about the candidate’s professional experience, but also expectations regarding the new job. This is also the moment to check references and confirm the authenticity of the information provided, which allows you to get to know the candidate better and assess his fit with the company’s organizational culture.
Client company meeting
The candidate is introduced to the client. This stage aims to match the future employee to a specific project, taking into account both their technical skills and design preferences, which maximizes the chances of successful cooperation.
Employment
We sign an agreement that includes the terms of cooperation, scope of duties, remuneration and other key aspects of employment, such as the rights and obligations of both parties. From now on, the candidate becomes an official employee of the company.
Onboarding + first day of work
A comprehensive process of familiarizing a new employee with the organization, team and tools, aimed at making it easier for him to join work as quickly and effectively as possible. In TTMS, we use an internal e-Learning platform to conduct modern onboarding.
Our offices
Warsaw
The heart of our company and our command center
The Management Board of the company and management of individual business areas function here. On a daily basis, it is here that the most important, strategic and business decisions are made, as well as pro-ecological iniciatives. The Warsaw branch – located in Varso Tower – aims to be the first to create a fully eco-friendly office using renewable Energy and environmentally friendly materials, which is confirmed by the BREEM certificate.