Senior Security Operations Lead — Digital Networks
Philips
- Location
- Bangalore
- Work model
- On-Site
- Level
- Senior
- Posted
- 7h ago
Skills
About this role
Job Title Senior Security Operations Lead — Digital Networks Job Description Senior Security Operations / SME / Governance — Digital Networks Role type: Senior individual contributor / hands-on subject-matter expert (with mentoring) Experience: ~10–15 years in enterprise network security, with deep and current hands-on depth on Cisco Secure Firewall and at least one major proxy/SSE platform. Hands-on is non-negotiable, this is not a review-only role.
About the role
Deep technical authority for our firewall, proxy, and generic secure-access estate. You are the person who is hands-on in the consoles, scripts, and vendor APIs every week; the final escalation point when something hard breaks; and the one who keeps the estate audit-ready between incidents. You work in a patient-safety-first engineering culture: direct, plain-spoken, evidence over slideware. Profile mix: 55% Security Operations | 25% Hands-on Technical (incl. automation & AIOps) | 20% Governance, Risk & Compliance.
What you'll own
Firewall estate — Cisco Secure Firewall (FTD / FMC / ASA / Firepower): rule lifecycle and hygiene, HA, FMC upgrades and migrations, perimeter, and internal segmentation. Proxy & web security — PAC file management at global scale (including China and other high-latency / restricted regions), proxy policy, SSL/TLS inspection. Secure Service Edge / SASE — Zscaler (ZIA / ZPA) and Cisco Umbrella as the primary platforms. Exposure to Palo-Alto, Netskope or Cloudflare One is a plus. Remote & site connectivity — IPSec / SSL VPN, AnyConnect / Secure Client, site-to-site (S2S), out-of-band management (OOBM), and partner access (S2S / VDI). Identity & access — Cisco ISE / AAA. Certificates & PKI — certificate lifecycle and expiry management, TLS, and closed-loop certificate automation. Vulnerability & advisory response — PSIRT cadence, patching, and upgrade lifecycle across the estate. Hands-on Technical: Deep, current hands-on across the estate: Cisco FTD/FMC/ASA/Firepower, ISE, Cisco SSE/Umbrella, Zscaler ZIA/ZPA, PAC files, PKI/TLS, rule design, SSL inspection, FMC HA and migrations, ISE policy, VPN (IPSec/SSL/S2S) troubleshooting. Holds L3/L4 escalation authority with Cisco TAC, Zscaler and managed-service partners, ie: the break-glass engineer when P1/MI hits: firewall HA failures, FMC migrations, PSIRT response. Writes and maintains automation in Python, Ansible and Terraform, working directly against vendor REST APIs: Cisco FMC, Zscaler, ISE, and IPAM/DNS (e.g. Efficient IP): safe bulk rule changes, PAC at scale. Maintains lab/sandbox to test changes and upgrades before production. Cloud network security — Liaises with Cloud Infrastructure, Security, DNS, IPAM and Active Directory teams to secure and enable network connectivity and integration across AWS, Azure, GCP and China cloud — Security groups, NACLs, NVA / cloud firewalls, Cloud On-Ramp, ExpressRoute/DX, TGW/VNet peering, SSE PoP integration and CSPM signal handoff. Operations & governance: Drives the firewall/proxy/SSE domain from reactive firefighting to a predictable run model: ITSM discipline, RCA, change governance, and SLA/KPI ownership for the domain. Senior ServiceNow change approver for firewall, proxy, VPN and other security-touching changes; technical reviewer on the change/technical review board. Keeps the estate audit-ready — NIS2, ISO 27001, healthcare-grade — with defensible evidence and change-to-change-record traceability. Maintains the domain security risk register and supports DR / security tabletop drills. Holds managed-service and OEM partners (Cisco, Zscaler and the relevant MSPs) technically accountable on delivery quality, feeding the commercial and escalation process owned by the Lead. Stakeholder, Communication & Escalation Management — Runs structured stakeholder engagement, leadership/vendor/audit communications, and escalation as a discipline (thresholds, pathways, ownership) feeding the Lead's commercial authority. Service