Job Description: Network Security Governance Consultant
Role: Network Security Governance Consultant
Work Model: Hybrid
Job Summary
We are seeking an experienced Network Security Governance Consultant to provide security reviews, governance oversight, risk assessments, and technical guidance across network, cloud, and infrastructure environments. The ideal candidate will have strong expertise in network security, vulnerability management, configuration drift controls, firewall reviews, and security compliance.
The consultant will work closely with infrastructure, engineering, and project teams to identify security gaps, assess risks, validate remediation activities, and ensure alignment with enterprise security policies and standards.
Key Responsibilities
- Review network and infrastructure configurations to ensure compliance with enterprise security policies, security baselines, and hardening standards.
- Monitor configuration drift, investigate security deviations, track remediation activities, and manage control exceptions.
- Analyze external perimeter scan results and vulnerability findings using tools such as Qualys and other vulnerability management platforms.
- Validate vulnerability remediation plans, assess control effectiveness, and provide risk-based recommendations.
- Review network traffic flows, firewall rules, routing, DNS, proxy, load balancer configurations, and connectivity requirements.
- Conduct security assessments of network architectures, application connectivity designs, and infrastructure deployments.
- Identify security gaps and provide technical guidance to engineering, infrastructure, and project teams.
- Assess cloud, on-premises, and hybrid environments for network segmentation, access control, perimeter security, and defense-in-depth.
- Evaluate security exceptions, compensating controls, and risk acceptance decisions.
- Support the development and maintenance of security standards, technical controls, configuration baselines, and hardening guidelines.
- Collaborate with technical teams to resolve security findings and improve the organization's overall security posture.
- Communicate security risks, assessment findings, and recommendations to technical and non-technical stakeholders.
Required Skills and Qualifications
- Strong understanding of network architecture, network security principles, and end-to-end network traffic flows.
- Experience reviewing firewall rules, routing, DNS, proxy, load balancers, and network device configurations.
- Hands-on experience with Qualys or similar vulnerability management tools, including perimeter scanning, vulnerability assessment, and remediation validation.
- Knowledge of configuration management, configuration drift monitoring, security baselines, and compliance controls.
- Experience conducting security reviews, risk assessments, and technical design evaluations.
- Strong knowledge of network segmentation, DMZ architecture, perimeter security, and hybrid connectivity.
- Experience with cloud platforms such as Microsoft Azure, AWS, or GCP and their network security controls.
- Understanding of security governance, risk management, control exceptions, and compensating controls.
- Strong analytical, investigative, documentation, and communication skills.
- Ability to collaborate with technical teams and provide practical, risk-based security recommendations.