Firewall Engineer – Level 2 (NNDOE) - N.

Publiée le 04/04/2026

Proximus Luxembourg logo

Proximus Luxembourg


Temps de travail
Langues parlées
EN
Niveau d'étude

About Proximus NXT

Proximus NXT Luxembourg supports all organizations in their digital transformation, by providing holistic ICT & Telecommunication solutions, as well as tailored managed services. With our partners and customers, we co-create opportunities and enable growth in a secure and sustainable manner. As a result of our unique expertise in next-gen IT services, mobile and advanced connectivity, we help our customers achieve their ambitions and realize their vision.

Together with them and our partners we implement sovereign and trusted solutions that make people work smarter.– www.proximusnxt.lu

Your mission :

Domain: Network Security / Firewall Services
On-Call: Yes (Level 2 rotation)

The Level 2 Firewall Engineer ensures the stability, security, automation, and continuous improvement of the enterprise firewall infrastructure.

The engineer handles complex incidents and problems, designs and maintains automation for firewall lifecycle operations, and ensures all configurations align with the CMDB as the authoritative Source of Truth.

The role bridges operational excellence and infrastructure engineering, applying DevOps principles to security infrastructure.


Key Responsibilities

Incident & Problem Management (Level 2 Scope)

  • Handle escalated incidents from Level 1
  • Troubleshoot complex firewall issues (routing, NAT, clustering, performance)
  • Perform deep packet analysis when required
  • Conduct root cause analysis (RCA)
  • Identify recurring issues and open Problem records
  • Participate in post-mortem analysis and improvement plans
  • Participate in Level 2 on-call rotation

Firewall Engineering & Automation

  • Design and maintain automation for:
    • Software upgrades (CheckPoint, Fortinet, Open-Source)
    • Cluster upgrades and failover validation
    • Policy deployment pipelines
    • Backup & restore procedures
  • Implement infrastructure changes through:
    • Ansible / AWX
    • Git-based workflows
    • CI/CD pipelines
  • Ensure infrastructure changes are reproducible and version-controlled
  • Contribute to Git repositories and review pull requests
  • Maintain configuration as code principles

Configuration Governance & CMDB Integrity

  • Ensure all firewall objects and rules align with CMDB data
  • Enforce Source of Truth model (e.g., NetBox or equivalent)
  • Avoid manual configuration drift
  • Implement validation checks before deployment
  • Contribute to compliance reporting

Firewall Platform Expertise

Check Point Software Technologies

  • R8x architecture
  • Management Server / MDS
  • SmartConsole
  • ClusterXL
  • Policy installation & troubleshooting

Fortinet

  • FortiGate
  • FortiManager
  • HA clusters
  • Security Fabric integration

Open-Source Firewalls

  • nftables / iptables
  • pfSense
  • OPNsense
  • Strong understanding of Linux networking stack

DevOps & Engineering Practices

  • Infrastructure as Code mindset
  • CI/CD pipeline integration
  • Unit testing for automation scripts
  • Use of Git branching strategies
  • Observability integration (logs, metrics, alerts)
  • Secure coding practices for automation

Upgrade & Lifecycle Management

  • Plan and execute:
    • Major version upgrades
    • Hotfix deployment
    • Security patching
  • Automate pre-checks and post-checks
  • Maintain upgrade playbooks
  • Document rollback strategies

Security & Compliance

  • Ensure firewall configurations align with security policies
  • Support audit evidence collection
  • Support vulnerability remediation
  • Ensure secure configuration standards, and best practices
  • Participate in security hardening initiatives

Your profile :

Technical Skills Required

Mandatory

  • 5+ years in enterprise firewall engineering
  • Strong knowledge of:
    • CheckPoint R8x
    • FortiGate
  • Solid understanding of:
    • TCP/IP
    • Routing (BGP, OSPF basics)
    • NAT
    • VPN technologies
  • Experience with Linux networking
  • Experience with automation (Ansible preferred)
  • Git proficiency
  • Strong troubleshooting skills

Nice to Have

  • Experience with containerized firewall deployment
  • API-driven firewall configuration
  • Experience with CI/CD tools (GitLab CI, etc.)
  • Experience integrating firewalls with cloud (AWS)
  • Experience in high-availability architectures

 Soft Skills

  • Analytical mindset
  • Ability to perform structured RCA
  • Autonomous and proactive
  • Strong documentation discipline
  • Ability to mentor Level 1 engineers
  • Clear communication during incident bridges

Our offer :

A professional and stimulating work environment in the IT & telecom sector. Multiple career opportunities within the Proximus Group at national and international level, cutting-edge training in new technologies, a wealth of recognized expertise. We also offer an attractive salary package and many other benefits.

Our company is an equal opportunity employer, valuing diversity in all its forms. We firmly believe that each individual brings a unique richness to our teams, and we are committed to creating an inclusive environment where every voice counts.

If at the end of the process your application is successful, you will be asked to provide an extract from your criminal record. Your personal information will be handled in compliance with applicable data protection laws.

Postulez en ligne

Firewall Engineer – Level 2 (NNDOE) - N.

Postuler
1

La Newsletter

Restez informé de l'état du marché du travail au Luxembourg et recevez nos conseils pratiques !

Désinscription possible à tout moment.