Senior Lead Engineer, Cybersecurity, Network Security

Stryker Costa Rica, Heredia San Antonio Business Park Updated 17 September 2026
MedTechPharmaQuality Assuranceraveinformazureaws

Job description

Work Flexibility: Hybrid Position Summary Designs, engineers, integrates, and continuously improves enterprise network security capabilities that protect organizational infrastructure from cyber threats. Develops secure network engineering patterns, technical standards, reference implementations, and security controls for enterprise, data center, cloud, remote access, and manufacturing environments. Partners with Security Architecture, Enterprise Architecture, Network and Infrastructure teams, Security Operations, and technology owners to translate cybersecurity requirements and architectural intent into secure, scalable, and operationally supportable solutions. This role maintains deep hands-on technical expertise and supports engineering, implementation, verification, and complex troubleshooting of security capabilities, while partnering with appropriate technology and operations teams for routine production administration and lifecycle operations. What will you do: Design, engineer, integrate, and continuously improve enterprise network security capabilities including next-generation firewalls, secure remote access, IDS/IPS, secure web gateways, DNS security, network access control, DDoS protection, and network segmentation. Develop secure network engineering patterns, standards, reference architectures, and configuration baselines supporting data centers, cloud environments (AWS, Azure, Google Cloud), remote workforce connectivity, and manufacturing environments, and hybrid infrastructure. Partner with Security Architecture and Enterprise Architecture to translate cybersecurity requirements, Zero Trust principles, standards, and risk requirements into implementable network security designs and technical controls. Engineer and verify network segmentation, firewall policy, security inspection, access-control, and routing-security strategies that reduce attack surface, constrain lateral movement, and enforce appropriate trust boundaries. Lead network security engineering for new capabilities, platform modernization, migrations, major upgrades, and complex infrastructure initiatives, including development of reference implementations and proofs of concept. Perform network security assessments, technical risk analyses, architecture and configuration reviews, and control-effectiveness testing to identify security gaps and recommend scalable improvements. Engineer and verify network security telemetry, logging, and integrations supporting Security Operations, Incident Response, and Vulnerability Management. Participate in complex cybersecurity investigations and incidents, providing advanced network security expertise including traffic analysis, containment design, and verification of network-based response controls. Develop automation using scripting, APIs, and infrastructure-as-code to improve security consistency, repeatability, verification, and operational efficiency; create and maintain supporting engineering documentation, architecture diagrams, configuration standards, and implementation guidance. Evaluate emerging network security technologies, AI-enabled security capabilities, vendor capabilities, and industry practices; conduct technical evaluations and provide recommendations regarding enterprise adoption. What you need: Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related discipline required; Master's degree preferred. Certifications preferred: CCNP Security, CCIE Security, Palo Alto Networks security certifications, CISSP, cloud security certifications, or equivalent demonstrated expertise. Advanced training or demonstrated expertise in enterprise and cloud networking, Zero Trust Architecture, software-defined networking, firewall engineering, network segmentation, secure network design, OT/manufacturing network security, and network security automation preferred. Qualifications & experience Minimum 6 years of enterprise network security engineering experience. Deep hands-on experience with enterprise next-generation firewall and network security technologies such as Palo Alto Networks, Cisco, Check Point, Fortinet, or equivalent platforms. Experience engineering VPN and secure remote access, IDS/IPS, NAC, DNS security, network segmentation, and associated network security controls. Experience securing Azure, AWS, Google Cloud, or hybrid cloud networking environments. Strong knowledge of routing, switching, TCP/IP, DNS, DHCP, TLS, network protocols, application traffic flows, and network security inspection technologies. Experience developing network security standards, configuration baselines, reference architectures, or repeatable engineering patterns. Experience with security telemetry, network traffic, packet capture and protocol analysis, SIEM integration, and supporting incident investigation or threat hunting. Experience with scripting, APIs, infrastructure-as-code, or other methods of automating network security configuration and verification. Working knowledge of Zero Trust principles, NIST CSF, CIS Controls, emerging AI security considerations, and applicable cybersecurity standards and frameworks. Travel Percentage: 10%

Stand out for this role

NoxPharm tailors your CV to this job description by aligning your experience with the role requirements and terminology. Built for pharma & life sciences.

Tailor my CV now — free to try