Opdrachten
Info
Functie
Network Security Design EngineerLocatie
RijswijkUren per week
40 uren per weekLooptijd
31.10.2022 - 29.05.2023Opdrachtnummer
121914Sluitingsdatum
Het CV en de motivatie dienen aangeboden te worden in het Engels.
Het CV dient in een Word format aangeleverd te worden.
*Job Description
The digital transformation strategy of Shell requires an increasingly flexible, agile and secure IT environment in order to enable best use of data, cloud services, personalization of user experience and connectivity of devices. Keeping our business goals and user experience in the forefront, Shell IT has taken the decision to insource or directly procure several connectivity services. By taking greater control over key aspects of connectivity we can provide our users with better user experience, speed and agility, while maintaining operational effectiveness and efficiency. As a result, we are building a partially insourced and multi-vendor ecosystem for our connectivity products and services and will be developing new skills and capabilities. Come join us on this exciting and ambitious journey.
This role is part of Shell IT’s Connectivity Portfolio team and specific to the Network Perimeter services, where Shell and third-party users and applications need to be connected. Specifically, this role is critical in supporting projects with design engineering capabilities under the renewed model.
The design engineer is expected to be a Subject Matter Expert (SME) covering the application of telecommunications and network technology deployed across the Shell Group. This covers all Shell’s businesses, all Shell’s location (offices, onshore plants, offshore plants, offices, trading floors, etc.) and various types of projects including capital projects and IT projects.
The purpose of the design engineer role is to participate in projects and deliver the network designs and implementations required based on defined standards. The design engineer will be the key person in the project for all telecom and network elements.
The key Accountabilities are:
1. Collect all requirements needed to produce the design by working with the project manager and relevant stakeholders
2. Apply the standards defined to create a design with all relevant details
3. Document the solution working with the architects
4. Develop a deployment strategy together with the project manager and create an implementation plan which leads to a successful deployment of the produced design
5. Share knowledge and drive continuous improvement across the community
*Requirements
Accountabilities:
For the services in scope:
• Collect and document requirements by specifying the needed functionality, all the non-functional requirements and all dependencies (e.g. cabling, construction or electrical work needed)
• Create a Shell standards-based design produced and signed off by the design assurance team.
• Work with architecture & portfolio to update standards in specific cases
• Work with other designers to produce specific elements of the design requiring special knowledge
• Develop an implementation plan and testing strategy which is aligned with business readiness and IT delivery timelines
• Handover the design and implementation plan to the project manager and operations center for deployment and operations
• Share knowledge obtained and learn from others as part of a natural team across architecture, portfolio, design, network engineers, operations, and service management, amongst others.
• Provide hands on implementation and operational support as required.
People Dimensions:
• Number of direct reports: 0
• Number of indirect reports: 1-3 project resources plus any subcontractors delivering project resources.
Financial Dimensions:
• Directly managed budget: < $ 0
Business Dimensions:
• The position supports Shell projects at various locations ranging from offices to remote environments.
• Directly controls or indirectly influences:
• Network projects with value up to $1M
No direct reports but has responsibility to provide oversight of contract staff engaged to support project delivery.
Special Challenges
• Manage complex interface structures across organizational and geographic boundaries.
• Ability to collaborate with project teams, telecom contractors / service providers (ISP), the Major Execution Contractors (FEED, EPC, EPCM, TSI etc.) and other contractors
Technical Qualifications - MANDATORY:
Network security, we are looking for “design experience with next generation firewalls and proxies and more specifically Palo Alto Networks L7 firewalls and Zscaler”.
• Minimum Education or Certification: Bachelor’s degree in electrical engineering, Computer Science, Telecommunications or equivalent work experience
• Cisco certifications – CCNP Route / Switch
• Palo Alto Certifications – PCNSA
• Zscaler Certifications – ZCCP IA/PA TAC
• Security Certification - CCISP
• Typical Years of Experience: 12-20 - leading and executing Telecoms project delivery, Telecoms operations, or IT consultancy assignments to design, develop and deliver viable network and telecom solutions, preferably in Oil and Gas or similar industry with offshore experience preferred.
• A high degree of technical network knowledge in the IP network technology with a specialization in network security.
• Highly proficient in, deployment and configuration of networking technologies specific to routing, switching and general network security best practices in a global enterprise environment.
• Experience and proficiency in a hands-on capacity with Data Center and Remote Office Enterprise/campus designs, architecture, deployment and configuration with physical and virtual appliances. Familiarity with applications driving modern infrastructure design in private and public cloud.
• Extensive Network and Network Security Deployment and Implementation utilizing Routers, Switches, NG Firewalls, VPNs, IDS/IPS Realtime Traffic Inspection/Analysis tools and Application/Service Analysis tools.
• Cloud Networking and Computing, Azure, AWS, Cloud frameworks, distributed applications and X-as-a-Service (X can be infrastructure, Platform, Software)
• Mastering OSI Model, TCP/IP protocol suite (IP, ARP, ICMP, TCP, UDP, SMTP, FTP, TFTP)
• Mastering IP v4 addressing and subnetting and routing concepts and skilled in IPv6
• Route/Switch Protocols and Services:
• L2 - STP, HSRP, VLAN, VPLS, Trunking, STP 802.1Q, VLANs, VTP, VPLS, L2 tunnels over MPLS
• L3 - OSPF, ISIS, BGP, EIGRP and IP MPLS, CEF, Route Redistribution, Summarization, Policy-Routing, Traffic Engineering, Inter AS VPN’s, MPLS VPN, MBGP, vPC, VSS, OTV, DMVPN, NHRP
• Route/Switch Products – Cisco, Nexus, ACI, HP Procurve, Brocade, Juniper, Cisco Catalyst, Cisco ASR, Cisco ISR, Arista, Cisco ACI, SDN (SD-LAN, SD-WAN, SD-WIRELESS), SDAm, Cisco Meraki, Viptela, Velocloud. (Emphasas on Viptella)
• Security Protocols and Services:
• Firewalls, VPNs (L2, L3, MPLS), Authentication (TACACS, AAA, PKI), 802.1x, NAC (Cisco ISE). Also, should have excellent implementation and troubleshooting skills for, L2/L3 VPN, IPSEC and SSL VPN, Cloud Proxy,
• Radius, RSA, PKI, 2 factor Authentication, Encryption, Remote access VPN, Clientless VPN and IPSec protocols, Web Proxies, DNS and DHCP design and IPAM tracking, IDS/IPS, Firewall Rules Management, Security Flow, NGFW, ClearPass, End Point Visibility, Authentication, End Point Blocking Policy Enforcement, PKI environments, Endpoint 802.1X, EAP supplicant methods and certificate integration. Firepower, Threat Protection,
• Security Vendors : Checkpoint, Juniper, Palo Alto and Cisco ASA, , Fortinet, Bluecoat, Macfee, Cisco ISE, F5, NetScaler, Zscaler, Symantec Proxy, Bluecoat, F5 LTM, A10
• Wireless – Aruba, Cisco
• Monitoring and Management Tools: Solarwinds, LiveAction, Riverbed, HP Openview, Cisco ISE, SNMP, Netflow, IPSLA, Netbrain, Lumeta, Algosec etc.
General Skills MANDATORY:
• Telecoms Industry knowledge with extensive experience in Networks and Telecommunications, Testing and Commissioning
• Knowledge of environmental and electrical safety in hazardous (IEC EX) that impact design of telecoms systems used in process plants; Upstream / Downstream IT infrastructure and telecom solutions e.g. Process Control/SCADA, Safety Critical Elements
• Knowledge of project delivery methodology for managing both IT and Capital Projects in Oil and Gas
• Consistently delivered results in a matrix, global virtualized organization
• Experience in negotiation skills
• Excellent communication skills, verbal and written
• Proven experience in stakeholder and relationship management including external vendors
• Ability to translate technical requirements and specifications into easily understood business concepts and vice versa
Skills PREFFERED:
• Technical network knowledge of telecom solutions such as Satellite, Optical/Radio links, Wireless Canopy, Mobile Radio (DMR/Tetra), Microwave, Fiber Optics, Marine and Aeronautical Radio, Sub-marine Fiber and Access Security/CCTV a plus.
• Cisco certifications – CCIE Route / Switch
• Palo Alto Certifications – PCNSE
• Zscaler Certifications – ZCCP IA/PA
• Python programming and app development skills for programmable networks
• Experience working in an (partially) outsourced environment
• Agile and waterfall project management knowledge and experience
• Service Management processes (Support Models, Service Level Management, Contract Management and Supplier Management)
• Experience in network operations
Shell
Het CV en de motivatie dienen aangeboden te worden in het Engels.
Het CV dient in een Word format aangeleverd te worden.
*Job Description
The digital transformation strategy of Shell requires an increasingly flexible, agile and secure IT environment in order to enable best use of data, cloud services, personalization of user experience and connectivity of devices. Keeping our business goals and user experience in the forefront, Shell IT has taken the decision to insource or directly procure several connectivity services. By taking greater control over key aspects of connectivity we can provide our users with better user experience, speed and agility, while maintaining operational effectiveness and efficiency. As a result, we are building a partially insourced and multi-vendor ecosystem for our connectivity products and services and will be developing new skills and capabilities. Come join us on this exciting and ambitious journey.
This role is part of Shell IT’s Connectivity Portfolio team and specific to the Network Perimeter services, where Shell and third-party users and applications need to be connected. Specifically, this role is critical in supporting projects with design engineering capabilities under the renewed model.
The design engineer is expected to be a Subject Matter Expert (SME) covering the application of telecommunications and network technology deployed across the Shell Group. This covers all Shell’s businesses, all Shell’s location (offices, onshore plants, offshore plants, offices, trading floors, etc.) and various types of projects including capital projects and IT projects.
The purpose of the design engineer role is to participate in projects and deliver the network designs and implementations required based on defined standards. The design engineer will be the key person in the project for all telecom and network elements.
The key Accountabilities are:
1. Collect all requirements needed to produce the design by working with the project manager and relevant stakeholders
2. Apply the standards defined to create a design with all relevant details
3. Document the solution working with the architects
4. Develop a deployment strategy together with the project manager and create an implementation plan which leads to a successful deployment of the produced design
5. Share knowledge and drive continuous improvement across the community
*Requirements
Accountabilities:
For the services in scope:
• Collect and document requirements by specifying the needed functionality, all the non-functional requirements and all dependencies (e.g. cabling, construction or electrical work needed)
• Create a Shell standards-based design produced and signed off by the design assurance team.
• Work with architecture & portfolio to update standards in specific cases
• Work with other designers to produce specific elements of the design requiring special knowledge
• Develop an implementation plan and testing strategy which is aligned with business readiness and IT delivery timelines
• Handover the design and implementation plan to the project manager and operations center for deployment and operations
• Share knowledge obtained and learn from others as part of a natural team across architecture, portfolio, design, network engineers, operations, and service management, amongst others.
• Provide hands on implementation and operational support as required.
People Dimensions:
• Number of direct reports: 0
• Number of indirect reports: 1-3 project resources plus any subcontractors delivering project resources.
Financial Dimensions:
• Directly managed budget: < $ 0
Business Dimensions:
• The position supports Shell projects at various locations ranging from offices to remote environments.
• Directly controls or indirectly influences:
• Network projects with value up to $1M
No direct reports but has responsibility to provide oversight of contract staff engaged to support project delivery.
Special Challenges
• Manage complex interface structures across organizational and geographic boundaries.
• Ability to collaborate with project teams, telecom contractors / service providers (ISP), the Major Execution Contractors (FEED, EPC, EPCM, TSI etc.) and other contractors
Technical Qualifications - MANDATORY:
Network security, we are looking for “design experience with next generation firewalls and proxies and more specifically Palo Alto Networks L7 firewalls and Zscaler”.
• Minimum Education or Certification: Bachelor’s degree in electrical engineering, Computer Science, Telecommunications or equivalent work experience
• Cisco certifications – CCNP Route / Switch
• Palo Alto Certifications – PCNSA
• Zscaler Certifications – ZCCP IA/PA TAC
• Security Certification - CCISP
• Typical Years of Experience: 12-20 - leading and executing Telecoms project delivery, Telecoms operations, or IT consultancy assignments to design, develop and deliver viable network and telecom solutions, preferably in Oil and Gas or similar industry with offshore experience preferred.
• A high degree of technical network knowledge in the IP network technology with a specialization in network security.
• Highly proficient in, deployment and configuration of networking technologies specific to routing, switching and general network security best practices in a global enterprise environment.
• Experience and proficiency in a hands-on capacity with Data Center and Remote Office Enterprise/campus designs, architecture, deployment and configuration with physical and virtual appliances. Familiarity with applications driving modern infrastructure design in private and public cloud.
• Extensive Network and Network Security Deployment and Implementation utilizing Routers, Switches, NG Firewalls, VPNs, IDS/IPS Realtime Traffic Inspection/Analysis tools and Application/Service Analysis tools.
• Cloud Networking and Computing, Azure, AWS, Cloud frameworks, distributed applications and X-as-a-Service (X can be infrastructure, Platform, Software)
• Mastering OSI Model, TCP/IP protocol suite (IP, ARP, ICMP, TCP, UDP, SMTP, FTP, TFTP)
• Mastering IP v4 addressing and subnetting and routing concepts and skilled in IPv6
• Route/Switch Protocols and Services:
• L2 - STP, HSRP, VLAN, VPLS, Trunking, STP 802.1Q, VLANs, VTP, VPLS, L2 tunnels over MPLS
• L3 - OSPF, ISIS, BGP, EIGRP and IP MPLS, CEF, Route Redistribution, Summarization, Policy-Routing, Traffic Engineering, Inter AS VPN’s, MPLS VPN, MBGP, vPC, VSS, OTV, DMVPN, NHRP
• Route/Switch Products – Cisco, Nexus, ACI, HP Procurve, Brocade, Juniper, Cisco Catalyst, Cisco ASR, Cisco ISR, Arista, Cisco ACI, SDN (SD-LAN, SD-WAN, SD-WIRELESS), SDAm, Cisco Meraki, Viptela, Velocloud. (Emphasas on Viptella)
• Security Protocols and Services:
• Firewalls, VPNs (L2, L3, MPLS), Authentication (TACACS, AAA, PKI), 802.1x, NAC (Cisco ISE). Also, should have excellent implementation and troubleshooting skills for, L2/L3 VPN, IPSEC and SSL VPN, Cloud Proxy,
• Radius, RSA, PKI, 2 factor Authentication, Encryption, Remote access VPN, Clientless VPN and IPSec protocols, Web Proxies, DNS and DHCP design and IPAM tracking, IDS/IPS, Firewall Rules Management, Security Flow, NGFW, ClearPass, End Point Visibility, Authentication, End Point Blocking Policy Enforcement, PKI environments, Endpoint 802.1X, EAP supplicant methods and certificate integration. Firepower, Threat Protection,
• Security Vendors : Checkpoint, Juniper, Palo Alto and Cisco ASA, , Fortinet, Bluecoat, Macfee, Cisco ISE, F5, NetScaler, Zscaler, Symantec Proxy, Bluecoat, F5 LTM, A10
• Wireless – Aruba, Cisco
• Monitoring and Management Tools: Solarwinds, LiveAction, Riverbed, HP Openview, Cisco ISE, SNMP, Netflow, IPSLA, Netbrain, Lumeta, Algosec etc.
General Skills MANDATORY:
• Telecoms Industry knowledge with extensive experience in Networks and Telecommunications, Testing and Commissioning
• Knowledge of environmental and electrical safety in hazardous (IEC EX) that impact design of telecoms systems used in process plants; Upstream / Downstream IT infrastructure and telecom solutions e.g. Process Control/SCADA, Safety Critical Elements
• Knowledge of project delivery methodology for managing both IT and Capital Projects in Oil and Gas
• Consistently delivered results in a matrix, global virtualized organization
• Experience in negotiation skills
• Excellent communication skills, verbal and written
• Proven experience in stakeholder and relationship management including external vendors
• Ability to translate technical requirements and specifications into easily understood business concepts and vice versa
Skills PREFFERED:
• Technical network knowledge of telecom solutions such as Satellite, Optical/Radio links, Wireless Canopy, Mobile Radio (DMR/Tetra), Microwave, Fiber Optics, Marine and Aeronautical Radio, Sub-marine Fiber and Access Security/CCTV a plus.
• Cisco certifications – CCIE Route / Switch
• Palo Alto Certifications – PCNSE
• Zscaler Certifications – ZCCP IA/PA
• Python programming and app development skills for programmable networks
• Experience working in an (partially) outsourced environment
• Agile and waterfall project management knowledge and experience
• Service Management processes (Support Models, Service Level Management, Contract Management and Supplier Management)
• Experience in network operations
Source
Voor deze opdracht dien je een bieding te plaatsen op Striive. Striive is het grootste opdrachtenplatform van de Benelux waar jaarlijks meer dan 20.000 opdrachten gepubliceerd worden.