Summary
✨ AI‑Generated
A cybersecurity engineer role focused on implementing Zero Trust principles, analyzing connected devices, improving network segmentation, and strengthening enterprise security controls.
Highlights
Opportunity to work on advanced cybersecurity initiatives involving network segmentation, security architecture, and enterprise technology environments.
Description
SEARGIN IS HIRING!
As a dynamic multinational tech company operating in 50 countries, we drive innovation and create projects that shape the future and greatly enhance the quality of life.
You will find our solutions in the space industry, supporting scientists in the development of cancer drugs, and implementing innovative technological solutions for industrial clients worldwide.
These are just some of the areas in which we operate!
Currently, for a new Seargin project we are looking for Network Security Engineer - Zero Trust and segmentation to take care of internal network segmentation.
Employment Type: contract
FTE: full-time
Working mode: hybrid from Poznań (minimum one day per week from the office)
Responsibilities:
Stage 1: Device and data analysis in Elisity
Review the devices in Phase 1 scope (printers, cameras, access control, UPS systems, environmental monitoring, legacy OEM endpoints) and confirm they have all been identified in ElisityVerify that devices are assigned to the correct Policy GroupsAnalyse device metadata (Identity Graph) against the PG matching criteriaTell which metadata changes are needed for devices to be admitted to the correct groups
Stage 2: Creating and deploying Policy Groups
Recommend the group structure, including when to split or merge groups so they are easier to administerCreate and deploy new Policy Groups in line with the naming standards and matching criteria provided by the clientEnsure new groups have no unwanted impact on existing policies, device categorisation or site configurations
Stage 3: Traffic analysis and segmentation policy recommendations
Analyse traffic flows from Elisity and, where appropriate, from Palo Alto firewallsEstablish what communication each device actually needs in order to operatePrepare policy recommendations that restrict device access on a least-privilege basis, balancing standardisation against riskSubmit the recommendations to the client for review and approval
Stage 4: Policy deployment, from simulation to production
Deploy approved policies in simulation mode, with no actual traffic blockingIdentify cases where a policy would block required traffic or leave excessive access openAdjust the policies accordinglyAfter an agreed period, move the policies from simulation mode to production, where traffic is actually blocked
Stage 5: Site-level validation
Produce evidence for each site that confirms correct device classificationConfirm Policy Group updatesConfirm that policy enforcement is effectiveConfirm change closure
Ongoing tasks throughout the project
Handle change management in ServiceNow: prepare change records, submit them to CAB, schedule implementation windows, track approvals, and document closure evidenceMaintain deployment records and provide regular progress updates in the agreed formatFollow the deployment playbook developed by GSK and Elisity.
The pilot and the first production wave run under close oversight from Elisity SMEsFlag any deviation from the playbook immediately and feed field observations back into playbook improvement
Requirements:
Creating PGs (Policy Groups)Hierarchy of PG matching criteriaElisity Identity Graph attributesConnector matchingAlignment of Identity Graph metadata attributes with PG matching criteriaElisity Identity GraphElisity Policy GroupsElisity segmentation policiesElisity Virtual Edge deploymentElisity flow analysis and troubleshootingCisco SwitchingJuniper SwitchingPalo Alto FirewallsPanoramaSecurity policy managementLog analysisServiceNow Incident ManagementServiceNow Change ManagementServiceNow Problem ManagementCAB processesService assets managementDeployment tracking and documentationZero Trust principlesOT/IoT segmentationTraffic-flow analysisLeast-privilege policy designSite validationChange implementationTroubleshootingTechnical documentationDeployment playbook adherence
Nice to Have:
Cisco DNACInfobloxThousandEyesNetFlow analysis
Discover the Power of IT Excellence.
Apply!
To learn more about Seargin, please visit our web page: www.seargin.com