Liberty Global is seeking a Network Security Specialist to help assure that its core and global tier-1 network has sound, industry best-practice security protection and that the security of these products and services is effectively monitored.
The role will work closely with Liberty Global core network architects, engineering and operational teams, and global security teams to identify improvements, drive network hygiene security initiatives, provide specialized skills in case of investigations, and translate security findings or deficiencies into clear security risks and advice on blocking issues and acceptable risk for the organization.
Job purpose
- Identify and drive improvements in network security on Liberty Global’s tier-1 core network.
- Identify and advise ISP networks to implement similar security measures and monitoring.
- Review and generate technical specifications and documentation.
- Translate, create, and hand over network monitoring use cases and threat playbooks to incident response teams.
- Act as a mentor, technical lead, and escalation point for other engineers.
- Monitor and respond to incidents.
Key accountabilities
- Serve as an authority on internet security-related topics such as network hygiene, MANRS, DDoS mitigation, BGP routing, and traffic analysis.
- Trace and identify sources of BGP hijacks, BGP leaks, DDoS, malware, or other abuse traffic.
- Review and update or improve security requirements set in policies and guidelines, ensuring these follow industry best practice.
- Identify potential areas of improvement and drive implementation.
- Liaise with the Global Security Operations Centre, Liberty Global and external operational teams, and other business units to set the right priorities for maximum effect.
- Work with and understand deliverables of external bodies such as M3AAWG, CableLabs, RIPE, and other security and standards organizations to assure Liberty Global networks and services follow industry best practice in security.
We tend to look for people with:
- Solid grasp of networking, security, and monitoring.
- Experience and expertise in securing and protecting large ISP networks.
- Familiarity with network hygiene measures such as BCP38/84 anti-spoofing protection, RPKI, other BGP routing BCPs, RIRs, internet routing registries, DNS/DNSSEC, and domain registration.
- Strong grasp of network security vulnerabilities and protections such as denial-of-service attacks and mitigation, BGP hijacking, CoPP, access-lists, Tacacs, and spam, malware, and abuse prevention.
- Experience presenting findings and making recommendations to other operational teams.
- Experience working with many collaborators to improve security and incident response, both internally and externally, in an international community.
- Demonstrated ability in an ISP environment and internet security arena.
- Experience with internet organizations such as RIRs and domain name registries, and tools such as whois/RDAP, RIPE RIS, BGP, and DNS monitoring.
- RIPE NCC certification (Database/BGP security) is a plus.
- Solid understanding of network security, security monitoring, and layers-of-defense principles.
Skills & abilities:
- Fluency in English (speaking and writing).
- Superb communication skills.
- Extensive knowledge or interest in at least four of the following areas: networking, TCP/IP, IPv4/IPv6, main services used by applications, BGP, RPKI, Control Plane Policing (CoPP), and DNS/DNSSEC.
- Knowledge of protection against DoS attacks, amplification factors, and mitigation techniques.
- Security analytics capabilities.
- Experience with monitoring and analytics solutions such as Arbor Threat Mitigation Suite, Splunk, Grafana, and Elastic Stack.
- Basic scripting, programming, or database skills.
- A great teammate, able to prioritise effectively and work independently well under pressure.
- Experience working with internal and external working groups to support improving network security and reduce the impact of denial-of-service attack factors or other service-disruptive activities in the company’s footprint.
Benefits
- 25 days annual leave with the option to purchase 5 more.
- Free access to LinkedIn Learning and Coursera to continue to develop and grow your career.
- Company pension contributions.
- Free premium subscription to Calm, a well-being and meditation app (NL only).
- Free public transport subscription for work and leisure travel on all modes of public transport anywhere in the Netherlands.
- Subsidy on health insurance premium.
- Company laptop, mobile, and phone subscription.