Engineering

Network & Security Engineer At Creastech Limited

Creastech Limited·Lagos, nigeria·Full Time·Contract
EngineeringFull TimeContract
-

About the Role

  • We are looking for a skilled and proactive Network & Security Engineer to join our team.
  • The successful candidate will be responsible for designing, implementing, maintaining, and securing the company's network infrastructure while ensuring reliable connectivity and protection of IT systems.

Key Responsibilities

  • Design, configure, maintain, and troubleshoot LAN/WAN and network infrastructure.
  • Monitor network performance and resolve connectivity and network-related issues.
  • Configure and manage routers, switches, firewalls, access points, and other network devices.
  • Implement and maintain network security controls, including firewalls, VPNs, access controls, and endpoint security measures.
  • Monitor networks for security threats, vulnerabilities, and unusual activities.
  • Perform network and security assessments and recommend improvements.
  • Manage user access, network permissions, and security configurations.
  • Maintain accurate documentation of network infrastructure, configurations, and security procedures.
  • Respond to network outages, security incidents, and other technical issues promptly.
  • Carry out regular system updates, patches, backups, and preventive maintenance.
  • Work with other technical teams to implement and support IT infrastructure projects.
  • Stay updated on emerging networking technologies, cybersecurity threats, and best practices.

Requirements

  • Bachelor's Degree / HND in Computer Science, Information Technology, Cybersecurity, or a related field.
  • 2 - 4 years of relevant experience in network administration, network engineering, or cybersecurity.
  • Strong knowledge of networking concepts, including TCP/IP, DNS, DHCP, VLANs, VPNs, routing, and switching.
  • Experience configuring and troubleshooting routers, switches, firewalls, and wireless networks.
  • Knowledge of network security principles and cybersecurity best practices.
  • Experience with network monitoring and troubleshooting tools.
  • Strong problem-solving and analytical skills.
  • Good communication and documentation skills.
  • Ability to work independently and as part of a team.

Certifications:

  • Relevant certifications such as CCNA, CCNP, CompTIA Security+, Fortinet, or equivalent certifications will be an advantage.

Key skills

BA/BSc/HND
Apply Now
Send your CV along with a cover letter tohr@creastech.com

Please use the job title as the subject line of your email.

At a glance

Company

Creastech Limited

Location

Lagos, nigeria

Employment

Full Time

Work style

Contract

Experience

Valid until

Not specified

Created

September 29, 2026

More opportunities

Similar roles you might like

Senior Network & Security Engineer At Heirs Holdings

Heirs Holdings

Lagos, nigeria

full-time

The Role As Senior Network & Security Engineer, you will design, build, and operate the network and security architecture that keeps this platform private, resilient, and impenetrable. You will own the platform's private cloud networking, zero-trust enforcement, perimeter security controls, and network-level threat monitoring working closely with the Platform Manager and Platform Manager (Security) to ensure that every layer of the network is hardened, observable, and compliant. On a banking platform built for continental scale, the network is the first line of defence and you own it. What You'll Do Network Architecture Design and own the platform's end-to-end network architecture defining the topology, segmentation model, and connectivity principles that govern how AWS, Azure, and on-premises environments interrelate and how traffic flows securely across all of them. Translate architectural decisions into a clean, scalable IP addressing strategy: plan and allocate CIDR blocks across both clouds with no overlapping ranges, room to grow, and dedicated subnets for containers, servers, storage, and management. Front and backend assets must be cleanly separated at the network layer. No internal service is ever publicly addressable. All architecture decisions must be documented, reviewed as the platform scales, and reflected in version-controlled infrastructure code. Network Engineering Own the hands-on engineering and operation of the platform's network infrastructure across cloud and on-premises environments including routing configuration, switching, firewall policy management, VPN setup, and on-premises edge device configuration (FortiGate, Cisco Nexus 9000). All network infrastructure must be written as clean, well-structured, and peer-reviewed code using Terraform, Ansible, and Bash covering VNets, subnets, NSGs, routing rules, firewall policies, and VPN gateways. All configurations must be version-controlled and stored in the central repository. No network change may ever be applied manually to any environment. Integrate network security checks into CI/CD pipelines and work with DevSecOps engineers to ensure no environment is ever provisioned with misconfigured or insecure network settings. Zero Trust Enforcement Implement and enforce zero-trust principles across the entire platform no implicit trust anywhere. Every request must be authenticated, authorised, and logged. Every network path must be explicitly permitted; everything else is denied by default. Continuously identify and close trust gaps across all environments. Perimeter & Firewall Security Own and operate the platform's security boundaries from the outermost perimeter to internal network segmentation. Externally: the only permitted internet entry point is Cloudflare DDoS protection WAF API Gateway; ensure DDoS rules, WAF policies, and API Gateway configurations are current, tested, and enforced as code. Internally: own all firewall and NSG rules across cloud and on-premises environments all policies must be defined exclusively via Infrastructure as Code, version-controlled, and subject to regular rule reviews to eliminate unnecessary access paths and enforce least-privilege networking. No manual firewall or NSG change is ever permitted. Cloud Network Security & Encryption Configure and maintain cloud-native network security controls across AWS and Azure including Security Groups, Network ACLs, AWS Network Firewall, and Azure Firewall. Ensure no cloud storage, database, or service is ever inadvertently exposed to the public internet. Enforce TLS 1.2+ across all services and connections in transit TLS 1.0 and 1.1 are prohibited. Own the certificate lifecycle provisioning, renewal, rotation, and revocation ensuring no expired or weak certificate ever reaches production. Hybrid & Site-to-Site Connectivity Design, implement, and maintain highly available, redundant connectivity between the platform's cloud environments and on-premises data centres using AWS Direct Connect, Azure ExpressRoute, and IPSec VPN Gateways as appropriate. Ensure failover paths are in place, tested, and documented so that loss of any single link does not interrupt connectivity to core banking systems. All site-to-site links must be encrypted, monitored, and governed as code. VPN & Admin Access Controls Design and operate the platform's JumpNet and VPN infrastructure the only permitted route for admin access to production environments. No exceptions. Enforce MFA on all VPN access and ensure all privileged sessions are logged and monitored. Global Traffic Management Design and operate the platform's global traffic management layer ensuring user traffic is intelligently distributed across AWS and Azure based on latency, availability, and health. Implement and maintain AWS Route 53 / Global Accelerator and Azure Traffic Manager / Front Door to route users seamlessly between clouds, with automatic failover when either environment degrades. Ensure no single cloud environment is a single point of failure for end-user traffic. Threat Detection & Network Monitoring Design, implement, and operate the platform's centralised network monitoring and threat detection infrastructure providing real-time visibility into device health, link utilisation, traffic flows, and anomalies across both cloud and on-premises environments. Working closely with the Platform Manager and Platform Manager (Security), implement IDS/IPS, anomaly detection, and traffic analysis tooling. Ensure all network telemetry feeds into the SIEM with alerting tuned for abnormal traffic volumes, lateral movement, port scanning, unauthorised connections, and attempts to bypass network controls or disable logging. No network event goes undetected or unacted upon. Incident Response Act as the first responder for network-level security incidents including containment, isolation, forensic evidence preservation, and root cause analysis. Contribute to the platform's Incident Response Plan and ensure network runbooks are documented, tested, and current. Documentation & Asset Management Maintain accurate, up-to-date network design documentation at all times. Own a centralised, version-controlled inventory of all core network assets including device configurations, IP allocations, CIDR assignments, VLAN maps, and topology diagrams. All infrastructure code and key network documentation must live in a central, secure, version-controlled repository always current, always accessible, and ready for audit or incident response at any time. What We're Looking For Must Have 5+ years of hands-on network and security engineering experience in a cloud-native production environment with demonstrated ownership of private network architecture, zero-trust implementation, and perimeter security at scale. Expert-level knowledge of cloud networking on AWS and/or Azure VNets, subnets, NSGs, Security Groups, Network ACLs, private endpoints, private DNS, VPN Gateways, and Transit Gateways. Hands-on experience with perimeter security tooling Cloudflare (DDoS, WAF), API Gateway configuration (Kong or equivalent), and web application firewall rule management. Strong working knowledge of zero-trust architecture identity-aware proxies, microsegmentation, least-privilege network access, and continuous verification principles. Proven experience with network threat detection and monitoring IDS/IPS, SIEM integration, anomaly detection, and network forensics. Expert-level knowledge of routing and switching protocols BGP, OSPF, EIGRP, spanning tree, and VLAN trunking and firewall and security concepts at depth. This is non-negotiable given the complexity of the platform's hybrid connectivity, site-to-site tunnels, and on-premises edge device configuration requirements. Hands-on experience configuring and managing enterprise firewall and core switching platforms specifically Fortinet FortiGate and Cisco Nexus 9000 series. The platform's on-premises core network runs these devices and this engineer will be expected to configure and manage them directly. Solid Infrastructure as Code skills Terraform, Ansible, and Bash with a clear understanding that all network security controls must be version-controlled and never manually provisioned. Active CCNP Security or CCNP Enterprise certification or a recognised equivalent. Professional-level routing, switching, and security credentials are required given the hybrid connectivity and on-premises edge responsibilities of this role. Nice to Have Fortinet NSE 4 or NSE 5 certification relevant given the FortiGate firewall estate. AWS Certified Security - Specialty and/or Microsoft Certified: Azure Network Engineer Associate (AZ-700). Experience with container network security Kubernetes network policies, service mesh (Istio or equivalent), and east-west traffic control. Hands-on experience with network security in regulated financial services environments PCI DSS network segmentation requirements, CBN guidelines, or equivalent. Familiarity with SIEM platforms (Splunk, Microsoft Sentinel, or equivalent) and experience writing detection rules or correlation queries for network-based threats.

3 months ago

Network & Security Engineer At It Horizons Limited

IT Horizons Limited

Lagos, nigeria

full-time

Summary As the Network & Security Engineer, you will be responsible for the design, implementation, maintenance, and support of the organization's network, security, voice, and server infrastructure. This role requires a hands-on professional capable of designing, implementing, and troubleshooting across multiple technology domains while ensuring the availability, security, and optimal performance of critical business systems. The role also includes managing and optimizing both on-premises and cloud-based networks, developing and enforcing network security protocols, and proactively troubleshooting and resolving network-related issues. Responsibilities Proactively scopes the technical solution required to address customer requirements, assesses customers' met and unmet needs, and recommends solutions that optimize value for both the customer and the firm. Oversee and execute planned enterprise network and security infrastructure maintenance activities while minimizing impact to services. Provide technical leadership on operational and project-related work. Design and implement plans to introduce new technology into the security and enterprise networks while minimizing network outages and ensuring a seamless end-user experience. Conduct a thorough analysis of service results and respond to any escalated service delivery issues in a timely manner. Design solutions and create implementation and support models for technology encompassing a specific specialization or platform. Configure, install, support, and troubleshoot security and enterprise network equipment Work effectively with other IS teams and outsourcing provider(s) to ensure technology solutions are effectively managed and performed Review reports to ensure all services are completely and successfully delivered. Proactively intervene to correct problems when they are encountered. Use metrics to improve processes. Assist in the development of network security and enterprise network operations processes, procedures, and documentation. Develop and maintain strong relationships with internal and external stakeholders to ensure optimal service delivery in the customer environment. Establishing the customer environment by designing system configurations, directing system installation, defining, documenting, and enforcing industry standards Analyzing existing network security and enterprise network infrastructure to proffer solutions for optimal performance of the customer network and security infrastructure Developing architecture plans for network security and enterprise network solutions and deployments. Deploy Enterprise network security solutions, including multi-vendor firewalls, network access control (NAC) devices, endpoint security solutions, etc Support and maintain customer network and security infrastructure, including routers, switches, firewalls, Network access control, and endpoint security solutions Provide L2/L3 escalation support for critical incidents. Documenting the customer enterprise network and security infrastructure to ensure accurate and up-to-date records of the network inventory and design, following every deployment or change. Collaborate with sales and pre-sales teams to drive technical engagements and deliver Proof of Value (POV) sessions for both existing and prospective customers. Certifications Must have CCNP certification Skills required: Strong understanding of routing and switching protocols. Protocols: EIGRP, OSPF, RIPv2, IS-IS, BGP, MPLS, IPSec, HSRP, GLBP, VRRP, VSS, VPc, Firewalls, and other security solutions.

5 months ago