Configure and administer enterprise-grade firewalls (Checkpoint 3980) protecting the perimeter of each localized lab, defining strict ingress/egress filtering rules. * Switching & Segmentation:
Configure and administer enterprise-grade firewalls (Checkpoint 3980) protecting the perimeter of each localized lab, defining strict ingress/egress filtering rules. * Switching & Segmentation:
Configure and administer enterprise-grade firewalls (Checkpoint 3980) protecting the perimeter of each localized lab, defining strict ingress/egress filtering rules. * Switching & Segmentation:
Configure and administer enterprise-grade firewalls (Checkpoint 3980) protecting the perimeter of each localized lab, defining strict ingress/egress filtering rules. * Switching & Segmentation:
Monitor the health, performance, and uptime of all RDL hardware, including Checkpoint 3980 Firewalls, SilverPeak SD-WAN appliances, Cisco Catalyst 9400/9200 switches, and Celestica DS2000/ES1500 ...
Monitor the health, performance, and uptime of all RDL hardware, including Checkpoint 3980 Firewalls, SilverPeak SD-WAN appliances, Cisco Catalyst 9400/9200 switches, and Celestica DS2000/ES1500 ...
Monitor the health, performance, and uptime of all RDL hardware, including Checkpoint 3980 Firewalls, SilverPeak SD-WAN appliances, Cisco Catalyst 9400/9200 switches, and Celestica DS2000/ES1500 ...
Monitor the health, performance, and uptime of all RDL hardware, including Checkpoint 3980 Firewalls, SilverPeak SD-WAN appliances, Cisco Catalyst 9400/9200 switches, and Celestica DS2000/ES1500 ...
Monitor the health, performance, and uptime of all RDL hardware, including Checkpoint 3980 Firewalls, SilverPeak SD-WAN appliances, Cisco Catalyst 9400/9200 switches, and Celestica DS2000/ES1500 ...
Monitor the health, performance, and uptime of all RDL hardware, including Checkpoint 3980 Firewalls, SilverPeak SD-WAN appliances, Cisco Catalyst 9400/9200 switches, and Celestica DS2000/ES1500 ...
Expert in supporting Checkpoint/Solaris firewalls in a high-availability enterprise environment. Excellent customer service experience highly desired to fit culture. Strong Checkpoint, Solaris and ...
Expert in supporting Checkpoint/Solaris firewalls in a high-availability enterprise environment. Excellent customer service experience highly desired to fit culture. Strong Checkpoint, Solaris and ...
$55.75 - $73/hr
Mandatory Skills: Checkpoint, Fortinet, Palo Alto A bachelor's degree from an accredited ... Experience with firewall management tools and technologies such as, Panorama, Firemon, Prisma ...
$55.75 - $73/hr
Mandatory Skills: Checkpoint, Fortinet, Palo Alto A bachelor's degree from an accredited ... Experience with firewall management tools and technologies such as, Panorama, Firemon, Prisma ...
Security Analyst:
Houston, TX · On-site
Mandatory to have good hands-on experience in one or more skills on the below products & technologies Firewalls (Checkpoint, Palo Alto), McAfee SIEM 9.6, McAfee Web Gateway, McAfee Web Reporter ...
Security Analyst:
Houston, TX · On-site
Mandatory to have good hands-on experience in one or more skills on the below products & technologies Firewalls (Checkpoint, Palo Alto), McAfee SIEM 9.6, McAfee Web Gateway, McAfee Web Reporter ...
Sr. Network Security Engineer || Hybrid role || W2 Only (No OPT's please) ||
Houston, TX · On-site
$55.75 - $73/hr
Mandatory Skills: Checkpoint, Fortinet, Palo Alto • A bachelor's degree from an accredited ... Experience with firewall management tools and technologies such as, Panorama, Firemon, Prisma ...
Sr. Network Security Engineer || Hybrid role || W2 Only (No OPT's please) ||
Houston, TX · On-site
$55.75 - $73/hr
Mandatory Skills: Checkpoint, Fortinet, Palo Alto • A bachelor's degree from an accredited ... Experience with firewall management tools and technologies such as, Panorama, Firemon, Prisma ...
Network Security Engineer
Westlake, TX · On-site
$100K - $137K/yr
Automation w/Python 2 - 4 Years GitHub 2 - 4 Years Experience working with Fortinet, Checkpoint and ... Extensive experience with and knowledge of firewall and IPS technologies. Experience working with ...
Network Security Engineer
Westlake, TX · On-site
$100K - $137K/yr
Automation w/Python 2 - 4 Years GitHub 2 - 4 Years Experience working with Fortinet, Checkpoint and ... Extensive experience with and knowledge of firewall and IPS technologies. Experience working with ...
... supporting Checkpoint/Solaris firewalls in a high-availability enterprise environment • Strong Checkpoint, Solaris and Cisco network skills. * Change Management and implementation, including ...
... supporting Checkpoint/Solaris firewalls in a high-availability enterprise environment • Strong Checkpoint, Solaris and Cisco network skills. * Change Management and implementation, including ...
Firewalls VPN Authentication Encryption Penetration Analysis Intrusion Detection Expert in supporting Checkpoint/Solaris firewalls in a high-availability enterprise environment Strong Checkpoint ...
Firewalls VPN Authentication Encryption Penetration Analysis Intrusion Detection Expert in supporting Checkpoint/Solaris firewalls in a high-availability enterprise environment Strong Checkpoint ...
Network Security Engineer
$94K - $129K/yr
Palo Alto, Checkpoint, ASA, and PIX Firewall/VPN Configurations. * Knowledge and experience with routing protocols BGP, OSPF, EIGRP and IGRP. * Advanced OSI model knowledge including advanced layer ...
Network Security Engineer
$94K - $129K/yr
Palo Alto, Checkpoint, ASA, and PIX Firewall/VPN Configurations. * Knowledge and experience with routing protocols BGP, OSPF, EIGRP and IGRP. * Advanced OSI model knowledge including advanced layer ...
Rapid 7 Network Security Engineer
$99K - $136K/yr
... Checkpoint/Solaris firewalls in a high-availability enterprise environment. Strong Checkpoint, Solaris and Cisco network skills. We need: A Rapid 7 Nexpose administrator with the ability to provide ...
Rapid 7 Network Security Engineer
$99K - $136K/yr
... Checkpoint/Solaris firewalls in a high-availability enterprise environment. Strong Checkpoint, Solaris and Cisco network skills. We need: A Rapid 7 Nexpose administrator with the ability to provide ...
Managed Services Delivery Manager, Network Security
Dallas, TX · On-site
$103K - $141K/yr
Check Point firewall deployment and configuration experience * Check Point firewall IPSEC VPN deployment and configuration experience * Customer service focus required with strong interpersonal ...
Managed Services Delivery Manager, Network Security
Dallas, TX · On-site
$103K - $141K/yr
Check Point firewall deployment and configuration experience * Check Point firewall IPSEC VPN deployment and configuration experience * Customer service focus required with strong interpersonal ...
Network Security
$89K - $122K/yr
Experience in Firewall implementation (low level implementation) Cisco Pix/ASA ,Checkpoint, Juniper. * Experience in F5, and Netscaler Load Balancers. * Experience in managing ACS (TACACS/RADIUS)
Network Security
$89K - $122K/yr
Experience in Firewall implementation (low level implementation) Cisco Pix/ASA ,Checkpoint, Juniper. * Experience in F5, and Netscaler Load Balancers. * Experience in managing ACS (TACACS/RADIUS)
Command Center Engineer Level III
Plano, TX · On-site
$125K - $150K/yr
Implement network and security solutions (firewalls, VPNs, patching, etc.). * Collaborate with ... Strong networking background (Cisco, Juniper, F5, Aruba, CheckPoint). * Experience with VMware ...
Quick apply
Command Center Engineer Level III
Plano, TX · On-site
$125K - $150K/yr
Implement network and security solutions (firewalls, VPNs, patching, etc.). * Collaborate with ... Strong networking background (Cisco, Juniper, F5, Aruba, CheckPoint). * Experience with VMware ...
Senior Network Security Operations Analyst, Leander, TX
Leander, TX · On-site
$95K - $123K/yr
... firewall products from, Checkpoint, Palo Alto Networks, Fortinet and Cisco ASA Firewall; and experience in Virtual Private Network VPN technologies including B2B VPN and Remote Access VPN as well as ...
Senior Network Security Operations Analyst, Leander, TX
Leander, TX · On-site
$95K - $123K/yr
... firewall products from, Checkpoint, Palo Alto Networks, Fortinet and Cisco ASA Firewall; and experience in Virtual Private Network VPN technologies including B2B VPN and Remote Access VPN as well as ...
Strong experience administering and optimizing firewall platforms, including Juniper and Checkpoint, as well as associated management solutions. * Led or contributed to disaster recovery (DR ...
Strong experience administering and optimizing firewall platforms, including Juniper and Checkpoint, as well as associated management solutions. * Led or contributed to disaster recovery (DR ...
Strong experience administering and optimizing firewall platforms, including Juniper and Checkpoint, as well as associated management solutions. * Led or contributed to disaster recovery (DR ...
Strong experience administering and optimizing firewall platforms, including Juniper and Checkpoint, as well as associated management solutions. * Led or contributed to disaster recovery (DR ...
Checkpoint Firewall information
See Texas salary details
$9.41 - $15.27
7% of jobs
$15.27 - $21.13
1% of jobs
$21.13 - $27
0% of jobs
$27 - $32.86
3% of jobs
$32.86 - $38.72
4% of jobs
$43.26 is the 25th percentile. Wages below this are outliers.
$38.72 - $44.59
12% of jobs
$44.59 - $50.45
5% of jobs
The median wage is $52.74 / hr.
$50.45 - $56.31
44% of jobs
$56.31 - $62.18
12% of jobs
$62.18 - $68.04
11% of jobs
$68.04 - $73.91
1% of jobs
$9
$50
$73
How much do checkpoint firewall jobs pay per hour?
What is a Checkpoint Firewall job?
A Checkpoint Firewall job involves managing, configuring, and maintaining Check Point security appliances and software to protect an organization's network from cyber threats. Professionals in this role handle firewall policies, VPN configurations, threat prevention, and troubleshooting security incidents. They also monitor network traffic, apply security patches, and ensure compliance with cybersecurity best practices. Strong knowledge of Check Point technologies, networking protocols, and security principles is essential for this role.
What are the key skills and qualifications needed to thrive in the Checkpoint Firewall position, and why are they important?
To thrive in a Checkpoint Firewall role, you need strong knowledge of network security concepts, TCP/IP protocols, and hands-on experience with firewall administration, often supported by a degree in computer science or an IT-related field. Familiarity with Check Point Security Management, expert use of SmartConsole, and certifications such as CCSA or CCSE are typically expected. Analytical thinking, troubleshooting abilities, and clear communication skills are valuable soft skills for this position. These skills and qualifications are crucial in protecting organizational networks from security threats and ensuring seamless, secure connectivity.
What are some typical responsibilities for someone in a Checkpoint Firewall position?
As a Checkpoint Firewall professional, your main duties usually focus on configuring, managing, and monitoring firewall rules and policies to safeguard the organization’s network. You will routinely analyze security logs, respond to alerts, and perform network troubleshooting to address potential vulnerabilities or incidents. Collaboration with network engineers, system administrators, and security teams is a common aspect of the role, especially during network upgrades or security audits. Staying current with emerging threats and applying updates or patches to firewall systems are ongoing responsibilities in this fast-changing field.

Other
Posted 10 days ago
Job description
Req ID: 137432
Region: Americas
Country: USA
State/Province: Texas
City: Richardson
We are seeking a highly experienced and meticulous Lead Network & Security Architect to join the IT Support team for the Hardware Platform Solutions (HPS) group. In this role, you will take ownership of our global Research and Development Lab (RDL) reference architecture and drive its deployment, management, and scaling across all current and future HPS Design Centers (including Silicon Valley, Richardson, Thailand, and other global hubs).
The successful candidate will be responsible for implementing and maintaining a completely isolated, air-gapped network environment that operates independently of standard corporate IT networks. You will manage complex secure access paths, isolated VLAN provisioning, private full-mesh SD-WAN overlays, and a multi-tiered global data package replication and distribution system. You will also serve as the key enablement architect, helping project teams quickly spin up new project-specific instantiations of the RDL network model while adhering to strict security constraints.
1. Architectural Implementation & Governance
- Deploy Reference Architecture: Standardize and implement the RDL reference design across all global HPS design locations (San Jose, Richardson, Thailand, Shanghai, SongShan Lake, Penang, Chennai and future locations).
- Support New Instantiations: Act as the primary technical design authority to spin up new RDL network instances (allocating subnets, configuring dedicated VLANs, establishing local jump hosts, and defining user authentication parameters) for upcoming HPS design projects.
- Strict Constraint Enforcement: Maintain absolute isolation of the RDL environments. Ensure zero direct or indirect public internet connectivity and guarantee that out-of-scope systems or agents (e.g., CrowdStrike, Threat Locker, Big Fix, ServiceNow Agents, ClearPass NAC, and Windows Domain joins) are strictly excluded from the lab network.
2. Network Infrastructure & Security
- SD-WAN & Routing: Design, configure, and maintain the private, full-mesh SD-WAN overlay connecting global RDL sites.
- Secure Firewalling: Configure and administer enterprise-grade firewalls (Checkpoint 3980) protecting the perimeter of each localized lab, defining strict ingress/egress filtering rules.
- Switching & Segmentation: Manage core and access layer switches (Cisco Catalyst 9400/9200 series, Celestica DS2000, ES1500 switches) to segment the RDL into logical, multi-tenant VLAN environments-specifically separating Export Controlled and Non-Export Controlled network zones.
3. Identity and Remote Access Management
- Remote Customer Access: Oversee the implementation and administration of CyberArk vPAM (Virtual Privileged Access Management) for remote customer connections.
- Corporate Remote Access: Configure and maintain Zscaler ZTNA (Zero Trust Network Access) and App Connectors to terminate connections securely on Linux-based local jump hosts.
- Decentralized Authentication: Design and maintain a secure user management protocol on jump hosts and local RDL nodes. As the RDL operates without Windows Active Directory, you will define standard operating procedures for the manual/programmatic creation of local system accounts and localized role-based access control (RBAC).
4. Secure Data Package Management & DevOps Repo Architecture
- Repository Architecture: Maintain the multi-tier secure data distribution system:
- IT Repository Server: Internet-facing ingestion nodes (running on Hyper-V/Dell PowerEdge) to securely pull packages, drivers, and applications.
- Global Repository Server: The middle-layer relay that acts as a secure, scanned transit point between the corporate IT network and the isolated RDL network.
- RDL Local Repository Server: Localized instances inside the labs that pull from the Global Repo and host files locally over HTTP/HTTPS at /var/www/html/repo/.
- Workflow Automation: Ensure seamless, secure, programmatically validated transfer of "transfer bundles" containing operating system packages (Rocky, Ubuntu, CentOS, etc.) across the air gap.
- Security Scans & Compliance: Coordinate with corporate IT and security teams to execute periodic vulnerability scanning and patching of repository servers, ensuring all packages undergo integrity checks before reaching the inner RDL networks.
Required Technical Skills
- Hardware & OS Competencies: Hands-on experience with Checkpoint Firewalls (Checkpoint 3980 preferred), Cisco Catalyst 9400/9200 switches, and SilverPeak SD-WAN solutions.
- Security & Identity Tools: Expert-level understanding of CyberArk (PVWM/vPAM) and Zscaler ZTNA/Zscaler App Connectors.
- Virtualization & Systems: Solid administration experience in VMware vSphere Enterprise and/or Microsoft Hyper-V running on bare-metal systems (e.g., Dell PowerEdge R670).
- Linux Administration: Strong proficiency with Linux environments (Rocky Linux, Ubuntu, CentOS) for jump host configuration and secure HTTP/HTTPS local web repository servers (Nginx/Apache).
- Network Segmentation & Protocols: Expert in VLAN tagging, inter-VLAN routing, subnetting, IP address management (IPAM), and secure file transfer protocols.
- Automated Data Pipelines: Familiarity with script-based file synchronization and automated extraction/integrity validation mechanisms (e.g., hashing, checksums) for software deployment across isolated boundaries.
Strongly Preferred Certifications
- Checkpoint Certified Security Expert (CCSE) or Master (CCSM)
- Cisco Certified Network Professional (CCNP) - Enterprise or Security
- CyberArk Certified Defender or Sentry
- Certified Information Systems Security Professional (CISSP)
Soft Skills & Working Style
- Detailed Documentation: Proven track record of generating flawless High-Level Designs (HLD) and Low-Level Designs (LLD), block diagrams, and standard operating procedures (SOPs).
- Strategic Problem Solver: Comfortable working around strict operational boundaries where typical modern agents and automated tools are banned for security compliance.
- Cross-functional Partner: Ability to collaborate closely with HPS Design Engineers, Project Managers, Corporate IT Security, and external Customers.
- Financial Stewardship: Ability to work closely with procurement to specify, justify, and size bill of materials (BOM) for both upgrading existing sites and provisioning new infrastructure.
- Duties of this position are performed in a normal office environment.
- Duties may require extended periods of sitting and sustained visual concentration on a computer monitor or on numbers and other detailed data. Repetitive manual movements (e.g., data entry, using a computer mouse, using a calculator, etc.) are frequently required.
Bachelor's degree in Network Engineering, Computer Science, Cybersecurity, or a related technical field.
Minimum of 8+ years of experience in network architecture, with a heavy emphasis on securing air-gapped or highly isolated enterprise environments.
This job description is not intended to be an exhaustive list of all duties and responsibilities of the position. Employees are held accountable for all duties of the job. Job duties and the % of time identified for any function are subject to change at any time.
Celestica is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, status as a protected veteran, or any other protected category under applicable federal, state, and local laws.
This policy applies to hiring, promotion, discharge, pay, fringe benefits, job training, classification, referral and other aspects of employment and also states that retaliation against a person who files a charge of discrimination, participates in a discrimination proceeding, or otherwise opposes an unlawful employment practice will not be tolerated. All information will be kept confidential according to EEO guidelines.
Celestica is an E-Verify employer.
COMPANY OVERVIEW:
Celestica, Inc. (NYSE: CLS; TSX: CLS) is a technology leader dedicated to driving customer success and market advancements. With deep expertise in design, engineering, manufacturing, supply chain, and platform solutions, Celestica enables critical data center infrastructure for AI, cloud, and hybrid cloud and advances technologies in high-growth markets. With a talented team and a strategic global network, Celestica helps its customers achieve competitive advantages.
Today, Celestica delivers innovative supply chain solutions globally to customers in strategic two operating and reporting segments: Advanced Technology Solutions (ATS) and Connectivity and Cloud Solutions (CC):
ATS: This segment serves customers in complex, regulated and high-reliability markets such as Industrial & Smart Energy, Aerospace & Defense, Semiconductor Capital Equipment, and HealthTech. It is engineering led, with deep expertise in design, manufacturing and lifecycle solutions.
CCS: This segment focuses on high-performance technology solutions and services for the data center, serving hyperscalers, digital native customers and enterprises. Celestica's Platform Solutions offering provides innovative and customizable computing, storage and networking solutions enabling AI-driven growth.
Built on a legacy of trust and performance, Celestica has earned its reputation by delivering results in complex and fast-changing markets. Celestica exceeds customer expectations by identifying trends and staying ahead of the curve. Backed by comprehensive capabilities and a global network across North America, Europe and Asia, Celestica helps customers gain competitive advantage with the quality, flexibility and resiliency they need to respond quickly to shifts in demand. Guided by a bold vision to accelerate market advancements, Celestica delivers innovative solutions and technologies that turn complexity into opportunity. Anchored in teamwork and commitment, Celestica strives to be the most trusted partner to its customers and colleagues worldwide.
Celestica would like to thank all applicants, however, only qualified applicants will be contacted.
Celestica does not accept unsolicited resumes from recruitment agencies or fee based recruitment services.