1

Overnight Network Firewall Engineer Jobs in San Rafael, CA

Senior Network Engineer

Brisbane, CA · On-site

$156K - $200K/yr

A minimum of 5 years Network Engineering experience ... A minimum of 3 years Firewall security experience. * A minimum of 3 years experience with ...

Senior Network Engineer

Brisbane, CA · Hybrid

$156K - $200K/yr

A minimum of 5 years Network Engineering experience ... A minimum of 3 years Firewall security experience. * A minimum of 3 years experience with ...

SUMMARY OF POSITION The Network Engineer is responsible for maintaining, monitoring, and ... Firewall Management: * Design, deploy, configure, and maintain Palo Alto and Fortinet firewalls to ...

... network engineers use products. You know the difficulties managing firewall policies across ... thousands of devices in critical environments. But more than domain knowledge, what makes someone ...

Sr, Network Engineer

Alameda, CA · On-site

$117K - $161K/yr

Alameda CA Duration: 6 months 100% ONSITE ROLE- LOCAL CANDIDATES PREFERRED Sr, Network Engineer- 2 positions - 10+ years of experience in operations and managing Network devices, firewalls ...

Network Security Engineer

San Rafael, CA · On-site

$116K - $159K/yr

ClifyX is a company seeking a Network Security Engineer with expertise in Palo Alto PRISMA and Next ... The role involves serving as a subject matter expert, managing firewall technologies, and ensuring ...

Senior Network Engineer

Emeryville, CA · Hybrid

$120K - $164K/yr

This role is a standard network engineering role with concentration on LAN/WAN and Security ... Cisco switch, router and firewall maintenance, upgrades, configuration, and deployment. * Develop ...

Network Engineer

San Francisco, CA · On-site

$293K - $385K/yr

About the Team OpenAI's Network Engineering team within IT and Security advances the mission of ... Implement and operate routing, switching, wireless, WAN, Internet edge, firewall, NAC, segmentation ...

next page

Showing results 1-20

Overnight Network Firewall Engineer information

See San Rafael, CA salary details

$36

$61

$85

How much do overnight network firewall engineer jobs pay per hour?

As of Sep 5, 2026, the average hourly pay for overnight network firewall engineer in San Rafael, CA is $61.99, according to ZipRecruiter salary data. Most workers in this role earn between $50.91 and $73.70 per hour, depending on experience, location, and employer.

What does an overnight network firewall engineer do?

An Overnight Network Firewall Engineer is responsible for monitoring, managing, and maintaining an organization’s firewall infrastructure during overnight hours. Their primary duties include responding to security alerts, configuring firewall rules, troubleshooting connectivity issues, and ensuring that unauthorized access attempts are detected and blocked. Working overnight helps provide continuous network protection and allows for system maintenance or updates during off-peak hours, minimizing disruptions to business operations.

What are the key skills and qualifications needed to thrive as an overnight network firewall engineer?

To thrive as an Overnight Network Firewall Engineer, you need strong knowledge of network protocols, firewall configurations, and security best practices, often supported by a degree in IT or cybersecurity and relevant certifications like Cisco CCNP Security or Fortinet NSE. Familiarity with tools such as Palo Alto, Cisco ASA, FortiGate firewalls, and network monitoring systems is typically required. Attention to detail, problem-solving abilities, and effective communication are vital soft skills, especially for troubleshooting and documenting incidents during off-hours. These skills ensure the network's security, minimize downtime, and support 24/7 business operations.

What are the unique challenges faced by overnight network firewall engineers, and how can they prepare for them?

Overnight Network Firewall Engineers often encounter the challenge of handling critical incidents with limited immediate support, as many teams operate with reduced staff during off-hours. They are responsible for monitoring, troubleshooting, and resolving firewall issues to ensure uninterrupted network security, which may require quick decision-making and strong problem-solving skills. Preparing for these challenges involves developing a deep understanding of firewall technologies, maintaining clear documentation, and leveraging automated monitoring tools. Effective communication with other teams and leaving detailed handovers for the daytime shift also help ensure seamless operations.

What is the difference between Overnight Network Firewall Engineer vs Network Security Analyst?

AspectOvernight Network Firewall EngineerNetwork Security Analyst
CertificationsCCNA, CISSP, CompTIA Security+CISSP, CompTIA Security+, CEH
Work Environment24/7 network operations, overnight shifts, technical troubleshootingMonitoring security systems, analyzing threats, policy development
Employer & Industry UsageIT departments, cybersecurity firms, telecom companiesFinancial institutions, government agencies, corporate security teams

The Overnight Network Firewall Engineer primarily focuses on configuring, maintaining, and troubleshooting firewalls during overnight shifts, ensuring network security and uptime. In contrast, the Network Security Analyst monitors security alerts, analyzes threats, and develops security policies. While both roles require similar certifications and work in cybersecurity environments, their daily tasks and focus areas differ, with the engineer more hands-on with firewall management and the analyst more involved in threat analysis and security strategy.

Security Engineer - Cloud and Network Security

Gusto, Inc.

San Francisco, CA • On-site

$230K - $270K/yr

Full-time

Re-posted 28 days ago


Gusto rating

8.0

Company rating: 8.0 out of 10

Based on 18 frontline employees who took The Breakroom Quiz


Job description

About the Role:

We're looking for a Security Engineer to lead Gusto's edge and network security strategy, owning the design and operation of our Cloudflare WAF, DDoS protection, Zero Trust, and broader perimeter controls. The ideal candidate brings deep, hands-on Cloudflare expertise and a proven track record of hardening edge and network architectures at scale, including tuning WAF rulesets, defending through live DDoS events, and shipping Zero Trust rollouts engineers actually adopt. You think in terms of layered defense, measurable risk reduction, and automation over manual toil. In this role, you'll serve as a force multiplier across the security org, partnering with infrastructure and product teams to make high-impact architectural decisions that compound over time.

About the Team:

The Gusto's Enterprise Security Engineering team, a small but high-leverage group responsible for cloud security posture, edge and network defense, container security, secrets management, and endpoint protection across the company. The team runs a modern stack including Cloudflare, Wiz, CrowdStrike, Panther, and Tines, scaling impact through automation, IaC, and AI-augmented tooling. The work carries real stakes, protecting the payroll, benefits, and HR systems that hundreds of thousands of small businesses and their employees rely on every day. The team is engineering-first, with most of the roadmap living in code and a strong emphasis on partnering with infrastructure and product teams rather than gatekeeping them.

Here's what you'll do day-to-day:

  • Design and operate Gusto's edge security stack including Cloudflare WAF, DDoS protection, Bot Management, WARP, Gateway, and Access, tuning rules against real traffic and shaping how engineers and operations teams reach internal systems securely.
  • Own the network security perimeter across AWS and the edge: VPC design, Network Firewall, Shield, CloudFront, NACLs, and egress filtering, all codified in Terraform and Crossplane, observable, and consistently enforced.
  • Develop policy-as-code patterns for WAF rules, network policies, and edge configuration so changes ship through pull requests with review, testing, and clean rollback paths.
  • Build detections and alerting on edge and network telemetry including Cloudflare logs, VPC Flow Logs, and CloudTrail flowing into Panther, and lead incident response for perimeter and network events.
  • Contribute broadly across the security engineering surface including cloud posture, container security, IAM, vulnerability management, and on-call, bringing a strong generalist instinct to wherever the work is most critical.
  • Operate as an AI-native engineer, using Claude Code, MCP-driven tooling, and agentic workflows as a daily force multiplier across investigation, automation, and detection engineering.
  • Prototype and ship agents, custom MCP servers, and LLM-assisted automations that compress security work from days to minutes and raise the bar for what one engineer can own.

Here's what we're looking for:

  • 10+ years of hands-on security engineering experience, with significant time owning edge, network, or perimeter security at scale.
  • Deep, production-grade expertise with Cloudflare's security stack including WAF, DDoS, Bot Management, WARP, Gateway, and Access, covering rule tuning, incident response, and Zero Trust rollouts.
  • Strong network architecture skills across edge and cloud: TLS/mTLS, segmentation, egress controls, DDoS resilience, and AWS networking including VPC, Network Firewall, Shield, CloudFront, and NACLs.
  • Fluency with policy-as-code, Terraform, and CI/CD-first delivery of security controls; Crossplane or similar a plus.
  • Solid generalist foundation across cloud security, IAM, container security, and detection engineering, with hands-on incident response experience on edge and network telemetry in a modern SIEM.
  • AI-native working style with daily use of Claude Code or equivalent agentic tooling, and a track record of building AI-assisted workflows including custom MCP servers, agents, and LLM automations that compound team output.
  • Excellent written and verbal communication; you can take a complex perimeter decision and explain the tradeoffs to a staff engineer, a PM, and a VP without changing the substance.
  • Relevant certifications a plus including AWS Certified Advanced Networking Specialty, AWS Certified Security Specialty, Cloudflare Certified Security Associate/Professional, CKS, or equivalent.

Our cash compensation amount for this role is targeted at $210,000/yr to $230,000/yr in Denver & most remote locations, $230,000/yr to $270,000/yr for San Francisco, New York & Seattle. Stock equity is additional. Final offer amounts are determined by multiple factors including candidate experience and expertise and may vary from the amounts listed above.


What Gusto employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom