Network Security Specialist

CMA CGMMontreal, QC
Onsite

About The Position

CMA CGM Montreal is looking for a Network Security Specialist to join the GLOBAL CYBERSECURITY Team. Candidates must be legally authorized to work in Canada. As a Network Security Specialist, you will be responsible for all solutions owned by Network Security, performing operational tasks and following best industry practices. This role involves configuration and maintenance of various network security solutions, including firewalls, load balancers, and proxy solutions, as well as DNS management, PKI/SSL certificate administration, and DDoS protection. You will also be responsible for staying updated on firmware vulnerabilities, assisting with security incidents, participating in projects, performing log investigations, and creating documentation. The position requires a Bachelor's degree in IT, Computer Science, Computer Engineering, or a related field, with at least 3-5 years of related experience. Strong knowledge of firewalls, VPN technologies, load balancers, proxies, and ZTNA is essential, along with a solid foundation in networking. Basic knowledge of DNS, PKI, and DDoS protection is also required. Preferred qualifications include experience with security management tools, Linux administration, scripting, and relevant certifications. The ideal candidate will have strong work ethic, excellent interpersonal and communication skills, be a team player, result-oriented, willing to work a shifting schedule, and fluent in English and French.

Requirements

  • Candidates must be legally authorized to work in Canada: valid work permit, permanent resident or citizen.
  • Bachelor's degree in IT, Computer Science, Computer Engineering, or related field.
  • At least 3-5 years of related experience.
  • Strong knowledge and experience on Firewalls (Cisco ASA, Palo Alto, Checkpoint).
  • Strong knowledge and experience on VPN Technologies (IPSEC S2S/Client SSL).
  • Strong knowledge and experience on Load balancers (F5 or Citrix ADC).
  • Strong knowledge and experience on Proxies (open source such as Squid, SOCKS, and FTP proxies; Cloud based proxy solutions – Zscaler ZIA).
  • Strong knowledge and experience on Zero Trust Network Access (ZTNA – Zscaler ZPA).
  • Strong foundation on Networking (routing and switching).
  • Basic knowledge and experience on DNS administration and PKI.
  • Basic knowledge of Distributed Denial of Service (DDoS) Protection.
  • Strong work ethic, professional integrity and the ability to apply the appropriate level of judgement and maturity.
  • Excellent interpersonal skills, and a strong ability to communicate, team player, and result oriented.
  • Willing to work on shifting schedule.
  • Fluent in English & French.

Nice To Haves

  • Security management tools such as Firemon, AlgoSec, Tuffin, or Red Seal.
  • Linux administration.
  • Scripting tools such as shell or Python.
  • Relevant certifications (CCNP Sec, PCNSE, etc.)
  • Knowledge in NAC appliances (Cisco ISE)

Responsibilities

  • Configuration and maintenance of firewall platforms (Cisco ASA, Palo Alto, Checkpoint, Fortinet), including creation/modification of objects and policies, establishing secured external connectivity with VPN technologies, and configuration/operation of firewall auxiliaries.
  • Configuration and maintenance of load balancers (Citrix ADC formerly known as Netscaler), including creation/modification and health checks of load balanced services, monitors, virtual servers, content switching, and ADC gateways; defining rewrites and responders; and SSL certificate installations and maintenance.
  • Configuration and maintenance of proxy solutions (local open source - Squid, SOCKS, FTP proxy; cloud - Zscaler), including creation/modification of security policies, whitelisting/blacklisting URL and IP addresses, maintenance of user internet access policies, troubleshooting proxy-related internet connectivity issues, Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) operations, and producing web usage reports.
  • DNS management (zones, records, GeoDNS, etc.)
  • PKI / SSL certificates administration.
  • Distributed Denial of Service Protection (DDoS) management.
  • Keeping up to date with information regarding firmware security vulnerabilities and bugs and ensuring firmware of security devices are secured and updated.
  • Working side by side with Cybersecurity to help with incidents.
  • Involvement in projects outside of daily operations to help with developments on technological solutions.
  • Log investigation, debugging, and packet captures.
  • Producing capacity planning reports.
  • Daily health checks for devices and services.
  • Making sure device inventory is updated and within standards.
  • Creating documents such as SOP or basic network diagram and ability to suggest improvements in the policies and processes.
  • License renewals and hardware refresh or replacements of devices.
  • Other responsibilities as required.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service