Senior Network Security Engineer positions focus on delivering results in their domain. This page aggregates open Senior Network Security Engineer roles and what employers typically expect.
About Lantern Lantern is the specialty care platform connecting people with the best care when they need it most. By curating a Network of Excellence comprised of the nation's top specialists for surgery, cancer care, infusions and more, Lantern delivers excellent care with significant cost savings to employers and their workforces. Lantern also pairs members with a dedicated care team, including Care Advocates and nurses, for the entirety of their care journey, helping them get back to good health, back to their families and back to work. With convenient access to specialists nationwide, Lantern means quality care is within driving distance for most. Lantern is trusted by the nation's largest employers to deliver care to more than 6 million members across the country. Learn more about us at lanterncare.com. Lantern is looking for a Sr. Network Security Engineer to join our fast-growing team. You will design, implement, and defend the network security architecture protecting our members’ healthcare data across on-premises, Azure, and edge environments. As the senior network security engineer on the Security Engineering & Operations team, you will own our Fortinet security fabric and Zero Trust network access architecture, drive automation of network security operations, and provide technical leadership across firewall, VPN, segmentation, and cloud network security domains. This role operates in a HIPAA, HITRUST CSF, and SOC 2 regulated environment and requires deep hands-on expertise, strong judgment, and effective collaboration with IT, cloud, and GRC partners. Location: Hybrid - at least 3 days/wk in our Dallas office located at 2100 Ross Avenue, Dallas, Texas 75201 Responsibilities: Design, implement, and manage secure network infrastructure across on-prem and Azure hybrid environments, including routing, switching, firewalls, VPN, and network segmentation. Own and operate the Fortinet security fabric: FortiGate firewalls, FortiManager, FortiAnalyzer, FortiClient EMS, FortiSwitch/FortiAP, and SD-WAN, including lifecycle upgrades and vulnerability remediation against CISA KEV and vendor advisories. Advance our Zero Trust architecture: design and operate ZTNA/SASE controls, identity-aware access policies, and micro segmentation to reduce reliance on perimeter and legacy VPN access. Maintain and continuously optimize firewall rule sets, NAT policies, IPS/IDS, and IPsec/SSL VPN configurations through regular audits, rule hygiene, and hardening against benchmark baselines. Engineer Azure network security controls: NSGs, Azure Firewall, VPN/ExpressRoute gateways. Automate network security operations using infrastructure-as-code and scripting (Terraform, Ansible, Python, PowerShell, REST APIs) to eliminate manual, error-prone changes. Monitor network traffic and detections (NDR, SIEM), tune signals and IOCs with a metrics-driven mindset, and lead network-layer incident response and root-cause analysis. Secure emerging traffic patterns, including AI agent and API traffic, in partnership with our AI governance and threat detection programs. Partner with IT, cloud, and platform teams on secure-by-design integration of network and system components; support audit and compliance evidence requests (HIPAA, HITRUST CSF, SOC 2). Produce and maintain high-quality documentation: network diagrams, configuration standards, and standard operating procedures. Mentor engineers on the team and contribute to on-call and change management processes. Requirements: 7+ years in network and/or security engineering roles with increasing scope and ownership. 5+ years of hands-on experience with Fortinet solutions (FortiGate, FortiManager, FortiAnalyzer, EMS, SD-WAN) and FortiCloud services. 5+ years of Azure networking and security experience in hybrid environments. Practical experience designing or operating Zero Trust / ZTNA / SASE architectures (e.g., Cloudflare Zero Trust, Zscaler, or equivalent). Experience with an NDR platform (e.g., Darktrace, Ext…