About the Role
As a Network Security Specialist, you will help design, implement, and govern network security controls for a modern, high-performance enterprise network. You will shape the network security roadmap, define security policies, and drive the adoption of Zero Trust and micro-segmentation. Working within the Connectivity Engineering Team, you will collaborate with Information Security, Platform, Infrastructure, and Application teams to embed security by design across on-premises, cloud, and containerized environments. You will also support LAN, WAN, Campus, and Data Centre network services, ensuring reliability, resilience, and high performance. This role involves maintaining and developing core network standards, coordinating network activities, contributing technical expertise, and producing high- and low-level designs. As a subject matter expert, you will provide 3rd-line escalation support. This role reports to the Network Manager and may include participation in an on-call rota, with occasional evening and weekend work. TOIL or overtime compensation will be available.
Responsibilities
- Design, implement, and maintain enterprise network security controls including firewalls, proxies, and secure access services aligned to business and regulatory requirements.
- Act as the technical authority for Fortinet, Palo Alto Networks, and Zscaler platforms.
- Ensure security policies are consistently enforced across data center, campus, cloud, and hybrid environments.
- Lead complex troubleshooting of network security issues, balancing security, performance, and availability.
- Help to define the network security roadmap, aligned with wider technology and security strategies.
- Design and evolve Zero Trust network architectures, including identity-aware access and least-privilege principles.
- Define and implement micro-segmentation strategies for traditional and containerized workloads.
- Provide design input into new initiatives (cloud adoption, Kubernetes/OpenShift, automation, AI platforms).
- Evaluate new security technologies and patterns, producing clear recommendations and design artifacts.
- Develop and maintain network security standards, patterns, and policy definitions.
- Ensure adherence to security policies through design reviews, operational controls, and continuous improvement.
- Partner with Information Security to translate policy into enforceable technical controls.
- Support audits, risk assessments, and regulatory obligations by providing clear evidence of control implementation.
- Act as a technical leader within the Connectivity Engineering Team, mentoring engineers and setting best practice.
- Work closely with Infrastructure, Platform, and Application teams to embed security by design.
- Provide subject-matter expertise to project teams and senior stakeholders.
Requirements
- Minimum 5 years’ experience operating in regulated, mission-critical environments (e.g., financial services, critical infrastructure).
- Deep hands-on expertise in enterprise network security engineering and large-scale network infrastructure support.
- Experience defining and implementing network segmentation and micro-segmentation strategies.
- Strong understanding of Zero Trust networking principles and identity-aware access controls.
- Strong experience designing, implementing, and optimizing firewall and proxy security policies.
- Deep hands-on experience with Palo Alto Networks (PAN-OS, Panorama, policy design).
- Deep hands-on experience with Fortinet (FortiGate, FortiManager, FortiAnalyzer).
- Deep hands-on experience with Zscaler (ZIA, ZPA, Zero Trust Exchange).
- Experience securing hybrid environments spanning on-prem, cloud, and containerized platforms.
- Exposure to security controls and design for Kubernetes/OpenShift.
- Experience with automation and infrastructure-as-code approaches for deploying security controls.
- Wide exposure to routing, switching, load balancing, and security architectures, with extensive operational and engineering experience.
- Strong grounding in core networking technologies and protocols, including: TCP/IP, BGP, OSPF, VLANs, VRF, VPN, VXLAN, NAT, ACLs, DNS.
- Hands-on experience with packet capture and network analytics and monitoring tools.
- Strong understanding of ITILv3 processes, including incident, problem, and change management.
- Ability to translate high-level security policies into practical, scalable technical designs.
- Strong analytical and diagnostic skills for assessing complex network and security environments.
- Competence in designing and optimizing security architectures, network policies, and segmentation models.
- Ability to work across hybrid and distributed environments (on-prem, cloud, container platforms).
- Strong capability to apply automation and IaC concepts to enhance security controls and operational efficiency.
- Ability to collaborate with cross-functional teams in highly regulated, high-availability environments.
- Methodical working approach, aligned to ITILv3 best practices with proven ability to implement processes.
- Willingness to challenge existing approaches and drive change.
- Strong attention to detail with a focus on operational excellence.
- Comfortable working under pressure, with changing priorities.
- A strong delivery mindset, setting and achieving realistic and timely execution of project deliverables across the portfolio.
- Strong communicator with the ability to engage effectively with engineers, architects, and senior management.
- Pragmatic and security-focused, balancing robust controls with delivery-oriented execution.
- Strategic thinker with a hands-on approach, comfortable navigating fast-paced and evolving technology landscapes.
- Analytical, detail-driven, and process-oriented, able to translate complexity into clear actions and documentation.
- Skilled at influencing, persuading, and guiding others toward the best technical and business outcomes.
- Collaborative team player and leader, with strong interpersonal skills and a passion for mentoring and developing others.
- Adaptable and dependable, able to work effectively across organizational boundaries and understand wider business drivers.
- Customer-focused and responsive, demonstrating a strong sense of urgency and commitment to service.
- Innovative and proactive, continually seeking improvements in problem-solving, processes, and solution design.
Skills
- Fortinet
- Palo Alto Networks
- Zscaler
- Zero Trust networking
- Micro-segmentation
- Firewall management
- Proxy management
- Secure access services
- Kubernetes/OpenShift security
- Automation
- Infrastructure-as-Code (IaC)
- TCP/IP
- BGP
- OSPF
- VLANs
- VRF
- VPN
- VXLAN
- NAT
- ACLs
- DNS
- Packet capture
- Network analytics
- Network monitoring
- ITILv3 processes
- Incident management
- Problem management
- Change management
Location
- UK-London
Work Type
- Permanent
- Standard 40 Hour Week
Experience Level
- Senior
- Minimum 5 years’ experience
Education Level
- Bachelor’s degree in Computer Science, Information Technology, or a related discipline, or equivalent combination of education, technical training, and practical experience.
- Relevant industry certifications (e.g. PCNSE, NSE, CCNP Security, or CISSP) or substantial real-world application.
- ITIL and/or PMI certification is considered an advantage.
About the Company
- The London Metal Exchange (LME) is the world centre for industrial metals trading.
- Most of the world’s global non-ferrous futures business is conducted on the LME’s three trading platforms totalling $21 trillion, 191 million lots and 4 billion tonnes notional with a market open interest high of 2.1 million lots in 2025.
- The metals community uses the LME, an HKEX Group company, as a venue to transfer or take on price risk, as a physical market of last resort and as the provider of transparent global reference prices.
- Hong Kong Exchanges and Clearing Limited (HKEX) is a publicly-traded company (HKEX Stock Code:388) and one of the world’s leading global exchange groups, offering a range of equity, derivative, commodity, fixed income and other financial markets, products and services, including the London Metals Exchange.
- As a superconnector and gateway between East and West, HKEX facilitates the two-way flow of capital, ideas and dialogue between China and the rest of world, through its pioneering Connect schemes, increasingly diversified product ecosystem and its deep, liquid and international markets.
- HKEX is a purpose-led organisation which, across its business and through the work of HKEX Foundation, seeks to connect, promote and progress its markets and the communities it supports for the prosperity of all.
Equal Opportunity
- The LME is committed to creating a diverse environment and is proud to be an equal opportunity employer.
- In recruiting for our teams, we welcome the unique contributions that you can bring in terms of education, ethnicity, race, sex, gender identity, expression & reassignment, nation of origin, age, languages spoken, colour, religion, disability, sexual orientation and beliefs.
- In doing so, we want every LME employee to feel our commitment to showing respect for all and encouraging open collaboration and communication.
