Senior Network Security Engineer
Lantern
About this role
About Lantern Lantern is the specialty care platform connecting people with the best care when they need it most. By curating a Network of Excellence comprised of the nation's top specialists for surgery, cancer care, infusions and more, Lantern delivers excellent care with significant cost savings to employers and their workforces. Lantern also pairs members with a dedicated care team, including Care Advocates and nurses, for the entirety of their care journey, helping them get back to good health, back to their families and back to work. With convenient access to specialists nationwide, Lantern means quality care is within driving distance for most. Lantern is trusted by the nation's largest employers to deliver care to more than 6 million members across the country. Learn more about us at lanterncare.com. About You: • You use LOGIC in your decision making and understand that progress is critical to making change. You focus on the execution of your content while balancing a fast-paced environment and you take the time to celebrate both the small & big wins. • INCLUSION is a core tenant of your personal beliefs. A diverse and inclusive environment is incredibly important to you. You understand and desire to be a part of a diverse team with different experiences and perspectives & you cherish the differences in each individual that you interact with. • You have the GRIT, drive and ambition to tackle big problems. Big problems require big ideas and a team that supports new ideas. • You care deeply for your customers are driven to keep HUMANITY in all decisions. Your customers aren’t just the individuals using your product. They are the driving factor in your motivation to make a change. • Integrity guides you in life. Focusing on the TRUTH vs. giving people the answers they want to hear. • You thrive in a Team Environment. Collaboration is key in innovation and creating change. These pillars of LIGHT are a reminder to our team that we are making a difference by providing guidance and support in navigating the often complex and confusing landscape of healthcare. We hope that through this LIGHT, individuals can find their way to the best care, resources, and support they need to get back to life. If this sounds like you, we would love to connect to speak further about career opportunities at Lantern. Please apply to our role & someone from our Talent Acquisition Team will reach out to help you navigate our interview process. Lantern is looking for a Sr. Network Security Engineer to join our fast-growing team. You will design, implement, and defend the network security architecture protecting our members’ healthcare data across on-premises, Azure, and edge environments. As the senior network security engineer on the Security Engineering & Operations team, you will own our Fortinet security fabric and Zero Trust network access architecture, drive automation of network security operations, and provide technical leadership across firewall, VPN, segmentation, and cloud network security domains. This role operates in a HIPAA, HITRUST CSF, and SOC 2 regulated environment and requires deep hands-on expertise, strong judgment, and effective collaboration with IT, cloud, and GRC partners. Location: Hybrid - at least 3 days/wk in our Dallas office located at 2100 Ross Avenue, Dallas, Texas 75201 Responsibilities: • Design, implement, and manage secure network infrastructure across on-prem and Azure hybrid environments, including routing, switching, firewalls, VPN, and network segmentation. • Own and operate the Fortinet security fabric: FortiGate firewalls, FortiManager, FortiAnalyzer, FortiClient EMS, FortiSwitch/FortiAP, and SD-WAN, including lifecycle upgrades and vulnerability remediation against CISA KEV and vendor advisories. • Advance our Zero Trust architecture: design and operate ZTNA/SASE controls, identity-aware access policies, and micro segmentation to reduce reliance on perimeter and legacy VPN access. • Maintain and continuously optimize firewall rule sets, NAT policies, IPS/IDS, and IPsec/SSL VPN configurations through regular audits, rule hygiene, and hardening against benchmark baselines. • Engineer Azure network security controls: NSGs, Azure Firewall, VPN/ExpressRoute gateways. • Automate network security operations using infrastructure-as-code and scripting (Terraform, Ansible, Python, PowerShell, REST APIs) to eliminate manual, error-prone changes. • Monitor network traffic and detections (NDR, SIEM), tune signals and IOCs with a metrics-driven mindset, and lead network-layer incident response and root-cause analysis. • Secure emerging traffic patterns, including AI agent and API traffic, in partnership with our AI governance and threat detection programs. • Partner with IT, cloud, and platform teams on secure-by-design integration of network and system components; support audit and compliance evidence requests (HIPAA, HITRUST CSF, SOC 2). • Produce and maintain high-quality documentation: network diagrams, configuration standards, and standard operating procedures. • Mentor engineers on the team and contribute to on-call and change management processes. Requirements: • 7+ years in network and/or security engineering roles with increasing scope and ownership. • 5+ years of hands-on experience with Fortinet solutions (FortiGate, FortiManager, FortiAnalyzer, EMS, SD-WAN) and FortiCloud services. • 5+ years of Azure networking and security experience in hybrid environments. • Practical experience designing or operating Zero Trust / ZTNA / SASE architectures (e.g., Cloudflare Zero Trust, Zscaler, or equivalent). • Experience with an NDR platform (e.g., Darktrace, ExtraHop) and integrating network telemetry into a SIEM. • Strong scripting and automation skills: Python and/or PowerShell, REST APIs, and version-controlled change workflows; infrastructure-as-code experience (Terraform, Ansible) strongly preferred. • Deep knowledge of network protocols and services (TCP/IP, DNS, BGP/OSPF, TLS), security architecture, policy development, and incident response. • Excellent communication skills with technical and non-technical stakeholders, and a track record of delivering engineering projects in complex, fast-changing environments. Strong Candidates Will: • 7+ years in network and/or security engineering roles with increasing scope and ownership. • 5+ years of hands-on experience with Fortinet solutions (FortiGate, FortiManager, FortiAnalyzer, EMS, SD-WAN) and FortiCloud services. • 5+ years of Azure networking and security experience in hybrid environments. • Practical experience designing or operating Zero Trust / ZTNA / SASE architectures (e.g., Fortinet ZTNA, Cloudflare Zero Trust or equivalent). • Experience with an NDR platform (e.g., Darktrace, ExtraHop) and integrating network telemetry into a SIEM. • Strong scripting and automation skills: Python and/or PowerShell, REST APIs, and version-controlled change workflows; infrastructure-as-code experience (Terraform, Ansible) strongly preferred. • Deep knowledge of network protocols and services (TCP/IP, DNS, BGP/OSPF, TLS), security architecture, policy development, and incident response. • Excellent communication skills with technical and non-technical stakeholders, and a track record of delivering engineering projects in complex, fast-changing environments. Benefits • Medical Insurance • Dental Insurance • Vision Insurance • Short & Long Term Disability • Life Insurance • 401k with company match • Flexible Time Off • Paid Parental Leave Lantern does not discriminate on the basis of race, sex, color, religion, age, national origin, marital status, disability, veteran status, genetic information, sexual orientation, gender identity or any other reason prohibited by law in provision of employment opportunities and benefits.
What we are looking for
8- 7+ years in network and/or security engineering roles with increasing scope and ownership.
- 5+ years of hands-on experience with Fortinet solutions (FortiGate, FortiManager, FortiAnalyzer, EMS, SD-WAN) and FortiCloud services.
- 5+ years of Azure networking and security experience in hybrid environments.
- Practical experience designing or operating Zero Trust / ZTNA / SASE architectures (e.g., Cloudflare Zero Trust, Zscaler, or equivalent).
- Experience with an NDR platform (e.g., Darktrace, ExtraHop) and integrating network telemetry into a SIEM.
- Strong scripting and automation skills: Python and/or PowerShell, REST APIs, and version-controlled change workflows; infrastructure-as-code experience (Terraform, Ansible) strongly preferred.
- Deep knowledge of network protocols and services (TCP/IP, DNS, BGP/OSPF, TLS), security architecture, policy development, and incident response.
- Excellent communication skills with technical and non-technical stakeholders, and a track record of delivering engineering projects in complex, fast-changing environments.
