L3 Network & Security Operations Engineer
Salary not stated · Compare with UK Software Engineer pay →
We are seeking a talented individual to join our Network and Security Operations team, part of Marsh. This role will be based in Cluj-Napoca. This is a hybrid role that has a requirement of working at least three days a week in the office.
As L3Network & Security Operations Engineer you will act as a senior escalation point for complex network incidents and changes. This is an operational, delivery-focused role (troubleshooting, remediation, and implementation) with a strong emphasis on modern load balancing (F5 Distributed Cloud and AWS ALB/NLB), plus WAN and branch connectivity.
You will join a combined Network and Security Operations team that supports end-to-end user-to-application flows across the network and security control path. The position is primarily network-operations focused, with clear exposure and progression into security operations toolsets if desired.
Working pattern
Hybrid working model with an expectation of time in the office and time working from home
Standard business hours, Monday to Friday
Global follow-the-sun support model across EMEA, APAC, and the Americas, with structured handovers between regions
Weekend on-call rota for major incidents only; shared across the full team with each person covering one weekend per rotation cycle
We will count on you to
Provide L3 escalation support for major incidents, leading technical triage, restoration activities, and clear stakeholder communication
Operate, troubleshoot, and implement load balancing services, with a primary focus on F5 Distributed Cloud (XC) and AWS Elastic Load Balancing (ALB/NLB)
Manage TLS/SSL enablement across load balancers and, where required, firewalls/WAFs, including certificate installation, chain management, binding, renewal, rotation, and end-to-end validation
Support SD-WAN, WAN, and branch connectivity services, including troubleshooting routing, pathing, carrier issues, and branch LAN/WLAN environments
Deliver network changes safely and effectively through ITIL-aligned governance, including planning, risk assessment, validation, and rollback readiness
Produce high-quality operational documentation, ITSM updates, and closure notes to improve repeatability and reduce mean time to resolution
Support legacy F5 BIG-IP services as required during transition to cloud/distributed platforms
Contribute to the team’s broader operational capability, with opportunities to gain exposure to firewall, WAF, cloud security controls, Zero Trust, and microsegmentation technologies
Growth & development (security operations pathway)
Opportunity to develop hands-on experience with firewall and WAF implementations where traffic flows require termination/inspection and policy troubleshooting
Exposure to cloud security controls and segmentation (e.g., security groups and cloud-native access patterns) as part of end-to-end flow support
Option to broaden into Zero Trust and microsegmentation technologies used by the team (e.g., Zscaler, Elisity, Illumio), depending on interest and team needs
What you need to have
Proven L3 Network Operations experience as a senior escalation resource in a NOC/operations environment.
Strong troubleshooting capability across L2–L7, including TCP/TLS and HTTP/HTTPS, with a structured and methodical approach to fault isolation and remediation
Hands-on experience with cloud/distributed load balancing, including F5 Distributed Cloud and/or AWS ALB/NLB
Practical experience deploying and managing CA-provided certificates, including import/install, chain management, binding/configuration, renewal/rotation, and post-change validation
Solid experience with Cisco multilayer switching (Layer 2 / Layer 3), including configuration and troubleshooting of VLANs, SVIs, routing, and high-availability concepts
Solid experience troubleshooting WAN and branch connectivity, including working with carriers and vendors during outages
Strong change management discipline within an ITIL framework, including Incident, Problem, and Change processes
What makes you stand out?
Operational experience with legacy F5 BIG-IP (LTM) and/or migration activities to cloud/distributed load balancing platforms.
Familiarity with firewall and WAF implementations, especially where TLS termination or inspection affects traffic flows.
Experience with Prisma SD-WAN (CloudGenix), Aviatrix, Aruba Central, and/or Juniper Mist.
Scripting or automation experience using PowerShell and/or Python to improve operational efficiency.
Why join our team
We help you be your best through professional development opportunities, interesting work, and supportive leaders;
We foster a vibrant and inclusive culture where you can work with talented colleagues to create new solutions and have an impact for colleagues, clients, and communities;
Our scale enables us to provide a range of career opportunities, as well as benefits and rewards to enhance your well-being;
A yearly budget and the opportunity to build your flexible benefits package (up to 20% of your annual salary);
30+ days off (including legal days, birthday, public holiday replacements, and benefits options);
Performance bonus scheme;
Matching charity contributions, charity days off, and the Pay it Forward charity challenge;
Core benefits: Pension, Life and Medical Insurance, Meal Vouchers, Travel Insurance.
Marsh (NYSE: MRSH) is a global leader in risk, reinsurance and capital, people and investments, and management consulting, advising clients in 130 countries. With annual revenue of over $27 billion and more than 95,000 colleagues, Marsh helps build the confidence to thrive through the power of perspective. For more information, visit marsh.com, or follow us on LinkedIn and X.
Marsh is committed to creating a diverse, inclusive and flexible work environment. We aim to attract and retain the best people and embrace diversity of age, background, disability, ethnic origin, family duties, gender orientation or expression, marital status, nationality, parental status, personal or social status, political affiliation, race, religion and beliefs, sex/gender, sexual orientation or expression, skin color, or any other characteristic protected by applicable law.
Marsh is committed to hybrid work, which includes the flexibility of working remotely and the collaboration, connections and professional development benefits of working together in the office. All Marsh colleagues are expected to be in their local office or working onsite with clients at least three days per week. Office-based teams will identify at least one “anchor day” per week on which their full team will be together in person.
More at this employer
Other roles open at Marsh McLennan
- Performance Reporting AnalystLondon, United Kingdom · Yesterday
- Project Manager - Claims Transformation TeamWarsaw, Poland · Yesterday
- Junior DevOps Engineer @MarshTechCluj-Napoca, Romania · Yesterday
- Investment Portfolio Operations AnalystLondon, United Kingdom · Yesterday
Similar roles elsewhere
Open roles in Cluj-Napoca, Romania
- Safety ArchitectAccenture · Cluj-Napoca · Today
- SW Developer with Functional Safety ExpertiseAccenture · Cluj-Napoca · Today
- Senior Software Engineer (Java Full Stack)LSEG · Cluj 21 Decembrie 1989 Boulevard · Today
- Technical Support AnalystComplyAdvantage · Cluj-Napoca, Cluj, Romania · 4 days ago
Read the whole thing? Let's get you ready for it.
Morganson writes a cover letter against this exact ad, tailors your CV to it, and tells you the day roles like it open — three free credits when you join.