Lead the design, implementation, and operation of enterprise network security infrastructure across data centers, cloud environments, offices, retail locations, and distribution centers. Manage Palo Alto, Fortinet, and Zscaler platforms; implement zero trust, segmentation, secure connectivity, and compliance controls; coordinate incident response; automate security operations; support audits; and provide architectural guidance. The role also oversees device lifecycle management, documentation, service-provider escalations, and continuous improvement of network security capabilities.
Category/Area of Expertise: IT & Technology
Job Requisition: 544623
Address: USA-IL-Chicago-300 South Riverside Plaza
Store Code: Infrastructure - Network (5118708)
Ahold Delhaize USA, a division of global food retailer Ahold Delhaize, is part of the U.S. family of brands, which includes five leading omnichannel grocery brands - Food Lion, Giant Food, The GIANT Company, Hannaford and Stop & Shop. Our associates support the brands with a wide range of services, including Finance, Legal, Sustainability, Commercial, Digital and E-commerce, Technology and more.
Primary Purpose
The Sr. Network Security Engineer will lead the engineering, delivery, and operations of ADUSA's network security platforms with a key focus on zero trust architecture, next-generation firewalls, and secure connectivity across the enterprise. This role is responsible for the technical design, implementation, and management of mission-critical network security infrastructure spanning ADUSA's data centers, cloud environments, retail locations, corporate offices, and distribution centers.
The Sr. Network Security Engineer will drive the multi-year strategy to transform ADUSA's network security posture, championing zero trust principles and ensuring all network traffic is inspected, segmented, and secured in alignment with PCI-DSS, HIPAA, and other regulatory compliance frameworks. This role has overall responsibility for the delivery of secure connectivity, threat mitigation, incident response coordination, firewall and proxy platform management, and policy enforcement across all brands.
Our flexible/hybrid work schedule includes 3 in-person days at one of our core locations and 2 remote days. Our core office location is Salisbury, NC and Chicago,IL.
Applicants must be currently authorized to work in the United States on a full-time basis.
Duties and Responsibilities
Required Qualifications
Preferred Qualifications
Salary Range: $125,040 - $187,560
All ADUSA job offers take multiple factors into consideration including, but not limited to salary range, internal equity, a candidate's qualifications, geographic region, job-related knowledge and skills.
This position is eligible for an incentive bonus based on company performance as provided by the plan terms and governing documents.
#LI-Hybrid #LI-SC1
At Ahold Delhaize USA, we provide services to one of the largest portfolios of grocery companies in the nation, and we're actively seeking top talent.
Our team shares a common motivation to drive change, take ownership and enable our brands to better care for their customers. We thrive on supporting great local grocery brands and their strategies.
Our associates are the heartbeat of our organization. We are committed to offering a welcoming work environment where all associates can succeed and thrive. Guided by our values of courage, care, teamwork, integrity (and even a little humor), we are dedicated to being a great place to work.
We believe in collaboration, curiosity, and continuous learning in all that we think, create and do. While building a culture where personal and professional growth are just as important as business growth, we invest in our people, empowering them to learn, grow and deliver at all levels of the business.
#BI-Hybrid
Job Requisition: 544623
Address: USA-IL-Chicago-300 South Riverside Plaza
Store Code: Infrastructure - Network (5118708)
Ahold Delhaize USA, a division of global food retailer Ahold Delhaize, is part of the U.S. family of brands, which includes five leading omnichannel grocery brands - Food Lion, Giant Food, The GIANT Company, Hannaford and Stop & Shop. Our associates support the brands with a wide range of services, including Finance, Legal, Sustainability, Commercial, Digital and E-commerce, Technology and more.
Primary Purpose
The Sr. Network Security Engineer will lead the engineering, delivery, and operations of ADUSA's network security platforms with a key focus on zero trust architecture, next-generation firewalls, and secure connectivity across the enterprise. This role is responsible for the technical design, implementation, and management of mission-critical network security infrastructure spanning ADUSA's data centers, cloud environments, retail locations, corporate offices, and distribution centers.
The Sr. Network Security Engineer will drive the multi-year strategy to transform ADUSA's network security posture, championing zero trust principles and ensuring all network traffic is inspected, segmented, and secured in alignment with PCI-DSS, HIPAA, and other regulatory compliance frameworks. This role has overall responsibility for the delivery of secure connectivity, threat mitigation, incident response coordination, firewall and proxy platform management, and policy enforcement across all brands.
Our flexible/hybrid work schedule includes 3 in-person days at one of our core locations and 2 remote days. Our core office location is Salisbury, NC and Chicago,IL.
Applicants must be currently authorized to work in the United States on a full-time basis.
Duties and Responsibilities
- Lead the design, engineering, and operations of ADUSA's network security platforms including next-generation firewalls (Palo Alto, Fortinet), secure web gateways, and cloud security solutions (Zscaler ZIA/ZPA), ensuring high availability, performance, and compliance across all environments.
- Architect and implement zero trust network security frameworks across the enterprise, defining and enforcing micro-segmentation, least-privilege access policies, identity-based authentication, and continuous verification strategies to minimize the attack surface.
- Manage and maintain firewall rule sets, security policies, NAT configurations, and VPN infrastructure across Palo Alto and Fortinet platforms, ensuring policies are optimized, documented, and aligned with PCI-DSS, HIPAA, and corporate security standards.
- Oversee Zscaler cloud security platform administration including ZIA (Zscaler Internet Access) and ZPA (Zscaler Private Access), managing URL filtering, SSL inspection, DLP policies, cloud firewall rules, and application access policies for all users and locations.
- Drive compliance initiatives by implementing and maintaining network security controls required for PCI-DSS, HIPAA, SOX, and other regulatory frameworks; lead audit preparation activities, evidence collection, and remediation of security findings.
- Act as a subject matter expert in network security design and architecture, evaluating emerging threats and technologies, and providing recommendations to the Network Architecture team for continuous improvement of the security posture.
- Participate in security incident response and forensic analysis, working with the SOC, threat intelligence, and risk teams to investigate network-based threats, contain breaches, and implement preventive controls.
- Develop and maintain network security automation to streamline firewall provisioning, policy deployment, configuration compliance checks, and security reporting across all platforms.
- Review and establish security documentation, standard operating procedures, and runbooks; ensure these standards are maintained and audit-ready at all times.
- Act as a point of escalation to external ADUSA managed service providers and internal teams in the incident management process, assisting in reviewing security incident and problem data, performing root cause analysis, and driving continuous improvement.
- Monitor and manage the security device lifecycle, including firmware maintenance, certificate management, and license compliance for all firewalls, proxies, IDS/IPS, and related network security infrastructure.
- Manage and influence analysis of business requirements to ensure that network security solutions meet established policies, risk tolerance, and compliance controls while enabling business agility.
Required Qualifications
- Bachelor's degree or equivalent years of work experience.
- 5+ years of progressive experience in network security engineering, with deep hands-on expertise in enterprise firewall platforms (Palo Alto Networks, Fortinet FortiGate)
- Strong experience with Zscaler cloud security platforms (ZIA, ZPA) including deployment, policy management, SSL inspection, and troubleshooting
- Demonstrated experience designing and implementing zero trust network architectures in large-scale enterprise environments
- Knowledge of PCI-DSS and HIPAA compliance requirements as they relate to network security controls, segmentation, and audit readiness
- Strong experience in network security design and architecture including DMZ design, network segmentation, micro-segmentation, VPN technologies (IPSec, SSL), and secure remote access solutions
- Experience with security information and event management (SIEM) platforms, and network monitoring tools such as Panorama, FortiManager, FortiAnalyzer, and SolarWinds
- Proficiency in automation and scripting for network security device management, policy deployment, and compliance reporting
- Solid technical foundation in networking (CCNA/CCNP level equivalent) with strong knowledge of L2/L3 technologies, routing protocols (BGP, OSPF), and switching
- Experience with cloud security architectures including AWS, Azure, cloud-based firewalls, and hybrid connectivity security
Preferred Qualifications
- Holds one or more industry certifications: PCNSE (Palo Alto Networks), NSE 7/8 (Fortinet), ZCCA/ZCCP (Zscaler), CISSP, CCNP Security, CCIE Security
- Experience with network access control (NAC), 802.1X, and identity-based network segmentation solutions
- Experience with IDS/IPS platforms, DDoS mitigation, and advanced threat protection technologies
- Experience working in an Agile (SAFe) environment
- Familiarity with DevSecOps practices and integrating network security into CI/CD pipelinesExperience with Infoblox DDI, F5 load balancers, and Arista/Cisco ACI in the context of security policy enforcement and micro-segmentation.
Salary Range: $125,040 - $187,560
All ADUSA job offers take multiple factors into consideration including, but not limited to salary range, internal equity, a candidate's qualifications, geographic region, job-related knowledge and skills.
This position is eligible for an incentive bonus based on company performance as provided by the plan terms and governing documents.
#LI-Hybrid #LI-SC1
At Ahold Delhaize USA, we provide services to one of the largest portfolios of grocery companies in the nation, and we're actively seeking top talent.
Our team shares a common motivation to drive change, take ownership and enable our brands to better care for their customers. We thrive on supporting great local grocery brands and their strategies.
Our associates are the heartbeat of our organization. We are committed to offering a welcoming work environment where all associates can succeed and thrive. Guided by our values of courage, care, teamwork, integrity (and even a little humor), we are dedicated to being a great place to work.
We believe in collaboration, curiosity, and continuous learning in all that we think, create and do. While building a culture where personal and professional growth are just as important as business growth, we invest in our people, empowering them to learn, grow and deliver at all levels of the business.
#BI-Hybrid
Ahold Delhaize USA Quincy, Massachusetts, USA Office
1385 Hancock St, Quincy, MA, United States, 02169
Similar Jobs at Ahold Delhaize USA
AdTech • eCommerce • Food • Marketing Tech • Retail
Leads the design, implementation, and operation of enterprise network security platforms across data centers, cloud environments, retail locations, offices, and distribution centers. Responsibilities include Palo Alto and Fortinet firewall management, Zscaler administration, zero trust architecture, segmentation, compliance controls, incident response, automation, documentation, device lifecycle management, and security architecture strategy.
Top Skills:
802.1XAristaAWSAzureBgpCi/CdCisco AciDdos MitigationF5 Load BalancersFortianalyzerFortimanagerFortinet FortigateIds/IpsInfoblox DdiIpsecNacOspfPalo Alto NetworksPanoramaSIEMSolarwindsSsl VpnZscaler ZiaZscaler Zpa
AdTech • eCommerce • Food • Marketing Tech • Retail
Leads the design, implementation, and operation of enterprise network security platforms across data centers, cloud environments, retail locations, offices, and distribution centers. Responsibilities include Palo Alto and Fortinet firewall management, Zscaler administration, zero trust architecture, segmentation, compliance controls, incident response, automation, documentation, device lifecycle management, and security architecture strategy.
Top Skills:
802.1XAristaAWSAzureBgpCi/CdCisco AciDdos MitigationF5 Load BalancersFortianalyzerFortimanagerFortinet FortigateIds/IpsInfoblox DdiIpsecNacOspfPalo Alto NetworksPanoramaSIEMSolarwindsSsl VpnZscaler ZiaZscaler Zpa
AdTech • eCommerce • Food • Marketing Tech • Retail
The Security Engineering Manager safeguards technology by enforcing security policies, managing incident responses, monitoring threats, and reporting on security incidents. Must collaborate across IT and business functions, ensuring compliance and conducting training.
Top Skills:
Cis ControlsIso/Iec 27001Mitre Att&CkNistSIEMSoc
What you need to know about the Boston Tech Scene
Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.
Key Facts About Boston Tech
- Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
- Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
- Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
- Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

