Network Security Engineer
Rochester, NH - USA
Job Summary
Job Title:Network Security Engineer
Department: Information Technology
Location: Rochester NY
Classification: Exempt
Reports To: Director of Information Technology
Company Overview:
Woods Oviatt Gilman LLP is a leading and reputable full-service law firm dedicated to providing exceptional legal services to our clients. With a team of highly skilled and experienced attorneys we strive to deliver comprehensive and effective solutions to meet the diverse needs of our clients. Our headquarters is in Rochester NY with additional offices in Albany and Buffalo NY.
We foster a collaborative and inclusive work environment where every team member is valued and respected. We encourage open communication teamwork and professional growth. Our firm promotes a healthy work-life balance and supports the well-being of our employees.
Position Summary:
The Network Security Engineer is a hands-on technical role responsible for implementing configuring and maintaining the firms security controls across a hybrid environment including FortiGate firewalls endpoint protection cloud email and Microsoft 365 Intune-managed devices and a co-managed monitoring and detection service. The Engineer works under the direction of the Director of Information Technology who sets security policy and priorities for the department and provides the technical assessment recommendations and documentation that support those decisions. Because the firm safeguards confidential and privileged client information this position calls for strong technical skill sound judgment discretion and clear communication with both the IT team and firm personnel.
Duties and Responsibilities:
Network and Perimeter Security
- Administer tune and monitor FortiGate firewalls including security policies VPN configuration intrusion prevention web and content filtering and logging
- Implement and maintain network segmentation secure remote access and wireless security across firm locations in line with the departments standards
- Maintain secure connectivity for remote and hybrid users including VPN and conditional access
- Conduct scheduled reviews of firewall rules and network configurations recommend changes to the Director of Information Technology and maintain accurate network security documentation
Endpoint Identity and Email Security
- Administer the firms endpoint protection platforms including CrowdStrike and Microsoft endpoint protection covering policy configuration detection review containment actions and agent coverage
- Configure and maintain device compliance configuration and application deployment through Microsoft Intune in a hybrid environment including full-disk encryption and recovery key handling
- Configure and maintain identity and access controls across Microsoft Entra ID and on-premises Active Directory including multifactor authentication conditional access and privileged account settings and perform periodic access reviews
- Configure and maintain security settings for cloud email and collaboration including mail flow and filtering rules phishing and malware defenses email authentication records and Microsoft 365 security configuration
- Perform vulnerability and patch management across servers endpoints and network devices including scanning prioritizing findings tracking remediation and reporting status to the Director of Information Technology
Monitoring Detection and Incident Response
- Serve as the day-to-day technical contact for the firms managed monitoring service triaging alerts validating findings and carrying issues through to resolution
- Investigate security events and perform containment eradication and recovery steps in accordance with the firms incident response procedures escalating promptly to the Director of Information Technology
- Contribute to the development maintenance and testing of the firms incident response plan including participation in tabletop exercises
- Verify that backup recovery and business continuity controls are functioning and tested and support the departments disaster recovery planning
Security Program Support Privacy and Compliance
- Provide technical evaluation and recommendations to support the departments selection and adoption of a recognized security framework such as the NIST Cybersecurity Framework CIS Controls or ISO 27001
- Implement and maintain the technical controls that support the framework and assist in assessing and reporting the firms posture against it
- Assist the Director of Information Technology in drafting and maintaining information security policies standards and procedures and implement the technical measures that carry them out
- Maintain security documentation control evidence and a working risk log and recommend remediation priorities to the Director of Information Technology
- Support compliance with applicable privacy and data protection obligations including the New York SHIELD Act and other state privacy requirements and requirements applicable to regulated client data such as protected health information
- Prepare technical responses and supporting documentation for client security requirements including outside counsel guidelines security questionnaires and client and third-party audits and complete remediation items assigned by the Director of Information Technology
- Support obligations arising from clients in regulated industries including financial services requirements such as NYDFS Part 500 as applied to the firm through client agreements
- Perform technical security reviews of vendors applications and services under consideration and provide findings and recommendations to the Director of Information Technology
- Assist with independent assessments including penetration testing and external audits and complete assigned remediation work
Awareness and Collaboration
- Administer the firms security awareness program including training delivery phishing simulations and user communication developed with the Director of Information Technology
- Partner with the IT team on secure configuration change management and project work and provide technical guidance to service desk staff on security escalations
- Report on control status vulnerabilities incidents and open remediation items to the Director of Information Technology
- Maintain current knowledge of emerging threats vulnerabilities and security technologies relevant to the legal industry and share findings with the department
Technical Skills:
- Hands-on administration of FortiGate firewalls including policy management VPN intrusion prevention and content filtering
- Endpoint detection and response administration ideally CrowdStrike Falcon and familiarity with Microsoft endpoint protection
- Microsoft 365 security administration including cloud email protection mail flow and filtering phishing defense and email authentication using SPF DKIM and DMARC
- Identity and access administration across Microsoft Entra ID and on-premises Active Directory in a hybrid configuration including multifactor authentication and conditional access
- Microsoft Intune administration including device compliance and configuration application deployment and device encryption in a hybrid environment
- Solid networking fundamentals including TCP/IP routing and switching VLANs DNS DHCP segmentation and wireless security
- Vulnerability management and patch management practice including scanning prioritization and remediation tracking
- Security monitoring and log analysis and experience working with a managed detection and response or co-managed SOC provider
- Working familiarity with a recognized security framework such as the NIST Cybersecurity Framework CIS Controls or ISO 27001 and experience implementing controls in support of one
- Familiarity with privacy and data protection requirements including state breach notification obligations and handling of regulated data
- Ability to produce clear technical documentation control evidence risk write-ups and status reporting for both technical and non-technical readers
Preferred
- Prior experience in a law firm or other professional services environment including familiarity with outside counsel guidelines and client security audits
- Experience preparing responses to client security questionnaires and third-party risk assessments
- Azure or other cloud security administration
- PowerShell or comparable scripting for automation and reporting
- Experience with data loss prevention email encryption or information rights management
- Experience with security awareness platforms and phishing simulation tools
- Familiarity with SD-WAN zero trust or secure access service edge architectures
- Relevant certifications such as Fortinet NSE CompTIA Security GIAC credentials Microsoft SC-200 or SC-300 CISSP or CISM
Qualifications and Competencies:
- Strong analytical and problem-solving skills with sound technical judgment in assessing and prioritizing risk
- Ability to manage assigned technical work independently while escalating decisions and exceptions appropriately
- Clear verbal and written communication including the ability to explain security risks and requirements to attorneys staff and IT colleagues
- Ability to weigh security requirements against practical business needs and recommend workable options
- Ability to influence behavior and support change constructively and without confrontation
- Highly organized and detail-oriented and able to manage concurrent projects alongside daily operational work
- Discretion and sound judgment in handling confidential and privileged information
- Commitment to continued technical development in a rapidly changing field
Education and Experience:
- Bachelor of Science in Information Technology Cybersecurity Computer Science or a related field or equivalent practical experience
- Five or more years of hands-on experience in network security information security or systems and network engineering with substantial security responsibility
- Experience implementing security controls in support of a security framework and exposure to policy compliance or audit support work
Physical Requirements:
The following are representative of the physical demands of this position. Reasonable accommodations may be made for qualified individuals with disabilities.
- Ability to work in server rooms and network closets including bending reaching and standing for extended periods
- Ability to install and service rack-mounted network and server equipment
- Ability to lift and move items weighing up to 50 pounds
- Availability for occasional after-hours maintenance windows and response to security incidents outside normal business hours
Other Duties:Please note this job description is not designed to cover or contain a comprehensive listing of activities duties or responsibilities that are required of the employee for this job. This is a snapshot of the core functions and responsibilities. All inquiries will be handled with the utmost confidentiality. The compensation range for this position is $100000-$120000 annually representing our good faith and reasonable estimate of the potential compensation at the time of posting. Actual compensation will be determined based on various factors including the candidates qualifications experience skill set and office location.
Woods Oviatt Gilman LLP is an Equal Opportunity Employer. We value an open mind dedication to work and a collaborative spirit. We hire based on these qualities a jobs requirements our business needs and an applicants qualifications. We do not tolerate discrimination or harassment of any kindin the hiring process or in the workplace. We comply with the ADA and consider reasonable accommodation measures that may be necessary for eligible applicants/employees to perform essential functions. We participate in E-Verify. We will provide the federal government with employees Form I-9 information to confirm authorization to work in the U.S. We will only use E-Verify once an employee has accepted a job offer and completed Form I-9.
Required Experience:
IC
About Company
We’ve been part of Western New York since 1852 and through our private and corporate clients; our partners, associates and staff; and the local organizations we help support, this community is truly part of our firm. Now, more than 160 years later, Woods Oviatt Gilman has a national a ... View more