Description
Complete Description:
We are seeking an experienced Sr. Network Security Engineer (Sr. NSE) to implement and support the organization's IT network, cloud, and computing infrastructure. The Sr. NSE performs day-to-day activities related to securing the organization's infrastructure, including documentation, research, analysis, design, and implementation of network and computing infrastructure.
The Sr. NSE will support a hybrid enterprise environment consisting of approximately 300 statewide locations, Palo Alto firewalls, Azure networking, ExpressRoute connectivity, WAF technologies, Splunk SIEM, SD-WAN, and mission-critical public-facing applications. The role partners closely with Infrastructure, Cloud Engineering, and the Information Security Office to maintain the confidentiality, integrity, and availability of the organization's network infrastructure.
Key Responsibilities:
- Ensure network security architecture aligns with operational security standards before and after deployment.
- Lead investigation and containment of network security incidents.
- Review firewall rule requests and ensure compliance with security standards.
- Design and maintain secure hybrid network architecture across on-premises and Azure environments.
- Monitor security events using SIEM technologies and coordinate incident response activities.
- Perform network security assessments and recommend remediation strategies.
- Develop and maintain network security standards, diagrams, and operational documentation.
- Support penetration testing and remediation efforts.
- Participate in on-call support during critical security incidents.
- Conduct proactive threat hunting and anomaly detection.
- Validate WAF and firewall placement, integration, exposure, and connectivity. Lead the implementation, review, and management of enterprise WAF solutions.
- Identify and diagnose system problems and security threats using system logs, line monitors, SIEM platforms, diagnostic software, and test equipment.
- Identify, prioritize, and remediate network security vulnerabilities.
- Provide documentation, network architecture topology diagrams, IP addressing schemes, firewall rules, and access control documentation as required.
- Work independently on assigned projects