Network Specialist
Role details
Job location
Tech stack
Job description
The Network Security Specialist is a critical role focused on securing our network infrastructure and ensuring the confidentiality, integrity, and availability of our data. This position requires a strong understanding of networking principles and protocols, coupled with deep expertise in security best practices and threat mitigation. This includes a strong understanding of both Interior Gateway Protocols (IGPs) such as OSPF and Exterior Gateway Protocols (EGPs) such as BGP.
Main Accountabilities (List 6-8 major areas of responsibilities in order of importance, and purpose of these activities:
- Network Security Engineering: Design, Document, implement, and maintain security solutions for our network infrastructure, including firewalls, intrusion detection/prevention systems (IDS/IPS), VPNs, and network access control (NAC) systems. This includes the secure configuration and hardening of routing protocols like OSPF and BGP.
- Security Monitoring & Incident Response: Proactively monitor network traffic for suspicious activity, analyze security alerts, and conduct thorough investigations of security incidents to determine root cause and implement appropriate remediation measures. Develop and refine incident response playbooks, specifically addressing potential routing-related security events.
- Vulnerability Management: Perform regular vulnerability assessments and penetration testing of network devices and systems, including an in-depth analysis of routing protocols like OSPF and BGP for potential vulnerabilities. Analyze results, prioritize remediation efforts, and work with IT teams to mitigate identified vulnerabilities.
- Security Policy & Compliance: Contribute to the development and maintenance of network security policies, standards, and procedures. Ensure network infrastructure and security controls adhere to industry best practices and regulatory requirements, including those related to routing security.
- Threat Intelligence: Stay abreast of emerging threats, vulnerabilities, and attack vectors. Analyze threat intelligence feeds and proactively implement countermeasures to protect the network from evolving threats, with specific attention to threats targeting routing protocols such as OSPF and BGP.
- Collaboration & Communication: Work closely with other IT teams, including system administrators, network engineers, and security analysts, to ensure the security of the overall IT environment. Effectively communicate security posture and findings to management and stakeholders, including explanations of complex routing security concepts.
Impact/Dimensions (Describe the strategic impact of the role / Using dollars and/or numbers, list the pertinent statistics of the position which clarify major areas of impact. Examples are: # of employees supervised, annual budget, annual sales/revenue):
- Directly responsible for the security posture of the organization's network infrastructure and data traversing it, including the security and integrity of routing protocols.
- Plays a crucial role in preventing data breaches, service disruptions, and reputational damage that could arise from compromised routing infrastructure.
- Contributes to regulatory compliance and maintaining customer trust by ensuring the secure operation of critical routing protocols.
Key Performance Indicators (KPIs) (Measurable outcomes that the position contributes to):
- Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) for security incidents, including those related to routing infrastructure.
- Number of vulnerabilities identified and remediated within defined SLAs, specifically addressing vulnerabilities in routing protocols and configurations.
- Network uptime and availability related to security incidents, including the ability to maintain routing availability during attacks or outages.
- Compliance with established security policies and industry best practices, particularly those related to routing security and configuration.
Major Opportunities and Decisions (Describe the more difficult and/or complex challenges or opportunities and decisions faced in doing work, improving processes or meeting customer needs. Where must position focus to be successful?):
- Recommending and implementing new security technologies and solutions to enhance network security posture, including advanced routing security mechanisms.
- Architecting and implementing secure network designs and configurations, incorporating best practices for routing security and resilience.
- Developing and refining incident response plans and procedures, with a focus on identifying and responding to routing-related security events.
- Providing expert guidance on complex security issues impacting network infrastructure, specifically addressing routing security challenges and solutions.
Management/Leadership (Describe the level of management and leadership skills required for the role. Identify key specialties, technical and knowledge areas necessary to accomplish responsibilities and desired results):
- May mentor and provide technical guidance to junior security analysts, particularly in the area of routing security.
- Act as a subject matter expert for network security within the organization, providing in-depth knowledge and guidance on routing protocols and their security implications.
Key Relationships, Stakeholders & Interfaces (External & Internal):
- Internal: IT operations, security operations center (SOC), system administrators, network engineers, application owners, with a focus on collaborating on routing security issues.
- External: Security vendors, industry peers, threat intelligence communities, actively participating in discussions and knowledge sharing related to routing security.
Requirements
- Deep understanding of TCP/IP networking, network protocols, and common network services, with an emphasis on routing protocols like OSPF and BGP.
- Expertise in firewall technologies, intrusion detection/prevention systems, VPNs, and NAC solutions, including their integration with routing infrastructure.
- Hands-on experience with security information and event management (SIEM) systems and log analysis, specifically analyzing logs from routers and routing protocols.
- Strong scripting skills (e.g., Python, Bash, PowerShell) for automation and security tooling, including the automation of routing security tasks and analysis.
- Familiarity with security frameworks such as NIST Cybersecurity Framework, CIS Controls, and ISO 27001, applying these frameworks to secure routing infrastructure.
- Strong understanding of OSPF and BGP, their configurations, security vulnerabilities, and best practices for implementation.
- Experience with securing and troubleshooting large-scale routing environments.
- Relevant industry certifications such as CCNP Security, CISSP, CISM, CEH, or SANS GIAC certifications are highly desirable.
Education/Experience (Identify types and length of education and experience needed to acquire the necessary skills and knowledge to accomplish the desired end results. Some examples are education & training, and years of experience):
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field, or equivalent experience.
- 10+ years of experience in a dedicated network security role, with demonstrated experience in securing routing protocols and infrastructure.
- Proven experience in designing, implementing, and managing network security solutions in an enterprise environment, including the implementation of secure routing designs.
- Strong analytical, problem-solving, and communication skills, capable of explaining complex routing security concepts to both technical and non-technical audiences.