Network Security Operations Engineer

UMASS BOSTON
Boston, MA, United States
10 days ago
Apply on jobs.localjobnetwork.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Software System Penetration Testing Complex Networks Cyber Security Dynamic Host Configuration Protocol Disaster Recovery Domainkeys Identified Mail Domain-Based Message Authentication Reporting and Conformance (DMARC) Domain Name System Security Extensions Domain Name System (DNS) Issue Tracking Systems Virtual Private Networks (VPN) Information Systems Security Architecture Professional
+20 more
Python (Programming Language) Network Security Network Segmentation Network Service PCI Data Security Standards Windows PowerShell Phishing Security Information and Event Management Software Vulnerability Management Scripting Network Access Control Computer Network Operations Computer Network Technologies Technical Debt Sender Policy Framework (SPF) Information Technology CIS Benchmarks Firewall Services Module Ddos Plan of Action and Milestones

Job description

Reporting to the Chief Information Security Officer (CISO), the Network Security Operations Engineer (NSOE) is responsible for the operational management, security, reliability, and continuous improvement of the University’s network security infrastructure. The position is responsible for the day-to-day operation of enterprise network security technologies, ensuring the confidentiality, integrity, availability, and resilience of university systems while partnering with Infrastructure, Network Services, and other IT teams. Primary responsibilities include ownership of enterprise firewall services, network security segmentation, VPN and Network Access Control (NAC) security services, security event monitoring within the Network and Security Operations Center (NSOC), and technical leadership for network security incident response in coordination with the Information Security Office and Network Services. The role requires after-hours support for critical security events.

Success in this role is measured by maintaining secure, resilient, and reliable network security services while continuously improving operational maturity, reducing organizational risk, and delivering exceptional service to the university community.

Examples of Duties:

  • Lead technical coordination of network security incidents at the Network and Security Operations Center (NSOC), overseeing security event monitoring, investigation, and response in accordance with enterprise incident response protocols.

  • Maintain secure, resilient firewall policies and configurations that protect university resources while enabling business operations.

  • Maintain the security configuration and operational effectiveness of network segmentation, VPN, and Network Access Control (NAC) technologies in partnership with Network Services.

  • Analyze, investigate, and coordinate response to network security events and alerts generated through enterprise monitoring platforms.

  • Maintain accurate operational documentation supporting service continuity, disaster recovery, audits, and knowledge transfer.

  • Maintain operational visibility across on-premises, cloud, and hybrid environments to ensure consistent enforcement of network security controls.

  • Leverage automation, security monitoring platforms, and enterprise security tools, including SIEM, to proactively monitor, analyze, and respond to threats while enabling rapid containment of security incidents and vulnerabilities.

  • Maintain an ongoing assessment of network security maturity, documenting risks, technical debt, and recommending remediation priorities through annual gap assessments and the University’s Plan of Action and Milestones (POAM).

  • Lead technical incident response activities in coordination with the Information Security Office.

  • Conduct post-incident reviews to identify gaps, refine security controls, minimize future risk, and track corrective actions through completion.

  • Partner with Network Services and ISO to translate complex technical issues into clear operational communications for leadership and campus stakeholders.

  • Develop and maintain network status dashboards, outage notifications, and service bulletins to keep the community informed of operational changes.

  • Participate in and contribute technical expertise to security risk assessments, audits, and penetration testing activities.

  • Lead the operational coordination of network security vulnerability remediation by identifying, prioritizing, tracking, and validating remediation activities in partnership with Desktop Services, Systems Administration, and Infrastructure teams.

  • Support mail security operations, including monitoring and tuning of email threat protection, anti-phishing, and anti-spoofing controls (SPF, DKIM, DMARC).

  • Evaluate emerging threats and translate threat intelligence into improvements to security controls and operational practices.

  • Participate in an on-call rotation and provide after-hours support for critical security incidents, network upgrades, and emergency response.

  • Train, mentor, and supervise student employees to support their professional development.

  • Build trusted partnerships across the university by delivering responsive, collaborative, and solutionsoriented security services.

  • Continuously improve network security operations by identifying opportunities to automate manual processes, reduce technical debt, enhance operational efficiency, and strengthen the University’s overall security posture.

  • Perform other duties as assigned., Provides technical leadership for cross-functional projects and supervises approximately five student employees. Collaborates closely with Infrastructure, Network Services, and Information Security teams to successfully deliver operational and security initiatives.

Requirements

  • Bachelor’s degree (BS) in Cybersecurity, Information Technology, Networking, or a related field, plus five (5) years of cumulative hands-on experience in network and security operations

  • Operational experience administering enterprise firewall platforms and network security controls in a production environment.

  • Demonstrated competency in network segmentation, VPN, and Network Access Control (NAC) concepts and operations.

  • Demonstrated experience using enterprise SIEM platforms for monitoring, investigation, and incident response.

  • Demonstrated experience participating in technical incident response within enterprise environments.

  • Proven ability to diagnose and resolve complex network security issues in enterprise environments.

  • Proven experience centrally managing DNS, DHCP, and IPAM (DDI) infrastructure.

  • Demonstrated experience implementing DNS security solutions that protect against DDoS, hijacking, cache poisoning, and other DNS-based threats. Proven ability to maintain continuous protection during active attacks, deploy adaptive defense mechanisms, and utilize global visibility tools to monitor and analyze attack patterns across distributed networks.

  • Hands-on experience configuring, monitoring, and troubleshooting security and network technologies in production environments, and a working knowledge of industry-standard network and security platforms and their best practices for implementation.

  • Experience developing automation using scripting languages such as PowerShell or Python.

Preferred Qualifications

  • CISSP (Certified Information Systems Security Professional) or CISM (Certified Information Security Manager) certification.

  • Experience working with multiple stakeholders in a matrixed environment consisting of Systems, Network Operations, Information Security, internal business units, and external incident response teams.

  • Experience supporting organizations aligned with NIST Cybersecurity Framework, CIS Controls, PCI-DSS, FERPA, GLBA, or other regulatory or compliance frameworks.

  • Knowledge of security risks, copyright violations, and other inappropriate or unlawful computing practices.

  • Strong interpersonal skills that facilitate positive working relationships with both co-workers and end-users.

  • Strong oral and written communication skills for personal interaction with end-users, written reports, documentation, and call ticket tracking.

  • Desire and willingness to work with end-users and provide high-quality customer service to people at all levels in a university setting.

  • Higher education experience preferred.

  • Strong commitment to customer service.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.localjobnetwork.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:51 min

Rising DDoS attacks and evaluating CDN mitigation strategies

Chris Heilmann +2 · LIVE

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:11 min

Surviving sudden scale events and malicious traffic

Justin Kitagawa · Coffee With Developers

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all