Security Engineer

McNees Wallace & Nurick LLC
Pittsburgh, PA, United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Software System Penetration Testing Microsoft Azure Cloud Computing Security CompTIA Security+ Cyber Security Information Systems Disaster Recovery Multi-Factor Authentication Identity and Access Management Intrusion Detection and Prevention Intrusion Detection Systems Information Systems Security Architecture Professional
+15 more
Python (Programming Language) Network Security Lightweight Directory Access Protocols (LDAP) OAuth Windows PowerShell Zero Trust Network Access Security Assertion Markup Language (SAML) Security Information and Event Management Single Sign-On Software Vulnerability Management Firewalls (Computer Science) Infrastructure Automation Frameworks Information Technology CIS Benchmarks Vulnerability Analysis

Job description

You will lead the design, implementation, and continuous improvement of the firm’s cybersecurity program. This is a high-impact role for a security professional who thrives on solving complex challenges, strengthening organizational resilience, and partnering across teams to embed security into every aspect of technology operations. Reporting to the Chief Information Officer, the Security Engineer will serve as the firm’s primary security expert, driving security strategy, incident response, risk management, and security architecture initiatives while helping to advance the overall capabilities of our IT team., * Design, implement, and maintain enterprise security infrastructure, including firewalls, intrusion detection and prevention systems (IDS/IPS), endpoint protection platforms, SIEM solutions, and application control technologies.

  • Lead the execution of the firm’s cybersecurity strategy and roadmap, aligning security initiatives with business objectives and risk management priorities.
  • Monitor security systems, investigate alerts, and coordinate responses to security incidents, including high-severity events and forensic investigations.
  • Conduct vulnerability assessments and penetration testing activities while partnering with system owners to remediate identified risks.
  • Develop, maintain, and enforce security policies, standards, and procedures aligned with industry frameworks such as NIST CSF, CIS Controls, and ISO 27001.
  • Manage identity and access management solutions, including multi-factor authentication, single sign-on, privileged access management, and periodic access reviews.
  • Support security and privacy compliance initiatives, audits, risk assessments, and third-party vendor security reviews.
  • Administer and optimize security tools, including email security gateways, web filtering solutions, and cloud security technologies.
  • Lead incident response, business continuity, disaster recovery, and major security-focused projects such as platform migrations and zero-trust initiatives.
  • Collaborate with infrastructure, cloud, and business teams to integrate security requirements into new and existing technologies and processes.
  • Advise firm leadership on cybersecurity risks, security architecture, and strategic technology investments.
  • Track emerging threats and security trends, and prepare metrics, dashboards, and reports demonstrating the firm’s security posture and program maturity.
  • Mentor colleagues, share technical expertise, and help foster a culture of security awareness across the organization.

Requirements

  • Bachelor’s degree in Information Security, Information Technology, Information Systems, or a related field, or an equivalent combination of education and experience.
  • Five or more years of progressive experience in cybersecurity or information security, including responsibility for complex security programs and initiatives.
  • Strong knowledge of network security, operating system hardening, Azure security, and modern security architectures, including zero-trust principles.
  • Hands-on experience with SIEM platforms, vulnerability management tools, endpoint detection and response (EDR), firewalls, and IDS/IPS technologies.
  • Working knowledge of security frameworks and standards such as NIST CSF, CIS Controls, ISO 27001, and SOC 2.
  • Understanding of identity and access management technologies and protocols, including SAML, OAuth, LDAP, and directory services.
  • Experience with scripting and automation tools such as PowerShell and Python.
  • Exceptional analytical, troubleshooting, and problem-solving abilities.
  • Strong written and verbal communication skills with the ability to present technical concepts to both technical and non-technical audiences.
  • Ability to manage multiple priorities, work independently, and maintain confidentiality in a professional services environment.
  • Industry certifications such as CISSP, CISM, CEH, GIAC, or CompTIA Security+ are strongly preferred.
  • Master’s degree in Cybersecurity, Information Security, or a related discipline is preferred.

LI-REMOTE

About the company

Joining McNees Wallace & Nurick LLC means becoming part of a team that values your voice, your growth, and your impact on clients, colleagues, and the communities we serve. Since 1935, McNees has been a trusted, client-focused law firm delivering practical, results-driven legal solutions with integrity and a client-first philosophy. We are a full-service firm with more than 170 attorneys and 350 professionals, committed to excellence across a wide range of practice areas and industries.

At McNees, we are guided by our core values of authentic relationships, excellence, growth, and balance to foster collaboration and innovation. We support your success through mentorship, leadership development, and continuous learning opportunities. Our commitment to community runs deep, with a strong tradition of stewardship through pro bono work, charitable initiatives, and civic engagement. We also prioritize flexibility and well-being with a family-focused culture, reasonable revenue hour expectations, and technology that drives efficiency.

If you’re looking for an opportunity to do meaningful work with people who value integrity and collaboration, you’ll feel at home at McNees.

McNees, Wallace & Nurick is actively seeking a Security Engineer to join our Information Technology department. At McNees, we believe our people are our greatest asset. We foster a culture of integrity, innovation, and collaboration - where your ideas matter, and your contributions make a real impact., Headquartered in Harrisburg, Pa., McNees operates offices across Pennsylvania, Maryland, Ohio, and Washington, D.C., giving our team a broad regional footprint and diverse opportunities for collaboration. We are ranked among the NLJ 500, Best Law Firms, and Best Lawyers, and nationally recognized for excellence in areas such as construction litigation and energy law.

Our attorneys deliver tailored strategies to businesses, individuals, and organizations across industries, including real estate, energy, healthcare, banking and finance, insurance, construction, and technology. We also have a strong presence in public sector law, advocating for clients in regulatory and legislative matters at all levels of government.

Our services span corporate law, real estate and construction, labor and employment, litigation, tax, intellectual property, energy and environmental, estate planning, and public sector law, complemented by affiliated businesses like Apollo Communications (strategic marketing and PR), Keystone Municipal Solutions (municipal consulting), and Pine Street Land Company (title and settlement services).

McNees offers an engaging work environment, robust opportunities for professional development, challenging and rewarding career paths, and competitive compensation. McNees is an Equal Opportunity Employer. Employment decisions are made without regard to any trait protected by law.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · World Congress 2023

Videos

See all

Related articles

See all