Cyber Security Firewall Administrator

Chicago Transit Authority
Chicago, IL, United States
10 days ago
Apply on diversityjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$120,565.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Access Control List Application Firewall User Authentication Microsoft Azure Unix Command-Line Interface Cyber Security Computer Networks Linux Network Address Translation Multi-Factor Authentication
+26 more
Firmware Identity and Access Management Internet Protocol Security (IP SEC) Intrusion Detection and Prevention Virtual Private Networks (VPN) Lightweight Directory Access Protocols (LDAP) PCI Data Security Standards Remote Access Technology Zero Trust Network Access Security Assertion Markup Language (SAML) Security Information and Event Management Syslog Web Applications Data Logging Network Routers Transport Layer Security Firewalls (Computer Science) Information Technology Cybercrime Palo Alto Networks RSA SecurID Fortinet Firewall Services Module Cisco SSL VPN Vmware

Job description

The Cyber Security Firewall Administrator is responsible for the deployment, configuration, and ongoing administration of firewall and remote access systems to safeguard the Chicago Transit Authority’s networks from cyber threats. This role involves implementing and maintaining firewall and remote access/VPN rules and policies, monitoring traffic for unusual activity, analyzing logs, and responding to security events. The administrator works closely with IT and cyber security teams to ensure firewall and remote access/VPN configurations align with organizational security standards and regulatory requirements, supporting a secure and resilient network environment., * Firewall Administration

  • Install, configure, and maintain enterprise firewall systems (e.g., Palo Alto, Cisco, Fortinet, Check Point).

  • Create, modify, review, and optimize firewall rules for security and performance.

  • Implement and update firewall rules and access control lists (ACLs) in accordance with security policies.

  • Monitor and interpret firewall logs and alerts to detect, analyze, and respond to potential security incidents.

  • Apply firmware updates and security patches to firewall systems to mitigate vulnerabilities.

  • Diagnose connectivity issues, packet drops, and misconfigured policies.

  • Troubleshoot firewall-related issues affecting network performance or connectivity.

  • Document firewall architecture, configurations, change management activities, and incident response actions.

  • Remote Access/VPN Management

  • Build and maintain IPsec and SSL VPNs, both site-to-site and client-based.

  • Configure, deploy, and maintain Virtual Private Network (VPN) solutions (e.g., IPsec, SSL VPN, remote access, site-to-site).

  • Implement and enforce security policies for Remote Access/VPN access in accordance with organizational standards.

  • Manage Remote Access/VPN user access, including provisioning, deprovisioning, and authentication setting protocols such as LDAP, RADIUS, or SAML.

  • Apply firmware updates and security patches to Remote Access/VPN appliances and associated infrastructure.

  • Monitor Remote Access/VPN performance, availability, and usage to ensure secure and reliable connectivity.

  • Integrate Remote Access/VPN solutions with identity and access management (IAM) systems and multi-factor authentication (MFA) like Duo, RSA SecurID, or Azure MFA.

  • Troubleshoot Remote Access/VPN-related issues affecting remote users or inter-site communications.

  • Maintain documentation of Remote Access/VPN architecture, configurations, changes, and procedures.

  • Conduct regular audits of firewall and remote access/VPN configurations to ensure compliance with internal and regulatory standards.

  • Researches and analyzes cyber security threat indicators and their behaviors for the prevention, detection, containment, and correction of security breaches, and recommends threat mitigation strategies.

  • Assesses new security technologies to determine potential value for the enterprise.

  • Performs related duties as assigned., * Subject to normal garage, shop, and terminal hazards such as noise, dust, grease, moving vehicles, etc. when working in bus/rail workshops, garages, and terminals.

EQUIPMENT, TOOLS, AND MATERIALS UTILIZED

  • Personal computer and related software as needed. Additional Details Employees and/or union members will be given priority consideration in the hiring process, per the applicable labor contracts.

Final salary will be determined in part by the qualifications of the selected candidate and may be higher or lower than target.

Applicants, if hired,must comply with CTA’s residency ordinance.

CTA IS AN EQUAL OPPORTUNITY EMPLOYER

No employee or applicant for employment will be discriminated against because of race, color, creed, religion, sex, marital status, national origin, sexual orientation, ancestry, age, unfavorable military discharge, disability or any other status protected by federal, state, or local laws; except where a bona fide occupational qualification exists We are committed to providing an inclusive environment for our workforce and supporting the communities we serve. CTA will make reasonable accommodations for the known disabilities of otherwise qualified applicants for employment as well as its employees, unless undue hardship would result. If you require an accommodation in the application or hiring process, please contact arc@transitchicago.com prior to the submission of your application or upon notification of your actual test date. CTA will work with you to determine if an accommodation can be provided.

During the hiring process, CTA’s Human Resources department will contact candidates with next steps . Failure to respond to these correspondences in a timely fashion may result in your application being closed out for non-responsiveness.

Requirements

  • Bachelor’s degree in information security/cyber security, information technology, computer science or related field required.

  • Cisco Certified Specialist - Security Core, Cisco Certified Network Professional (CCNP) Security, Cisco Certified CyberOps Professional, or similar.

  • Three to five years of experience in firewall administration or related position for large enterprises.

PHYSICAL REQUIREMENTS

  • Requires remaining in a stationary position for extended periods of time and constantly operating a computer.

  • May be required to travel to various field locations.

  • Must be able to lift, maneuver and carry material weight up to 50 pounds.

  • Service Area Requirement: Exempt (Non-Union) employees must live within the boundaries of the CTA Statutory Service Area either at the time of employment or within 6 months of beginning employment at CTA.

KNOWLEDGE, SKILLS, AND ABILITIES

  • Be a proficient problem-solver that can work autonomously and with others.

  • Knowledge of network applications and protocols, configuration, routers, logging, monitoring, administration.

  • Knowledge of Syslog and SIEM principles, operations, configuration, and usage.

  • Knowledge of operating systems such as Unix, Linux, Microsoft Windows, VMware and Cisco.

  • Detailed knowledge of Command Line Interface syntax and use.

  • Awareness of NIST, ISO 27001, PCI-DSS, HIPAA, or similar frameworks.

  • Knowledge of encryption technology, tools, and techniques.

  • Knowledge of certificate-based authentication, pre-shared keys, IKE/IPsec negotiation, and TLS.

  • Knowledge of ACLs, security zones, policies, rule base configuration, and best practices.

  • Knowledge of Defense-in-depth, zero trust, intrusion prevention, NAT, packet filtering, and stateful inspection.

  • Ability to maintain absolute confidentiality of sensitive files, data and materials accessed, discussed, or observed, and while adhering to security policies and procedures.

Benefits & conditions

$120,565.16, * General office environment.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on diversityjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:03 min

Microsoft integrating native Unix coreutils into Windows environments

Chris Heilmann Chris Heilmann +2 · LIVE

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:04 min

Defining timestamps and the international standard format

Denny Biasiolli Denny Biasiolli · Europe 2026 Virtual

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

Videos

See all

Related articles

See all