Network Security Engineer 1/2

The University Of Connecticut
Mansfield, United States of America
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Junior
Compensation
$ 110K

Job location

Mansfield, United States of America

Tech stack

PHP
API
Amazon Web Services (AWS)
Apache HTTP Server
Azure
Complex Networks
Computer Security
Computer Programming
Computer Networks
Computer Telephony Integration
System Configuration
Desktop Computing
DNS
Perl
Identity and Access Management
IIS
Intrusion Detection Systems
Virtual Private Networks (VPN)
Python
Network Security
Lightweight Directory Access Protocols (LDAP)
Log Analysis
Simple Mail Transfer Protocols
NetFlow
Network Architecture
Network Planning and Design
Network Monitoring
Packet Analyzer
Powershell
Security Information and Event Management
SQL Databases
Systems Integration
Terminal Access Controller Access-Control System (TACACS)
Data Logging
Scripting (Bash/Python/Go/Ruby)
Transport Layer Security
Identity Services Engine
Enterprise Software Applications
Software Security
Firewalls (Computer Science)
Juniper
NetScout
Cisco Firewalls
Fortinet
Firewall Services Module
Splunk
Cisco networks

Job description

Under the direction of the Chief Information Security Officer, the Network Security Engineer is responsible for the development and operation of UConn's Network Security (NetSec) infrastructure and systems. The engineer deploys and manages highly available network security technologies to support secure network and secure digital communication at the university. The role will assess, develop, deploy and maintain network security systems including firewalls, site to site VPN, client VPN, IDP, IDS, network detection and response (NDR), varied firewall rulesets, access control rulesets, and related systems.

The Network Security Engineer is responsible for investigating a diverse range of technical issues across multiple platforms and working with clients who have a wide range of technical proficiency. The engineer works among a team of skilled information security and network professionals to address problems within a complex network environment and develop solutions that will operate effectively in the environment.

The Network Security Engineer is responsible for processes and procedures to ensure the continuous improvement of monitoring, detection, and mitigation capabilities network communications. The engineer plans, organizes and establishes priorities related to an assignment; works independently with minimal outside support; and handles sensitive information in a confidential manner., Network Security Engineer 1

  • Uses security tools to identify, investigate, and mitigate threats to the environment.
  • Supports UConn's security infrastructure, including but not limited to, firewalls, VPNs, IDS / IDP / NDR, logging, SIEM, and identity access management.
  • Monitor and respond to threats, events, alerts and incidents.
  • Use SIEM, IDS/IDP, EDR, NDR and Firewall systems to identify threats and attacks.
  • Assist in containment and mitigation activities.
  • Patch and update firewalls.
  • Maintain and troubleshoot firewall rules and configurations.
  • Maintain and troubleshoot VPN configurations.
  • Triage and respond to service requests from customers and/or internal teams.
  • Maintain awareness of potential and developing threats across industry and in general.
  • Participate in incident response activities as required for cyber security incidents.
  • Maintain appropriate documentation and diagrams of infrastructure and security systems.
  • Promote security awareness to improve and ensure system security and best practices.
  • Interact with customers, forge relationships, and contribute to the development of the community.
  • May participate in on-call rotation, after-hour changes, and after-hour escalations as needed.
  • Other related duties as assigned.

Network Security Engineer 2 (additional responsibilities inclusive of Engineer 1)

  • Administers, develops and supports UConn's security infrastructure, including but not limited to, firewalls, VPNs, IDS / IDP / NDR, firewall management, logging, SIEM, and identity access management.
  • Research, recommend, implement, and support security tools and counter measures to reflect the evolving security terrain and trends; perform network security testing and reports as needed.
  • Develop scripts or deploy programs to assist with automation, provisioning, and/or telemetry, and to ensure integrity of resources to dependent systems.
  • Produce and maintain detailed engineering plans, operating procedures, diagrams, models, and standards as they relate to network security design, deployment, and operations.
  • Proactively analyze network traffic, system logs, to identify threats, intrusions, and/or compromises.
  • Performs analysis of security incidents to help determine root cause and prevent future occurrences.
  • Triage and respond to service requests from customers and/or internal teams.
  • Maintain awareness of potential and developing threats across industries and in general.
  • Participate in cyber security incident response activities as required.
  • Maintain appropriate documentation and diagrams of infrastructure and security systems.
  • Promote security awareness to improve and ensure system security and best practices.
  • Participate in on-call rotation, after-hour changes, and after-hour escalations as needed.
  • Other related duties as assigned.

RELATED SKILLS AND COMPETENCIES

  • Problem Solving: Demonstrates sound analytic and diagnostic skills dealing with issues that are loosely defined and/or where information is available but must be further manipulated. Once decisions are made, follow and direct action to implement intended results. Breaks a problem down to manageable pieces and implements effective, timely solutions. Openly and directly confront issues until resolved.
  • Team Orientation: Builds relationships with peers and other departments to achieve objectives. Balances team and individual responsibilities. Exhibits objectivity and openness to others' views. Gives and welcomes feedback. Puts success of team above self. Responsibilities are assigned with some latitude for setting priorities and decision-making using established policies and procedures. Results are reviewed with next-level team lead/manager for clarification and direction before proceeding.
  • Planning and Project Management: Works with, or serves as, the project lead in identifying those project tasks that are most important, establishes clear priorities and understands the larger picture. Executes project tasks and creates documentation as required.
  • Physical Demands: This position involves extended periods of sitting and the extensive use of computers and office equipment. May involve stooping, kneeling, crouching and/or working on step ladders. Involves close vision, color vision, depth perception, and focus adjustment. Must be able to lift 35 lbs. to shoulder height., This is a full-time, permanent position located at the Storrs Campus in Storrs, CT. This position is on-site. THIS IS NOT A REMOTE POSITION. The position may be eligible for a hybrid work schedule under applicable bargaining agreements, not less than an annual review, and management approval. This position may require you to travel in-state and you may be required to work irregular hours to support operational or security activities and initiatives.

Requirements

Network Security Engineer 1

  • Must meet and maintain eligibility requirements associated with working on CUI/CTI data, such as but not limited to holding U.S. citizenship or permanent residency, at the level required and as determined by the Facility Security Officer and the Office of Export Control.

  • Bachelor's degree and two (2) years of related experience (IT/Security), OR Associate's degree and two (4) years of related experience (IT/Security), OR Six (6) years of related experience (IT/Security).

  • Demonstrated knowledge of network architecture concepts including topology, protocols, components, and principles.

  • Experience creating, troubleshooting, and managing firewall rules.

  • Experience setting up, installing, configuring, deploying and patching firewalls.

  • Knowledge of information security concepts including confidentiality, accessibility, integrity, threats, risk, authentication, authorization and others.

  • Knowledge of detection and protection techniques.

  • Knowledge of information security event triage and incident response concepts.

  • Demonstrated technical, analytical, interpersonal, and organizational skills.

Network Security Engineer 2 (inclusive of Network Security Engineer 1)

  • Bachelor's degree and two (2) years of related experience (IT/Security), OR Associate's degree and four (4) years of related experience (IT/Security), OR Six (6) years of related experience (IT/Security).

  • One (1) or more years of experience working in an information security role in the network security domain.

  • Experience applying knowledge of network architecture concepts including topology, protocols, components, and principles.

  • Experience setting up, installing, configuring, deploying and patching firewalls in an enterprise environment.

  • Experience applying knowledge of firewalls, VPN, network proxies, and network design.

  • Experience with network flow data (i.e., NetFlow, sFlow, IPFIX) or related forms of flow records and session summary data.

  • Demonstrated understanding of diagnostic and troubleshooting tools, such as the ability to perform detailed analysis on packet capture data, SIM/SIEM log analysis, and failure diagnosis.

  • Experience managing enterprise security devices/platforms from vendors such as Fortinet, Palo Alto, Arbor/NetScout, f5, iBoss, Splunk, Cisco and/or Juniper.

  • Demonstrated programming/development/scripting skills (Python, PHP, PERL, and/or Powershell).

  • Experience in security analysis, policies, procedures and standards.

  • Demonstrated technical, analytical, interpersonal, and organizational skills.

PREFERRED QUALIFICATIONS

Network Security Engineer 1

  • Bachelor's degree or higher in a Science, Technology, Engineering, Math (STEM) field.

  • Experience working with network flow data.

  • Experience using NDR/XDR technologies.

  • Demonstrated ability to stay informed in securing evolving technologies.

  • Experience working in a higher education environment.

Network Security Engineer 2 (inclusive of Network Security Engineer 1)

  • Demonstrated understanding of a wide array of enterprise applications/services including DNS, SMTP, SSL/TLS, IIS, Apache, LDAP, CAS, Entra, Azure/AWS, SQL, RADIUS, TACACS, etc.

  • Demonstrated understanding of related security domain concepts including Identity & Access Management, Security Operations, Application Security, Risk Management, and Incident Management.

  • Experience securing on-prem and cloud provider-based networks.

  • Experience configuring and troubleshooting client and point to point VPNs.

  • Experience administering and deploying Palo Alto firewalls.

  • Experience administering and deploying Cisco firewalls.

  • Experience administering and deploying Fortinet firewalls.

  • Experience administering and deploying Meraki network gear.

  • Experience deploying, administering, operating, and troubleshooting firewall management systems such as Tufin, Panorama, Fortimanager, and Cisco FMC.

  • Experience deploying, administering, operating, integrating and troubleshooting Cisco Anyware and Cisco ISE.

  • Experience with NDR/XDR (ie SNA/Stealthwatch, Vectra).

  • Experience with network monitoring platforms (ie LogicMonitor).

  • Experience with automation using vendor API's.

  • Experience in contract negotiations, pricing, terms, and conditions.

  • Professional certifications in Network Security or related information security domains.

Benefits & conditions

Pulled from the full job description Retirement plan Paid sick time Paid holidays, * Network Security Engineer 1 (Information Security Analyst 1 - UCP 4): $67,666 to $87,966

  • Network Security Engineer 2 (Information Security Analyst 2 - UCP 6): $84,880 to $110,344

Note: Please indicate the role you are applying for in your cover letter. All minimum qualifications must be met at the applicable level to be eligible for consideration at that level. Applicable role will be verified by the hiring committee with respect for qualifications and demonstrated experience. Final salary will be commensurate with experience., * Defined contribution with employer match or defined benefit program retirement options

  • Excellent and affordable healthcare options
  • 35-hour work week
  • 22 paid vacation days per year, paid sick leave, and 13 paid holidays
  • Employee and dependent tuition waivers
  • A highly desirable work environment and work-life balance, This is a full-time, end-dated position with the possibility of renewal subject to performance and funding. The University offers a competitive salary, and outstanding benefits, including employee and dependent tuition waivers at UConn, and a highly desirable work environment.

Other rights, terms, and conditions of employment are contained in the collective bargaining agreement between the University of Connecticut and the University of Connecticut Professional Employees Association (UCPEA).

Apply for this position