Unknown Company

Network Security Engineer (Network & Cybersecurity)

san antonio, tx • Posted 2 weeks ago
Remote Contract IT & Technology

Baker Engineering and Risk Consultants Inc BakerRisk is a global provider of process safety and risk management services to companies in the petroleum and chemical industries as well as engineering and testing services for government agencies and private companies involved with hazardous materials Utilizing advanced methodologies and proprietary in house tools BakerRisk engineers assess the consequences and risks associated with potentially catastrophic events including explosions fires and toxic material releases

Position Summary

BakerRisk is seeking a highly skilled and motivated Network Security Engineer with strong networking fundamentals who has evolved into a cybersecurity focused practitioner and is comfortable owning security operations Microsoft identity security and VMWareCloud networking in a small enterprise environment to join our Global Management Network team This role is responsible for the design implementation administration and security of BakerRisks enterprise network infrastructure cloud connectivity cybersecurity policy implementation tools & infrastructure The ideal candidate will possess strong experience with enterprise networking technologies security architecture firewalls cloud networking and security monitoring with a successful track record working in a team oriented environment This individual will play a key role in protecting critical business systems while supporting a reliable scalable and secure technology environment across multiple office locations datacenters and cloud platforms This position offers the opportunity to work with modern technologies including Cisco Meraki Arista VMware Microsoft Azure SD WAN network segmentation Zero Trust principles EntraID MS365 and enterprise cybersecurity solutions

Essential Responsibilities

  • Network Engineering & Infrastructure Design implement maintain and troubleshoot enterprise LAN WAN wireless and data center network infrastructure
  • Configure and manage Cisco Meraki and Arista network devices
  • Administer VPN technologies and secure remote access solutions
  • Manage SD WAN connectivity between offices cloud environments and datacenters
  • Maintain IP address management IPAM network documentation and infrastructure diagrams
  • Monitor network performance and availability while proactively identifying capacity and reliability improvements
  • Implement VMWare NSX NSX
  • Cybersecurity & Network Protection Serve as the primary technical owner for cybersecurity operations security controls and vulnerability management by designing implementing and continuously enhancing firewalls IDSIPS network segmentation Zero Trust architecture and other security initiatives in partnership with IT management and architecture leadership
  • Administer and maintain perimeter security devices and cloud security controls
  • Support vulnerability management remediation and risk reduction initiatives
  • Participate in incident detection investigation response and recovery activities
  • Monitor security alerts and work with internal stakeholders to address threats and vulnerabilities
  • Implement security hardening standards across network and cloud platforms
  • Assist with regulatory and compliance initiatives including NIST 800 171 DFARS cybersecurity assessments and security audits
  • Identity & Microsoft Security Administer and secure Active Directory and Microsoft Entra ID environments
  • Implement and support identity security controls including MFA Conditional Access privileged access management and identity governance
  • Support security compliance and operational controls across Microsoft 365 services including Exchange Online Teams SharePoint and OneDrive
  • Leverage Crowdstrike Falcon and related security platforms to improve detection response visibility and risk reduction
  • Partner with infrastructure teams to improve identity security posture and reduce organizational risk
  • Cloud & Hybrid Infrastructure Design configure and manage MS365 Azure & VCF networking and hybrid connectivity solutions including virtual networks VPNs private connectivity network segmentation and secure integration between cloud and on premises environments
  • Implement and maintain cloud security architectures and controls that protect VCF Azure hybrid infrastructure and business critical services
  • Collaborate with infrastructure and architecture teams to ensure secure scalable and resilient cloud and hybrid deployments
  • Documentation & Operational Excellence Develop and maintain detailed network diagrams standards procedures and operational documentation within ManageEngine OpsManager
  • Participate in change management and project planning activities
  • Manage vendor relationships support contracts and technology evaluations
  • Provide Tier III escalation support for complex networking and security issues
  • Participate in an on call rotation and support after hours maintenance as needed

Required Qualifications

  • Bachelors degree or equivalent experience
  • 5 years of enterprise network engineering experience
  • Demonstrated ability to balance networking cybersecurity cloud technologies operational support documentation and project work within a small or mid sized IT organization
  • Strong experience with Cisco networking technologies including routing switching VPNs firewalls and network security controls
  • Experience with Microsoft Azure networking hybrid cloud connectivity and secure integration between cloud and on premises environments
  • Experience supporting Active Directory and Microsoft Entra ID administration and security
  • Experience implementing identity security controls including Multi Factor Authentication MFA Conditional Access privileged access controls and secure authentication practices
  • Experience securing Microsoft 365 environments and cloud based collaboration platforms
  • Knowledge of network and cybersecurity principles including Zero Trust network segmentation secure remote access infrastructure hardening and risk reduction
  • Experience with security monitoring vulnerability management remediation planning incident response and cybersecurity operations
  • Experience supporting cybersecurity compliance initiatives security assessments and NIST based security frameworks
  • Demonstrated ability to balance networking cybersecurity cloud technologies operational support documentation and project work in a small or mid sized IT organization
  • Strong troubleshooting analytical documentation verbal communication and written communication skills

Preferred Qualifications

  • Experience with Cisco Meraki and Arista networking platforms
  • Experience with VMware networking technologies including NSX network virtualization distributed firewalling overlay networking logical routing and micro segmentation
  • Experience with EDR CrowdStrike Falcon Microsoft Defender SIEM IDSIPS and security monitoring platforms
  • Familiarity with NIST Cybersecurity Framework NIST 800 171 CMMC and DFARS compliance requirements
  • Experience supporting multi site environments and datacenter operations
  • Experience with scripting and automation using PowerShell Python & ManageEngine or similar tools

Preferred Certifications

  • CCNP Enterprise
  • CCNP Security
  • CISSP
  • CompTIA Security
  • Microsoft Azure Administrator AZ 104
  • Microsoft Azure Security Engineer AZ 500
  • Palo Alto Fortinet or equivalent firewall certifications
  • VMWare vSphere or VCF Certification

What Success Looks Like

  • Within the first year this individual will Strengthen BakerRisks network security posture
  • Improve visibility into network and security events
  • Reduce organizational risk through improved segmentation and hardening
  • Assist with and help drive cybersecurity compliance initiatives including NIST 800 171 DFARS CMMC readiness activities security assessments remediation planning and audit preparation
  • Help modernize network and cloud infrastructure while maintaining high availability and performance

BakerRisk offers a competitive salary and benefit package including holiday vacation and sick leave pay medicaldental insurance 401k Employee Stock Ownership Plan ESOP and potential for a year end bonus Position and pay DOE

Equal opportunity employer All qualified applicants will receive consideration for employment without regard to sex race color religion national origin disability protected Veteran status age or any other characteristic protected by law

Additional Information For additional information please see our website at

#J-18808-Ljbffr

Network Security Engineer (Network & Cybersecurity) in san antonio at Unknown Company

This position is listed as contract and able to be worked remotely.

Back to Job Search