Overview
Network Security Engineer – K). Primarily responsible for the day-to-day management of a large enterprise multi-vendor firewall environment. Interacts with business users and vendors to identify, define requirements, and expectations of new and existing network systems security needs. Participates in design, implementation, and troubleshooting for complex firewall solutions. Assists in the development and strategy of network firewalls through system monitoring, maintenance, and upgrades.
Responsibilities
- Work closely with other team members to design, build and maintain new and existing network security technology.
- Create and deploy firewall standards for internet, datacenter, and cloud connectivity.
- Participate in security and network incidents, response, and remediation.
- Design, test, and deploy network and security solutions following the defined change control process.
- Conduct requirements gathering, analyze, and propose solutions to networking security needs.
- Provide capacity planning for firewalls.
- Monitor, analyze, and report metrics of network firewall services.
- Complete work requests submitted via the Service Request System.
- Create and maintain comprehensive documentation related to the network security infrastructure.
- Participate in on-call service rotation; provide 24x7 production support on a rotating basis.
- Perform occasional night or weekend work as required by the environment.
Additional Responsibilities
- Performs other duties as assigned.
- Complies with all policies and standards.
- Refer to department documentation during orientation for specific duties and responsibilities.
- Abide by all requirements to safely and securely maintain Protected Health Information (PHI) for patients; annual training and UH policies address appropriate use of PHI in the workplace.
Education
- Bachelor's Degree preferably in Information Technology or related field with an interest in Information Technology Networks (Required) or
- 10 years of relevant experience can be substituted in lieu of the degree (Required)
Work Experience
- 10+ years of Enterprise Network Security infrastructure experience, including design, implementation, ongoing management and troubleshooting in a mid to large-sized company (Required)
Knowledge, Skills, & Abilities
- Proficiency with Palo Alto or similar enterprise-grade firewalls (Required).
- Proficiency with Cisco or similar enterprise-grade switches and routers (Required).
- Extensive experience with PAN Palo Alto Networks and Cisco firewalls.
- Experience managing on-prem and cloud firewalls and applying security best practices.
- Experience configuring, deploying, and supporting remote connectivity for client-to-site and site-to-site VPNs.
- Experience with firewall management tools and technologies such as Panorama, Firemon, Prisma Access, IPSec, Global Protect VPN, Cisco AnyConnect.
- Experience with networking technologies (e.g., F5, Cisco switching & routing, ACI, STP, EIGRP, OSPF, BGP, MPLS, TCP/IP, DHCP, DNS, QoS, HSRP, VRRP, LACP, ACLs).
- Practical experience using network monitoring tools such as SolarWinds, Stealthwatch, LiveAction, Splunk, Syslog-ng, Viavi, and Wireshark.
Licenses and Certifications
- Cisco Certified Networking Professional (CCNP) Enterprise, CCNP Security, CyberOps Professional (Preferred Upon Hire).
- Driver's License (Valid) with reliable transportation (Required).
- Palo Alto Preferred Certifications: PCNSE, PCCSE, PCSAE (Preferred Upon Hire).
Physical Demands
- Standing Occasionally
- Walking Occasionally
- Sitting Constantly
- Lifting up to 20 lbs occasionally
- Carrying up to 20 lbs occasionally
- Pushing up to 20 lbs occasionally
- Pulling up to 20 lbs occasionally
- Climbing Rarely
- Balancing Occasionally
- Stooping Occasionally
- Kneeling Occasionally
- Crouching Occasionally
- Crawling Occasionally
- Reaching Occasionally
- Handling and Grasping Occasionally
- Feeling Occasionally
- Talking and Hearing Constantly
- Repetitive motions Frequently
- Eye/hand/foot coordination Frequently
Travel Requirements
- 10%