Network Security Engineer
PB Search ·www.pbsearch.com
Apply directHigh Profile mid-sized Asset Management Firm seeks Network Security Engineer with strong Threat Vulnerability Management experience.
In a very hands-on capacity you will responsible for the support and administration of several core network security tools... interesting projects, very professional and high-end environment.
You will be responsible for the administration, engineering, and support of security initiatives related to Threat Vulnerability Management and Network Security.
This is a full-time direct hire role with a targeted base salary of 130,000 - 140,000 plus an annual bonus and a great benefits package (8% company retirement contribution, 4 weeks vacation,...).
In summary:
- Work closely with Information Security to ensure a secure enterprise network environment through the enforcement of network security controls, threat and vulnerability management (TVM), and logging and monitoring for applications, servers and network devices through the SIEM process.
- Leverage and implement tools that automate and support Network Security, TVM and SIEM processes, helping to develop capabilities to early detect and quickly respond to potential cybersecurity breaches and incidents.
- Implement appropriate changes, updates, and upgrades in response to vulnerabilities and incursions; help to gather evidence for audits and to remediate audit issues.
- Support the process owners for Network Security, Threat Vulnerability Management and and SIEM by actively participating in risk assessments
- Participate in the organization and coordination of penetration testing.
- Review and respond to alerts generated by the Cyber Security Operations Center teams.
- Review, respond and resolve alerts originating Carbon Black products to ensure appropriate system processing and applications requirements are met.
- Ensure Microsoft Defender / McAfee alerts are monitored and resolved.
- Assist and deploy standard firewall rules.
- Implement appropriate changes, updates, and upgrades in response to vulnerabilities and incursions.
- Provide day-to-day support of network security systems in a backup capacity.
- Follow run books for deployments and/or system upgrades during and off-hours.
- Participate in metric collection to demonstrate situational awareness to management regarding current threats and risks.
Requirements include:
- Experience with Vulnerability Management solutions and relevant work experience with tools that provide vulnerability detection and reporting, logging and monitoring, and other cybersecurity solutions such as IPS/IDS, anti-virus and DLP.
- Working knowledge of next-gen firewall administration and configuration; some related Palo Alto Firewall administration (Panorama), network security, operations and management best practices preferred
- Endpoint management and best practices: McAfee Endpoint Protection, Microsoft Defender, Carbon Black, and LogRhythm.
- Understanding of network design, infrastructure, Active Directory and Group Policy
- Knowledge of enterprise patching / updates is a must
- Scripting skills (Python,,...)
- Working knowledge of security protocols, authentication, authorization and security.
- Strong hands-on experience with public cloud platforms (AWS/Azure) in production environments.
- Preferred certifications or professional training: ITIL Foundation and any training with Palo Alto, Carbon Black, Tenable/Nessus and/or LogRhythm
- Ability to resolve security alerts in a timely manner and escalate events that could lead to a security breach.
- Analytical skills to troubleshoot events and correlate user or system activity.
- Hands-on experience deploying firewall rules to meet business and technical requirements.
- Good Project Management skills
- Completed Bachelor’s degree with Computer Science or related (math, engineering,...) course of study.
*This is a hybrid role onsite ~3 days per week in NYC