it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

12 jobs found

Email me jobs like this
Refine Search
Current Search
security engineer vulnerability detection hybrid
Network & Security Engineer
EAM-Mosca Corporation Hazleton, Pennsylvania
Job Description Job Description EAM-Mosca Corp. Title: - Network & Security Engineer Job Type: Full Time, Salaried Reporting Structure: Reports to IT Manager EAM-Mosca Corp., Hazle Township PA, a dynamic market leader in the area of end-of-line automated packaging machinery and consumable strapping solutions, is seeking a skilled and versatile Network & Security Engineer to join our growing team. EAM-Mosca is privately held and retains a unique, focused, entrepreneurial culture. EAM-Mosca also enjoys a blue-chip client base of highly successful North and South American manufacturing companies and has a portfolio of products applicable to a variety of end-use markets. The key to the ongoing success of the business is a system-based product portfolio featuring standard as well as custom engineered packaging machinery solutions and a superior consumable packaging product, complimented by quality technical service and readily available aftersales parts support. Job Summary : In this dual-focused role, you will be the backbone of our IT infrastructure, ensuring our network is fast, reliable, and highly secure. You will split your time between administering daily network operations and designing, implementing, and monitoring our cybersecurity defenses. This is an excellent opportunity for a proactive professional who thrives in a business environment, takes full ownership of projects, and enjoys balancing infrastructure management with proactive threat defense. The position requires you to be on site at our Hazle Township office. Roles and Responsibilities: Network Administration & Infrastructure Manage and maintain the company's infrastructure consisting of LAN, WAN, WLAN, switches, firewalls, and routers Monitor network performance and uptime, proactively troubleshooting connectivity, latency, and hardware issues Configure and support secure remote access solutions, including VPNs for remote offices and staff Handle network provisioning, including user access controls, VLAN segmentation, and IP address management (DHCP & DNS) Perform routine maintenance, firmware updates, patches, and backup/disaster recovery protocols Information Security & Threat Defense Design and enforce corporate security policies, access controls, and data protection strategies Monitor security alerts from firewalls and endpoint detection software to investigate and neutralize potential threats Conduct regular audits, vulnerability scans, and risk assessments to identify and patch system weaknesses Lead incident response efforts in the event of a security breach, malware infection, or unauthorized access attempt Promote security awareness by helping to educate internal staff on phishing and safe digital practices Profile and Background: A minimum of an Associate's degree. Bachelor's degree preferred. 3-5+ years working in Network Administration, System Engineering, or Network Security Certifications Preferred but not required: Comptia Security+, Comptia Network+, CCNA Knowledge, Skills & Abilities: Must be a team player Clear communication skills and able to explain technical risks to non-technical teams Ability to multi-task and work under strict deadlines Deep understanding of core networking concepts (TCP/IP, routing protocols, DHCP, DNS, and VLANS) Expertise in configuring firewalls, routers, and switches, intrusion detection/preventions systems (IDS/IPS), and endpoint security Familiar with securing cloud or hybrid environments is a strong plus Familiar with virtual machine technology and topologies Sophos XDR and Crowdstrike experience preferred Sonicwall and Aruba experience preferred Juniper Mist administration experience helpful All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Powered by JazzHR qyFsZkAXH4
09/16/2026
Full time
Job Description Job Description EAM-Mosca Corp. Title: - Network & Security Engineer Job Type: Full Time, Salaried Reporting Structure: Reports to IT Manager EAM-Mosca Corp., Hazle Township PA, a dynamic market leader in the area of end-of-line automated packaging machinery and consumable strapping solutions, is seeking a skilled and versatile Network & Security Engineer to join our growing team. EAM-Mosca is privately held and retains a unique, focused, entrepreneurial culture. EAM-Mosca also enjoys a blue-chip client base of highly successful North and South American manufacturing companies and has a portfolio of products applicable to a variety of end-use markets. The key to the ongoing success of the business is a system-based product portfolio featuring standard as well as custom engineered packaging machinery solutions and a superior consumable packaging product, complimented by quality technical service and readily available aftersales parts support. Job Summary : In this dual-focused role, you will be the backbone of our IT infrastructure, ensuring our network is fast, reliable, and highly secure. You will split your time between administering daily network operations and designing, implementing, and monitoring our cybersecurity defenses. This is an excellent opportunity for a proactive professional who thrives in a business environment, takes full ownership of projects, and enjoys balancing infrastructure management with proactive threat defense. The position requires you to be on site at our Hazle Township office. Roles and Responsibilities: Network Administration & Infrastructure Manage and maintain the company's infrastructure consisting of LAN, WAN, WLAN, switches, firewalls, and routers Monitor network performance and uptime, proactively troubleshooting connectivity, latency, and hardware issues Configure and support secure remote access solutions, including VPNs for remote offices and staff Handle network provisioning, including user access controls, VLAN segmentation, and IP address management (DHCP & DNS) Perform routine maintenance, firmware updates, patches, and backup/disaster recovery protocols Information Security & Threat Defense Design and enforce corporate security policies, access controls, and data protection strategies Monitor security alerts from firewalls and endpoint detection software to investigate and neutralize potential threats Conduct regular audits, vulnerability scans, and risk assessments to identify and patch system weaknesses Lead incident response efforts in the event of a security breach, malware infection, or unauthorized access attempt Promote security awareness by helping to educate internal staff on phishing and safe digital practices Profile and Background: A minimum of an Associate's degree. Bachelor's degree preferred. 3-5+ years working in Network Administration, System Engineering, or Network Security Certifications Preferred but not required: Comptia Security+, Comptia Network+, CCNA Knowledge, Skills & Abilities: Must be a team player Clear communication skills and able to explain technical risks to non-technical teams Ability to multi-task and work under strict deadlines Deep understanding of core networking concepts (TCP/IP, routing protocols, DHCP, DNS, and VLANS) Expertise in configuring firewalls, routers, and switches, intrusion detection/preventions systems (IDS/IPS), and endpoint security Familiar with securing cloud or hybrid environments is a strong plus Familiar with virtual machine technology and topologies Sophos XDR and Crowdstrike experience preferred Sonicwall and Aruba experience preferred Juniper Mist administration experience helpful All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Powered by JazzHR qyFsZkAXH4
Network & Cybersecurity Systems Engineer
Evolv Technologies Inc. Waltham, Massachusetts
Job Description Job Description The Elevator Pitch Are you ready to own the network and cybersecurity backbone of a company that's redefining security technology? Do you thrive at the intersection of network engineering, cybersecurity operations, and compliance-where your work directly reduces risk and keeps the business resilient against an ever-changing threat landscape? Evolv is seeking a Network & Cybersecurity Engineer to design, implement, and defend our network infrastructure and security tooling. You'll be the technical owner of Evolv's network and security posture-from firewalls and access control to identity governance and threat detection-reporting to the Senior Director of Cybersecurity & Technology. This is a pivotal role in maturing Evolv's security program to meet the evolving demands of the business and our growing compliance obligations. You'll partner closely with the Systems Engineer and the rest of the IT team, and serve as the subject matter expert on networking, enterprise cybersecurity, and compliance tooling. If you're energized by staying ahead of emerging threats and building durable, well-governed security controls, this role is for you. Success in the Role: What are performance outcomes over the first 6-12 months you will work toward completing? In the first 30 days, you will: Get to know the IT and security team and the tools/platforms currently in use Start building relationships with key stakeholders across the company, especially R&D and Legal/Compliance Learn Evolv's compliance commitments and ongoing authorization efforts, and how best to support them Gain familiarity with the current network/security toolstack: firewalls (Palo Alto), switching (Cisco/Meraki), NAC, VPN/ZTNA, identity platforms (Okta, Entra ID), SIEM/EDR/DLP tooling, and the MDR relationship Within 3 months, you will: Begin implementing or improving network and security controls that measurably reduce risk Build trust-based relationships with peers in IT and stakeholders across business units Become the established subject matter expert on network security and compliance tooling at Evolv Take ownership of the MDR relationship and escalated detection response By the end of the first year, you will: Be recognized as the trusted subject matter expert across network infrastructure, and security operations Have driven measurable improvements to Evolv's security posture and compliance readiness Successfully supported compliance requirements and audit readiness, partnering closely with Legal/Compliance and R&D Documented network and security architecture, processes, and runbooks that reduce single points of failure Be seen as the go-to resource for network security questions, escalations, and best-practice guidance The Work: What type of work will you be doing? What assignments, requirements, or skills will you be performing on a regular basis? Infrastructure, Security & Compliance: Design, implement, and maintain network infrastructure: firewalls (Palo Alto), switching (Cisco/Meraki), NAC, and VPN/ZTNA solutions Administer identity and access: Okta/Entra ID, Conditional Access policies, MFA enforcement, identity lifecycle management, and IGA Own security tooling and controls: SIEM, EDR, DLP, and vulnerability management, aligned to CIS Controls, NIST CSF, and other relevant compliance frameworks Manage the MDR relationship and respond to escalated detections Drive the IT process and policy redesign required to meet current compliance requirements, and to support additional frameworks as those efforts come online, in partnership with Legal/Compliance Harden AWS/Azure environments from a security perspective: IAM least-privilege, VPC/network security, Azure Policy Provide front-line escalation support and mentoring to IT teammates; maintain runbooks and documentation Assess technology and network risk across the company and recommend remediations Leadership, Team Structure & Culture You will join the IT organization as a direct report to the Senior Director of Cybersecurity & Technology, working alongside a Systems Engineer peer who owns day-to-day systems and endpoint operations. This is a hands-on, collaborative team that takes security and operational excellence seriously. This is a senior individual contributor role focused on deep technical impact-your job is to own and mature Evolv's network security and cybersecurity posture through the systems, controls, and automation you build. You'll have meaningful autonomy over how you approach problems and are actively encouraged to bring creative solutions, identify improvement opportunities, and advocate for better ways of working. You'll work alongside teammates who share your drive for continuous improvement, and you'll have a manager who values initiative, trusts the team to execute, and wants to hear your ideas. Where is the role located? This role is based out of Evolv HQ in Waltham, Massachusetts. This is a hybrid role with an expectation of 3 days per week on-site. Fully remote candidates will not be considered. Compensation and Transparency Statement The base salary range for this full-time position is $102,000-$166,000. In addition to base salary, this role offers a competitive target bonus, equity, and a comprehensive benefits package. This range reflects our commitment to pay transparency and equity, in alignment with applicable state laws. Our compensation ranges are determined based on factors such as role, level, location, market benchmarks, and internal equity. The posted range represents the good-faith estimate of what we expect to pay for this role across U.S. locations. Actual compensation within the range will be based on the candidate's skills, experience, education, and geographic location. In accordance with state and local pay transparency laws-including those in California, Colorado, Massachusetts, New York, New Jersey, and others-we disclose salary ranges in all job postings and provide additional information upon request. During the hiring process, your recruiter will share: •The specific salary range for your preferred location •A general overview of our benefits and equity offerings •Insights into how compensation decisions are made, including factors that influence starting pay We are committed to fair pay practices, and we regularly review our compensation programs to ensure they are competitive, equitable, and aligned with our values. Benefits At Evolv, we're on a mission to help make public spaces safer through innovative security technology. So, we're looking for future teammates who embody our values, people who: Do the right thing, always; Put people first' Own it; Win together; and continue to Be bold, stay curious. Our Benefits Include : Equity as part of your total compensation package Medical, dental, and vision insurance Health Savings Account (HSA) A 401(k) plan (and 2% company match) Flexible Paid Time Off (PTO)- take the time you need to recharge, with manager approval and business needs in mind Quarterly stipend for perks and benefits that matter most to you Tuition reimbursement to support your ongoing learning and development Subscription to Calm Evolv Technology ("Evolv") is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind. We welcome and encourage diversity in the workplace, and all employment decisions are made without regard to race, color, religion, national, social or ethnic origin, sex (including pregnancy), age, disability, HIV Status, sexual orientation, gender identity and/or expression, veteran status, or any other status protected by law in the locations where we operate. Evolv will not tolerate discrimination or harassment based on any of these characteristics. Evolv is committed to offering an inclusive and accessible experience for all job seekers, including individuals with disabilities. If you need a reasonable accommodation as part of the job application process, please connect with us at . Evolv participates in E-verify for all employees after the completion of Form I-9.
09/15/2026
Full time
Job Description Job Description The Elevator Pitch Are you ready to own the network and cybersecurity backbone of a company that's redefining security technology? Do you thrive at the intersection of network engineering, cybersecurity operations, and compliance-where your work directly reduces risk and keeps the business resilient against an ever-changing threat landscape? Evolv is seeking a Network & Cybersecurity Engineer to design, implement, and defend our network infrastructure and security tooling. You'll be the technical owner of Evolv's network and security posture-from firewalls and access control to identity governance and threat detection-reporting to the Senior Director of Cybersecurity & Technology. This is a pivotal role in maturing Evolv's security program to meet the evolving demands of the business and our growing compliance obligations. You'll partner closely with the Systems Engineer and the rest of the IT team, and serve as the subject matter expert on networking, enterprise cybersecurity, and compliance tooling. If you're energized by staying ahead of emerging threats and building durable, well-governed security controls, this role is for you. Success in the Role: What are performance outcomes over the first 6-12 months you will work toward completing? In the first 30 days, you will: Get to know the IT and security team and the tools/platforms currently in use Start building relationships with key stakeholders across the company, especially R&D and Legal/Compliance Learn Evolv's compliance commitments and ongoing authorization efforts, and how best to support them Gain familiarity with the current network/security toolstack: firewalls (Palo Alto), switching (Cisco/Meraki), NAC, VPN/ZTNA, identity platforms (Okta, Entra ID), SIEM/EDR/DLP tooling, and the MDR relationship Within 3 months, you will: Begin implementing or improving network and security controls that measurably reduce risk Build trust-based relationships with peers in IT and stakeholders across business units Become the established subject matter expert on network security and compliance tooling at Evolv Take ownership of the MDR relationship and escalated detection response By the end of the first year, you will: Be recognized as the trusted subject matter expert across network infrastructure, and security operations Have driven measurable improvements to Evolv's security posture and compliance readiness Successfully supported compliance requirements and audit readiness, partnering closely with Legal/Compliance and R&D Documented network and security architecture, processes, and runbooks that reduce single points of failure Be seen as the go-to resource for network security questions, escalations, and best-practice guidance The Work: What type of work will you be doing? What assignments, requirements, or skills will you be performing on a regular basis? Infrastructure, Security & Compliance: Design, implement, and maintain network infrastructure: firewalls (Palo Alto), switching (Cisco/Meraki), NAC, and VPN/ZTNA solutions Administer identity and access: Okta/Entra ID, Conditional Access policies, MFA enforcement, identity lifecycle management, and IGA Own security tooling and controls: SIEM, EDR, DLP, and vulnerability management, aligned to CIS Controls, NIST CSF, and other relevant compliance frameworks Manage the MDR relationship and respond to escalated detections Drive the IT process and policy redesign required to meet current compliance requirements, and to support additional frameworks as those efforts come online, in partnership with Legal/Compliance Harden AWS/Azure environments from a security perspective: IAM least-privilege, VPC/network security, Azure Policy Provide front-line escalation support and mentoring to IT teammates; maintain runbooks and documentation Assess technology and network risk across the company and recommend remediations Leadership, Team Structure & Culture You will join the IT organization as a direct report to the Senior Director of Cybersecurity & Technology, working alongside a Systems Engineer peer who owns day-to-day systems and endpoint operations. This is a hands-on, collaborative team that takes security and operational excellence seriously. This is a senior individual contributor role focused on deep technical impact-your job is to own and mature Evolv's network security and cybersecurity posture through the systems, controls, and automation you build. You'll have meaningful autonomy over how you approach problems and are actively encouraged to bring creative solutions, identify improvement opportunities, and advocate for better ways of working. You'll work alongside teammates who share your drive for continuous improvement, and you'll have a manager who values initiative, trusts the team to execute, and wants to hear your ideas. Where is the role located? This role is based out of Evolv HQ in Waltham, Massachusetts. This is a hybrid role with an expectation of 3 days per week on-site. Fully remote candidates will not be considered. Compensation and Transparency Statement The base salary range for this full-time position is $102,000-$166,000. In addition to base salary, this role offers a competitive target bonus, equity, and a comprehensive benefits package. This range reflects our commitment to pay transparency and equity, in alignment with applicable state laws. Our compensation ranges are determined based on factors such as role, level, location, market benchmarks, and internal equity. The posted range represents the good-faith estimate of what we expect to pay for this role across U.S. locations. Actual compensation within the range will be based on the candidate's skills, experience, education, and geographic location. In accordance with state and local pay transparency laws-including those in California, Colorado, Massachusetts, New York, New Jersey, and others-we disclose salary ranges in all job postings and provide additional information upon request. During the hiring process, your recruiter will share: •The specific salary range for your preferred location •A general overview of our benefits and equity offerings •Insights into how compensation decisions are made, including factors that influence starting pay We are committed to fair pay practices, and we regularly review our compensation programs to ensure they are competitive, equitable, and aligned with our values. Benefits At Evolv, we're on a mission to help make public spaces safer through innovative security technology. So, we're looking for future teammates who embody our values, people who: Do the right thing, always; Put people first' Own it; Win together; and continue to Be bold, stay curious. Our Benefits Include : Equity as part of your total compensation package Medical, dental, and vision insurance Health Savings Account (HSA) A 401(k) plan (and 2% company match) Flexible Paid Time Off (PTO)- take the time you need to recharge, with manager approval and business needs in mind Quarterly stipend for perks and benefits that matter most to you Tuition reimbursement to support your ongoing learning and development Subscription to Calm Evolv Technology ("Evolv") is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind. We welcome and encourage diversity in the workplace, and all employment decisions are made without regard to race, color, religion, national, social or ethnic origin, sex (including pregnancy), age, disability, HIV Status, sexual orientation, gender identity and/or expression, veteran status, or any other status protected by law in the locations where we operate. Evolv will not tolerate discrimination or harassment based on any of these characteristics. Evolv is committed to offering an inclusive and accessible experience for all job seekers, including individuals with disabilities. If you need a reasonable accommodation as part of the job application process, please connect with us at . Evolv participates in E-verify for all employees after the completion of Form I-9.
Security Engineer / Network Engineer (DoD AWS GovCloud)
Credence Mc Lean, Virginia
Job Description Job Description Overview Join a team where innovation meets mission. Our AI, cloud, cyber, and modernization solutions save agencies thousands of hours, safeguard national security, and strengthen health and humanitarian missions worldwide. With more than 1,700+ team members, 1,500+ AI & data experts, and 100+ prime contracts, we deliver at scale and with purpose. We've been recognized as a Top Workplace by The Washington Post for six consecutive years and named to the Inc. 5000 list of Fastest-Growing Private Companies in 13 of the past 14 years. Credence is a welcoming environment for those looking to grow and make a meaningful impact. We encourage employees to push boundaries and help solve critical, world-changing federal challenges. Position Summary: Credence has an immediate opening for a highly skilled Security Engineer / Network Engineer to support and secure a mission-critical AWS GovCloud environment within a DoD-aligned ecosystem. This role will be responsible for implementing, maintaining, and enhancing security controls across cloud and network infrastructure, ensuring compliance with federal cybersecurity standards while supporting operational resilience. Responsibilities include, but are not limited to the duties listed below: - Design, implement, and maintain security controls across AWS GovCloud infrastructure and hybrid environments - Support security operations including monitoring, detection, and response activities - Configure and manage network security solutions including firewalls and WAFs - Integrate and support SIEM solutions for centralized logging and threat detection - Perform vulnerability management including scanning and remediation tracking - Ensure compliance with DoD requirements (STIGs, RMF, NIST) - Support incident response efforts including triage and containment - Collaborate with cross-functional teams to enhance security posture - Support continuous monitoring and audit readiness Requirements - Must have a Bachelor's degree in Computer Science, Information Technology, or a related field (or equivalent experience). - Must hold an Active DoD Secret or Top-Secret clearance - Must have a minimum of 5+ years of hands-on experience in cybersecurity, network engineering, or cloud security - Must be experience with AWS (GovCloud preferred) - Must have strong network security knowledge (firewalls, WAFs) - Must have experience with SIEM tools - Must have working knowledge of NIST 800-53, RMF, and STIGs Salary Range: $ 120,000.00 to $150,000.00 annually. Actual compensation will be determined based on the selected candidate's experience, education, skills, and overall qualifications. Please join us, as together we build a better world one mission at a time powered by Technology and its People! Benefits Health Care Plan (Medical, Dental & Vision) Retirement Plan (401k, IRA) Life Insurance (Basic, Voluntary & AD&D) Paid Time Off (Vacation, Sick & Public Holidays) Family Leave (Maternity, Paternity) Short Term & Long Term Disability Training & Development Wellness Resources
09/15/2026
Full time
Job Description Job Description Overview Join a team where innovation meets mission. Our AI, cloud, cyber, and modernization solutions save agencies thousands of hours, safeguard national security, and strengthen health and humanitarian missions worldwide. With more than 1,700+ team members, 1,500+ AI & data experts, and 100+ prime contracts, we deliver at scale and with purpose. We've been recognized as a Top Workplace by The Washington Post for six consecutive years and named to the Inc. 5000 list of Fastest-Growing Private Companies in 13 of the past 14 years. Credence is a welcoming environment for those looking to grow and make a meaningful impact. We encourage employees to push boundaries and help solve critical, world-changing federal challenges. Position Summary: Credence has an immediate opening for a highly skilled Security Engineer / Network Engineer to support and secure a mission-critical AWS GovCloud environment within a DoD-aligned ecosystem. This role will be responsible for implementing, maintaining, and enhancing security controls across cloud and network infrastructure, ensuring compliance with federal cybersecurity standards while supporting operational resilience. Responsibilities include, but are not limited to the duties listed below: - Design, implement, and maintain security controls across AWS GovCloud infrastructure and hybrid environments - Support security operations including monitoring, detection, and response activities - Configure and manage network security solutions including firewalls and WAFs - Integrate and support SIEM solutions for centralized logging and threat detection - Perform vulnerability management including scanning and remediation tracking - Ensure compliance with DoD requirements (STIGs, RMF, NIST) - Support incident response efforts including triage and containment - Collaborate with cross-functional teams to enhance security posture - Support continuous monitoring and audit readiness Requirements - Must have a Bachelor's degree in Computer Science, Information Technology, or a related field (or equivalent experience). - Must hold an Active DoD Secret or Top-Secret clearance - Must have a minimum of 5+ years of hands-on experience in cybersecurity, network engineering, or cloud security - Must be experience with AWS (GovCloud preferred) - Must have strong network security knowledge (firewalls, WAFs) - Must have experience with SIEM tools - Must have working knowledge of NIST 800-53, RMF, and STIGs Salary Range: $ 120,000.00 to $150,000.00 annually. Actual compensation will be determined based on the selected candidate's experience, education, skills, and overall qualifications. Please join us, as together we build a better world one mission at a time powered by Technology and its People! Benefits Health Care Plan (Medical, Dental & Vision) Retirement Plan (401k, IRA) Life Insurance (Basic, Voluntary & AD&D) Paid Time Off (Vacation, Sick & Public Holidays) Family Leave (Maternity, Paternity) Short Term & Long Term Disability Training & Development Wellness Resources
Network Security Engineer
Etched San Jose, California
Job Description Job Description About Etched Etched is building hardware for frontier intelligence. We co-design chips, racks, software, and manufacturing to deliver best-in-class throughput and latency across both prefill and decode workloads. Our first products are heavily focused on inference . Backed by hundreds of millions from top-tier investors and staffed by leading engineers, Etched is redefining the infrastructure layer for the fastest growing industry in history. Job Summary Etched's infrastructure spans some of the most sensitive compute environments in the industry: bare-metal HPC clusters running proprietary ASIC workloads, hybrid on-prem/cloud deployments, and internal toolchains that house irreplaceable chip design IP. As we scale from early silicon to production, securing these environments is foundational - not an afterthought. As our first dedicated Network Security Engineer, you will own the design and implementation of Etched's network security posture end to end. You'll work alongside the infrastructure team to harden our physical and virtual networks, enforce least-privilege access to chip design environments, and build the detection and response capabilities that keep our most sensitive assets safe. This is a high-ownership role for someone who wants to shape security architecture at a company building the compute infrastructure for the next decade of AI - not maintain someone else's stack. Key Responsibilities Design and implement a zero-trust network architecture across on-prem datacenters, multiple office locations, and multi-cloud platforms, including secure remote access that eliminates VPN sprawl without sacrificing engineer usability and speed Define and enforce network segmentation policies that isolate sensitive ASIC development workflows from general infrastructure, customer access, validation labs, and manufacturing infrastructure Balancing prevention and detection, deploy, tune, and operate NDR, IDS/IPS, and next-generation firewalls across our physical and virtual network fabric; build automation to continuously assess and enforce firewall rules, ACLs, and routing policies - treating network security configuration as code Integrate and operate EDR/XDR, MDM/MAM, SASE, and CASB tooling in partnership with end-user and IT teams, enforcing unified DLP policies and device compliance posture across endpoint, cloud, and network control planes to eliminate data exfiltration risk Own our vulnerability management process for network-layer exposure: scanning, prioritization, and remediation tracking in partnership with infrastructure engineers Lead incident response for network-layer security events: detection, containment, root-cause analysis, and post-incident hardening Partner with legal, compliance, and leadership to support regulatory requirements and customer security reviews as they arise Architect and deploy network segmentation for our HPC clusters, isolating EDA tool traffic, ASIC simulation workloads, and CI pipelines from each other and from the corporate network Architect and deploy a ZTNA-based corporate network that eliminates VPN sprawl and ensures end-user devices maintain a consistent security posture and seamless access to sensitive development environments - whether engineers are on-site, remote, or traveling - replacing location-dependent trust with continuous identity and device health verification Design and implement a scalable NDR pipeline that ingests flow data across bare-metal switches and cloud VPCs, feeds a centralized SIEM, and generates actionable alerts with low false-positive rates Develop runbooks and automated playbooks for the highest-probability incident scenarios - credential compromise, lateral movement, and exfiltration from IP-sensitive environments Integrate EDR/XDR telemetry with SASE enforcement and CASB inline controls to build a unified DLP detection and response pipeline spanning endpoints, cloud SaaS, and the corporate network Partner with end-user and IT teams to roll out MDM/MAM policies that containerize sensitive IP on engineer devices and enforce compliance-based conditional access across managed and unmanaged environments You may be a good fit if you have (Must-have qualifications) Bring deep, broad networking expertise - from low-level packet analysis and firewall log forensics to BGP configuration, multi-cloud networking, and CASB/SASE integration across a diverse SaaS landscape Have hands-on experience with the Fortinet ecosystem - firewalls, FortiSASE, FortiAPs, and switches - and are comfortable with Arista switch platforms, including configuration, EOS automation, and integration into a broader security architecture Treat security as an engineering discipline: you write code and automation rather than relying on point-and-click tooling, version-control your configurations, and develop intent-driven network automation Have experience securing high-value compute environments - datacenters, HPC clusters, semiconductor design environments, or similar settings where the cost of a breach is extremely high Have deployed and integrated EDR/XDR, MDM/MAM, SASE, and CASB tooling, and understand how to stitch them together into a unified DLP and access control framework that spans endpoints, cloud, and the network Have built or operated ZTNA-based access models and understand how to enforce consistent security posture across on-site, remote, and traveling users without degrading the experience for engineers Are comfortable owning your domain with minimal oversight: you can independently scope a project, identify the right tooling, and drive it to completion Have strong Linux fundamentals and understand how OS-level networking (iptables/nftables, network namespaces, eBPF) interacts with physical and virtual network security controls Have built or operated network security monitoring at scale - you know the difference between a good alert and noise, and you can architect a detection pipeline that surfaces real signal Can communicate risk clearly to both technical peers and non-technical leadership, and can translate security requirements into actionable infrastructure changes Strong candidates may also have experience with (Nice-to-have qualifications) Experience with EDA environments or semiconductor IP security Familiarity with cloud-native network security controls on AWS, GCP, or Azure (security groups, VPC flow logs, cloud firewalls, CSPM) Background in or exposure to NIST, SOC 2, or ISO 27001 frameworks Experience with eBPF-based network observability and security tooling Benefits Medical, dental, and vision packages with generous premium coverage $500 per month credit for waiving medical benefits Housing subsidy of $2k per month for those living within walking distance of the office Relocation support for those moving to San Jose (Santana Row) Various wellness benefits covering fitness, mental health, and more Daily lunch and dinner in our office Unlimited compute budget subject to ROI justification How we're different Etched believes in the Bitter Lesson. We are the first inference-focused frontier AI system. Our addressable market is the entirety of inference, unlike many of our competitors. We are a fully in-person team in San Jose (Santana Row), and greatly value engineering skills. We do not have boundaries between engineering and research, and we expect all of our technical staff to contribute to both and work across disciplines as needed. Compensation Range: $175K - $275K
09/15/2026
Full time
Job Description Job Description About Etched Etched is building hardware for frontier intelligence. We co-design chips, racks, software, and manufacturing to deliver best-in-class throughput and latency across both prefill and decode workloads. Our first products are heavily focused on inference . Backed by hundreds of millions from top-tier investors and staffed by leading engineers, Etched is redefining the infrastructure layer for the fastest growing industry in history. Job Summary Etched's infrastructure spans some of the most sensitive compute environments in the industry: bare-metal HPC clusters running proprietary ASIC workloads, hybrid on-prem/cloud deployments, and internal toolchains that house irreplaceable chip design IP. As we scale from early silicon to production, securing these environments is foundational - not an afterthought. As our first dedicated Network Security Engineer, you will own the design and implementation of Etched's network security posture end to end. You'll work alongside the infrastructure team to harden our physical and virtual networks, enforce least-privilege access to chip design environments, and build the detection and response capabilities that keep our most sensitive assets safe. This is a high-ownership role for someone who wants to shape security architecture at a company building the compute infrastructure for the next decade of AI - not maintain someone else's stack. Key Responsibilities Design and implement a zero-trust network architecture across on-prem datacenters, multiple office locations, and multi-cloud platforms, including secure remote access that eliminates VPN sprawl without sacrificing engineer usability and speed Define and enforce network segmentation policies that isolate sensitive ASIC development workflows from general infrastructure, customer access, validation labs, and manufacturing infrastructure Balancing prevention and detection, deploy, tune, and operate NDR, IDS/IPS, and next-generation firewalls across our physical and virtual network fabric; build automation to continuously assess and enforce firewall rules, ACLs, and routing policies - treating network security configuration as code Integrate and operate EDR/XDR, MDM/MAM, SASE, and CASB tooling in partnership with end-user and IT teams, enforcing unified DLP policies and device compliance posture across endpoint, cloud, and network control planes to eliminate data exfiltration risk Own our vulnerability management process for network-layer exposure: scanning, prioritization, and remediation tracking in partnership with infrastructure engineers Lead incident response for network-layer security events: detection, containment, root-cause analysis, and post-incident hardening Partner with legal, compliance, and leadership to support regulatory requirements and customer security reviews as they arise Architect and deploy network segmentation for our HPC clusters, isolating EDA tool traffic, ASIC simulation workloads, and CI pipelines from each other and from the corporate network Architect and deploy a ZTNA-based corporate network that eliminates VPN sprawl and ensures end-user devices maintain a consistent security posture and seamless access to sensitive development environments - whether engineers are on-site, remote, or traveling - replacing location-dependent trust with continuous identity and device health verification Design and implement a scalable NDR pipeline that ingests flow data across bare-metal switches and cloud VPCs, feeds a centralized SIEM, and generates actionable alerts with low false-positive rates Develop runbooks and automated playbooks for the highest-probability incident scenarios - credential compromise, lateral movement, and exfiltration from IP-sensitive environments Integrate EDR/XDR telemetry with SASE enforcement and CASB inline controls to build a unified DLP detection and response pipeline spanning endpoints, cloud SaaS, and the corporate network Partner with end-user and IT teams to roll out MDM/MAM policies that containerize sensitive IP on engineer devices and enforce compliance-based conditional access across managed and unmanaged environments You may be a good fit if you have (Must-have qualifications) Bring deep, broad networking expertise - from low-level packet analysis and firewall log forensics to BGP configuration, multi-cloud networking, and CASB/SASE integration across a diverse SaaS landscape Have hands-on experience with the Fortinet ecosystem - firewalls, FortiSASE, FortiAPs, and switches - and are comfortable with Arista switch platforms, including configuration, EOS automation, and integration into a broader security architecture Treat security as an engineering discipline: you write code and automation rather than relying on point-and-click tooling, version-control your configurations, and develop intent-driven network automation Have experience securing high-value compute environments - datacenters, HPC clusters, semiconductor design environments, or similar settings where the cost of a breach is extremely high Have deployed and integrated EDR/XDR, MDM/MAM, SASE, and CASB tooling, and understand how to stitch them together into a unified DLP and access control framework that spans endpoints, cloud, and the network Have built or operated ZTNA-based access models and understand how to enforce consistent security posture across on-site, remote, and traveling users without degrading the experience for engineers Are comfortable owning your domain with minimal oversight: you can independently scope a project, identify the right tooling, and drive it to completion Have strong Linux fundamentals and understand how OS-level networking (iptables/nftables, network namespaces, eBPF) interacts with physical and virtual network security controls Have built or operated network security monitoring at scale - you know the difference between a good alert and noise, and you can architect a detection pipeline that surfaces real signal Can communicate risk clearly to both technical peers and non-technical leadership, and can translate security requirements into actionable infrastructure changes Strong candidates may also have experience with (Nice-to-have qualifications) Experience with EDA environments or semiconductor IP security Familiarity with cloud-native network security controls on AWS, GCP, or Azure (security groups, VPC flow logs, cloud firewalls, CSPM) Background in or exposure to NIST, SOC 2, or ISO 27001 frameworks Experience with eBPF-based network observability and security tooling Benefits Medical, dental, and vision packages with generous premium coverage $500 per month credit for waiving medical benefits Housing subsidy of $2k per month for those living within walking distance of the office Relocation support for those moving to San Jose (Santana Row) Various wellness benefits covering fitness, mental health, and more Daily lunch and dinner in our office Unlimited compute budget subject to ROI justification How we're different Etched believes in the Bitter Lesson. We are the first inference-focused frontier AI system. Our addressable market is the entirety of inference, unlike many of our competitors. We are a fully in-person team in San Jose (Santana Row), and greatly value engineering skills. We do not have boundaries between engineering and research, and we expect all of our technical staff to contribute to both and work across disciplines as needed. Compensation Range: $175K - $275K
Network Security Engineer
Credence Mc Lean, Virginia
Job Description Job Description Overview Join a team where innovation meets mission. Our AI, cloud, cyber, and modernization solutions save agencies thousands of hours, safeguard national security, and strengthen health and humanitarian missions worldwide. With more than 1,700+ team members, 1,500+ AI & data experts, and 100+ prime contracts, we deliver at scale and with purpose. We've been recognized as a Top Workplace by The Washington Post for six consecutive years and named to the Inc. 5000 list of Fastest-Growing Private Companies in 13 of the past 14 years. Credence is a welcoming environment for those looking to grow and make a meaningful impact. We encourage employees to push boundaries and help solve critical, world-changing federal challenges. Position Summary Credence has an immediate opening for a Network Security Engineer to join our internal IT team. This individual will own enterprise network and security infrastructure across physical and cloud-hosted environments, administer multi-vendor firewalls, and maintain compliance-aligned controls within a CMMC Level 2 and SOC 2 audit environment. The role carries meaningful responsibility for SSP accuracy, ISSO support functions, and GCP organization-level governance. The ideal candidate combines deep network security expertise with documentation discipline and a proactive, compliance-first mindset Responsibilities:Network Infrastructure & Operations Provide technical ownership of the corporate WAN, LAN, and wireless infrastructure, including planning, implementation, expansion, and lifecycle management. Monitor and maintain network performance and reliability, ensuring a minimum of 99% uptime for corporate systems, phone systems, and connectivity. Configure and manage routing, switching, firewalls, and VPNs across Palo Alto NGFW (HQ and branch), Palo Alto VM-Series (AWS Commercial), and FortiGate VM (Azure Government). Serve as primary administrator across all firewall platforms, including policy management, rule additions and modifications, allow-list maintenance, and configuration backups; maintain privileged access under a documented change-controlled process. Oversee network configuration management and backups to ensure recoverability and business continuity. Analyze and resolve escalated Tier 2+ network support tickets. Administer enterprise wireless infrastructure across multiple vendor platforms including Cisco, Aruba, and Ubiquiti; manage access point provisioning Security & Compliance Identify, assess, and mitigate network vulnerabilities through proactive monitoring and remediation. Implement and manage network security controls including firewalls, intrusion detection/prevention systems, antivirus, and secure access solutions. Collaborate with Systems Administrators on vulnerability scanning, patch management, and remediation efforts (e.g., Nessus scan results, OS hardening). Support audit readiness and compliance for CMMC Level 2 and SOC 2, including maintaining network-layer controls in the System Security Plan (SSP), providing firewall and network evidence for assessments, and contributing to ISSO functions as needed. Coordinate firewall rule changes and network modifications through a documented change management process, maintaining an audit-ready record of all changes for SOC 2 and CMMC assessment cycles. Collaboration & Support Work in coordination with Systems and Security administrators to ensure smooth systems and network integration across on-prem and cloud environments. Provide training, documentation, and knowledge sharing to IT staff on new network technologies and processes. Assist in disaster recovery planning and implementation of secure, redundant connectivity solutions. Write and maintain technical documentation, including network diagrams, cabling layouts, and internal knowledge base articles. Contribute to internal IT automation and tooling initiatives, including scripting, infrastructure-as-code, and network-layer input on expanding internal platforms and dashboards. Cloud Infrastructure & GCP Governance Serve as the GCP organization owner, maintaining folder hierarchy, org policies, IAM governance, and network configurations across all projects and access boundaries. Administer cloud-hosted network infrastructure including Palo Alto VM-Series in AWS Commercial and FortiGate VM in Azure Government; design and maintain hybrid connectivity patterns across cloud environments. Support GCP cloud networking operations including Cloud NCC hub-and-spoke architecture, HA-VPN with BGP over IKEv2, Cloud Router, and Cloud NAT. Requirements Must be a U.S. Citizenship Bachelor's degree in Computer Science, Information Technology, or a related field (or equivalent experience). Must have a minimum of 5+ years of hands-on working experience in network engineering, IT administration, or a related technical role. Must have a strong knowledge of Windows operating systems and enterprise networking fundamentals. Hands-on experience with enterprise firewall administration; Palo Alto NGFW experience and Cisco or equivalent routing and switching experience required. Must be proficient in managing network security tools (firewalls, IDS/IPS, VPNs, antivirus). Must be familiar with configuration management, monitoring, and documentation tools. Must have 5+years of demonstrated ability to maintain and update network security documentation including firewall rule baselines, network diagrams, and SSP network control contributions. Must have the ability to troubleshoot complex issues and communicate effectively with both technical and non-technical staff. Preferred Qualifications Certifications such as Palo Alto PCNSE, FortiGate NSE 4 or higher, CCNA, CCNP, Security+, or equivalent. FortiGate experience, including FortiGate VM in Azure Government, preferred; candidates with strong enterprise firewall experience may ramp up on FortiGate with internal support. Experience supporting Microsoft 365, Azure Government (GCC High), AWS Commercial, and GCP environments; familiarity with compliance boundaries specific to Azure Gov and GCC High preferred. Familiarity with VoIP, secure mail flow, and endpoint management integration. Experience contributing to IT/security-related project initiatives. Prior experience in an ISSO or ISSO support role, or familiarity with SSP documentation and NIST 800-171 network control mapping. Experience administering cloud-hosted firewall VMs (Palo Alto VM-Series or FortiGate VM) in AWS or Azure environments. Experience with network monitoring and management platforms such as PRTG Network Monitor, network documentation tools such as NetBox, and network automation and configuration management tools such as Ansible. Experience with Workload Identity Federation (WIF) and OIDC-based service account authentication in GCP; ability to audit and migrate from key-based service accounts. GCP Professional Cloud Network Engineer certification or equivalent demonstrated experience. Familiar with GCP organization-level governance including IAM, org policies, and folder hierarchy. Experience in a federal contractor environment or familiarity with government compliance frameworks (CMMC, FedRAMP) preferred. Comfort with scripting languages (Python, Bash) or infrastructure automation tools for network configuration and operational tasks. Salary Range: $130,000.00 to $155,000.00 annually. Actual compensation will be determined based on the selected candidate's experience, education, skills, and overall qualifications. Please join us, as together we build a better world one mission at a time powered by Technology and its People! Benefits Health Care Plan (Medical, Dental & Vision) Retirement Plan (401k, IRA) Life Insurance (Basic, Voluntary & AD&D) Paid Time Off (Vacation, Sick & Public Holidays) Family Leave (Maternity, Paternity) Short Term & Long Term Disability Training & Development Wellness Resources
09/15/2026
Full time
Job Description Job Description Overview Join a team where innovation meets mission. Our AI, cloud, cyber, and modernization solutions save agencies thousands of hours, safeguard national security, and strengthen health and humanitarian missions worldwide. With more than 1,700+ team members, 1,500+ AI & data experts, and 100+ prime contracts, we deliver at scale and with purpose. We've been recognized as a Top Workplace by The Washington Post for six consecutive years and named to the Inc. 5000 list of Fastest-Growing Private Companies in 13 of the past 14 years. Credence is a welcoming environment for those looking to grow and make a meaningful impact. We encourage employees to push boundaries and help solve critical, world-changing federal challenges. Position Summary Credence has an immediate opening for a Network Security Engineer to join our internal IT team. This individual will own enterprise network and security infrastructure across physical and cloud-hosted environments, administer multi-vendor firewalls, and maintain compliance-aligned controls within a CMMC Level 2 and SOC 2 audit environment. The role carries meaningful responsibility for SSP accuracy, ISSO support functions, and GCP organization-level governance. The ideal candidate combines deep network security expertise with documentation discipline and a proactive, compliance-first mindset Responsibilities:Network Infrastructure & Operations Provide technical ownership of the corporate WAN, LAN, and wireless infrastructure, including planning, implementation, expansion, and lifecycle management. Monitor and maintain network performance and reliability, ensuring a minimum of 99% uptime for corporate systems, phone systems, and connectivity. Configure and manage routing, switching, firewalls, and VPNs across Palo Alto NGFW (HQ and branch), Palo Alto VM-Series (AWS Commercial), and FortiGate VM (Azure Government). Serve as primary administrator across all firewall platforms, including policy management, rule additions and modifications, allow-list maintenance, and configuration backups; maintain privileged access under a documented change-controlled process. Oversee network configuration management and backups to ensure recoverability and business continuity. Analyze and resolve escalated Tier 2+ network support tickets. Administer enterprise wireless infrastructure across multiple vendor platforms including Cisco, Aruba, and Ubiquiti; manage access point provisioning Security & Compliance Identify, assess, and mitigate network vulnerabilities through proactive monitoring and remediation. Implement and manage network security controls including firewalls, intrusion detection/prevention systems, antivirus, and secure access solutions. Collaborate with Systems Administrators on vulnerability scanning, patch management, and remediation efforts (e.g., Nessus scan results, OS hardening). Support audit readiness and compliance for CMMC Level 2 and SOC 2, including maintaining network-layer controls in the System Security Plan (SSP), providing firewall and network evidence for assessments, and contributing to ISSO functions as needed. Coordinate firewall rule changes and network modifications through a documented change management process, maintaining an audit-ready record of all changes for SOC 2 and CMMC assessment cycles. Collaboration & Support Work in coordination with Systems and Security administrators to ensure smooth systems and network integration across on-prem and cloud environments. Provide training, documentation, and knowledge sharing to IT staff on new network technologies and processes. Assist in disaster recovery planning and implementation of secure, redundant connectivity solutions. Write and maintain technical documentation, including network diagrams, cabling layouts, and internal knowledge base articles. Contribute to internal IT automation and tooling initiatives, including scripting, infrastructure-as-code, and network-layer input on expanding internal platforms and dashboards. Cloud Infrastructure & GCP Governance Serve as the GCP organization owner, maintaining folder hierarchy, org policies, IAM governance, and network configurations across all projects and access boundaries. Administer cloud-hosted network infrastructure including Palo Alto VM-Series in AWS Commercial and FortiGate VM in Azure Government; design and maintain hybrid connectivity patterns across cloud environments. Support GCP cloud networking operations including Cloud NCC hub-and-spoke architecture, HA-VPN with BGP over IKEv2, Cloud Router, and Cloud NAT. Requirements Must be a U.S. Citizenship Bachelor's degree in Computer Science, Information Technology, or a related field (or equivalent experience). Must have a minimum of 5+ years of hands-on working experience in network engineering, IT administration, or a related technical role. Must have a strong knowledge of Windows operating systems and enterprise networking fundamentals. Hands-on experience with enterprise firewall administration; Palo Alto NGFW experience and Cisco or equivalent routing and switching experience required. Must be proficient in managing network security tools (firewalls, IDS/IPS, VPNs, antivirus). Must be familiar with configuration management, monitoring, and documentation tools. Must have 5+years of demonstrated ability to maintain and update network security documentation including firewall rule baselines, network diagrams, and SSP network control contributions. Must have the ability to troubleshoot complex issues and communicate effectively with both technical and non-technical staff. Preferred Qualifications Certifications such as Palo Alto PCNSE, FortiGate NSE 4 or higher, CCNA, CCNP, Security+, or equivalent. FortiGate experience, including FortiGate VM in Azure Government, preferred; candidates with strong enterprise firewall experience may ramp up on FortiGate with internal support. Experience supporting Microsoft 365, Azure Government (GCC High), AWS Commercial, and GCP environments; familiarity with compliance boundaries specific to Azure Gov and GCC High preferred. Familiarity with VoIP, secure mail flow, and endpoint management integration. Experience contributing to IT/security-related project initiatives. Prior experience in an ISSO or ISSO support role, or familiarity with SSP documentation and NIST 800-171 network control mapping. Experience administering cloud-hosted firewall VMs (Palo Alto VM-Series or FortiGate VM) in AWS or Azure environments. Experience with network monitoring and management platforms such as PRTG Network Monitor, network documentation tools such as NetBox, and network automation and configuration management tools such as Ansible. Experience with Workload Identity Federation (WIF) and OIDC-based service account authentication in GCP; ability to audit and migrate from key-based service accounts. GCP Professional Cloud Network Engineer certification or equivalent demonstrated experience. Familiar with GCP organization-level governance including IAM, org policies, and folder hierarchy. Experience in a federal contractor environment or familiarity with government compliance frameworks (CMMC, FedRAMP) preferred. Comfort with scripting languages (Python, Bash) or infrastructure automation tools for network configuration and operational tasks. Salary Range: $130,000.00 to $155,000.00 annually. Actual compensation will be determined based on the selected candidate's experience, education, skills, and overall qualifications. Please join us, as together we build a better world one mission at a time powered by Technology and its People! Benefits Health Care Plan (Medical, Dental & Vision) Retirement Plan (401k, IRA) Life Insurance (Basic, Voluntary & AD&D) Paid Time Off (Vacation, Sick & Public Holidays) Family Leave (Maternity, Paternity) Short Term & Long Term Disability Training & Development Wellness Resources
Network Security Engineer
Zoox San Mateo, California
Job Description Job Description Zoox's Network Security team architects and defends the digital borders of the company - from corporate offices to engineering labs and product/mission environments. As a Network Security Engineer, you will design, implement, and operate security controls across Zoox's enterprise, OT networks, and cloud infrastructure spanning on-premises data centers and public cloud environments (AWS, GCP), partnering closely with Network Engineering, IT, Product Security, and Software Engineering teams. In This Role, You Will Design, implement, and maintain secure hybrid/multi-cloud network architectures (AWS/GCP, CloudWAN); enforce zero-trust access controls and network segmentation across corporate, data center, lab, and edge environments; develop and maintain related policies, standards, and architecture diagrams Own and operate next-generation firewall platforms (Palo Alto Networks, Fortinet), managing policy architecture, segmentation, NAT, URL filtering, SSL/TLS decryption, and threat prevention tuning Architect, operate, and own the lifecycle of secure remote access solutions (VPN, ZTNA, site-to-site tunnels), ensuring high availability, certificate-based authentication, and integration with identity providers (SAML, Entra ID) Drive automation and Infrastructure-as-Code (IaC) using Terraform, Python, CI/CD, and REST APIs for configuration management, firewall policies, and security baselines; integrate LLM-based tools to streamline operational tasks and reduce manual toil Oversee security operations including 24/7 network security monitoring, traffic analysis, threat detection, vulnerability assessments, and remediation; support compliance requirements by conducting security reviews for new projects and infrastructure changes Drive 802.1X/certificate-based Network Access Control (NAC) initiatives across wired and wireless environments Collaborate with team members and contribute to cross-functional security initiatives with Product Security, SRE, IT, and Software Engineering teams Qualifications 6+ years of network security engineering experience securing enterprise, cloud, and OT/lab environments Platform Expertise: Deep, hands-on expertise in next-gen firewalls (Palo Alto, Fortinet), AWS NFW, WAFs, IDS/IPS, NAC/802.1X, PKI, VPN, and ZTNA solutions (Zscaler, Netskope, Prisma Access, or equivalent) Technical Knowledge: Strong understanding of core network protocols (TCP/IP, BGP, OSPF, VLAN, 802.1X, TLS/PKI) and cloud networking security principles (AWS, GCP, or Azure) Automation: Hands-on experience with IaC and automation tooling including Terraform, Python, CI/CD pipelines, and REST APIs Security Operations: Experience with network security monitoring, threat detection, and security operations tooling (SIEM, IDS/IPS, vulnerability management platforms), including integration with network controls Compliance: Proven experience supporting major compliance initiatives (NIST 800-53, CSF 2.0, ISO 27001), including control implementation and evidence collection Bonus Qualifications Experience in autonomous vehicle, robotics, IT/OT or automotive environments Certifications: PCNSE, AWS Security Specialty, CCNA Experience experimenting with or deploying AI/ML-based security capabilities (e.g., anomaly detection, behavioral analytics, LLM-driven copilots) in network or cloud security workflows There are three major components to compensation for this position: salary, Amazon Restricted Stock Units (RSUs), and Zoox Stock Appreciation Rights. A sign-on bonus may be offered as part of the compensation package. The listed range applies only to the base salary. Compensation will vary based on geographic location and level. Leveling, as well as positioning within a level, is determined by a range of factors, including, but not limited to, a candidate's relevant years of experience, domain knowledge, and interview performance. The salary range listed in this posting is representative of the range of levels Zoox is considering for this position. Zoox also offers a comprehensive package of benefits, including paid time off (e.g. sick leave, vacation, bereavement), unpaid time off, Zoox Stock Appreciation Rights, Amazon RSUs, health insurance, long-term care insurance, long-term and short-term disability insurance, and life insurance. About Zoox Zoox is developing the first ground-up, fully autonomous vehicle fleet and the supporting ecosystem required to bring this technology to market. Sitting at the intersection of robotics, machine learning, and design, Zoox aims to provide the next generation of mobility-as-a-service in urban environments. We're looking for top talent that shares our passion and wants to be part of a fast-moving and highly execution-oriented team. Follow us on LinkedIn Accommodations If you need an accommodation to participate in the application or interview process please reach out to or your assigned recruiter. A Final Note: You do not need to match every listed expectation to apply for this position. Here at Zoox, we know that diverse perspectives foster the innovation we need to be successful, and we are committed to building a team that encompasses a variety of backgrounds, experiences, and skills. We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
09/15/2026
Full time
Job Description Job Description Zoox's Network Security team architects and defends the digital borders of the company - from corporate offices to engineering labs and product/mission environments. As a Network Security Engineer, you will design, implement, and operate security controls across Zoox's enterprise, OT networks, and cloud infrastructure spanning on-premises data centers and public cloud environments (AWS, GCP), partnering closely with Network Engineering, IT, Product Security, and Software Engineering teams. In This Role, You Will Design, implement, and maintain secure hybrid/multi-cloud network architectures (AWS/GCP, CloudWAN); enforce zero-trust access controls and network segmentation across corporate, data center, lab, and edge environments; develop and maintain related policies, standards, and architecture diagrams Own and operate next-generation firewall platforms (Palo Alto Networks, Fortinet), managing policy architecture, segmentation, NAT, URL filtering, SSL/TLS decryption, and threat prevention tuning Architect, operate, and own the lifecycle of secure remote access solutions (VPN, ZTNA, site-to-site tunnels), ensuring high availability, certificate-based authentication, and integration with identity providers (SAML, Entra ID) Drive automation and Infrastructure-as-Code (IaC) using Terraform, Python, CI/CD, and REST APIs for configuration management, firewall policies, and security baselines; integrate LLM-based tools to streamline operational tasks and reduce manual toil Oversee security operations including 24/7 network security monitoring, traffic analysis, threat detection, vulnerability assessments, and remediation; support compliance requirements by conducting security reviews for new projects and infrastructure changes Drive 802.1X/certificate-based Network Access Control (NAC) initiatives across wired and wireless environments Collaborate with team members and contribute to cross-functional security initiatives with Product Security, SRE, IT, and Software Engineering teams Qualifications 6+ years of network security engineering experience securing enterprise, cloud, and OT/lab environments Platform Expertise: Deep, hands-on expertise in next-gen firewalls (Palo Alto, Fortinet), AWS NFW, WAFs, IDS/IPS, NAC/802.1X, PKI, VPN, and ZTNA solutions (Zscaler, Netskope, Prisma Access, or equivalent) Technical Knowledge: Strong understanding of core network protocols (TCP/IP, BGP, OSPF, VLAN, 802.1X, TLS/PKI) and cloud networking security principles (AWS, GCP, or Azure) Automation: Hands-on experience with IaC and automation tooling including Terraform, Python, CI/CD pipelines, and REST APIs Security Operations: Experience with network security monitoring, threat detection, and security operations tooling (SIEM, IDS/IPS, vulnerability management platforms), including integration with network controls Compliance: Proven experience supporting major compliance initiatives (NIST 800-53, CSF 2.0, ISO 27001), including control implementation and evidence collection Bonus Qualifications Experience in autonomous vehicle, robotics, IT/OT or automotive environments Certifications: PCNSE, AWS Security Specialty, CCNA Experience experimenting with or deploying AI/ML-based security capabilities (e.g., anomaly detection, behavioral analytics, LLM-driven copilots) in network or cloud security workflows There are three major components to compensation for this position: salary, Amazon Restricted Stock Units (RSUs), and Zoox Stock Appreciation Rights. A sign-on bonus may be offered as part of the compensation package. The listed range applies only to the base salary. Compensation will vary based on geographic location and level. Leveling, as well as positioning within a level, is determined by a range of factors, including, but not limited to, a candidate's relevant years of experience, domain knowledge, and interview performance. The salary range listed in this posting is representative of the range of levels Zoox is considering for this position. Zoox also offers a comprehensive package of benefits, including paid time off (e.g. sick leave, vacation, bereavement), unpaid time off, Zoox Stock Appreciation Rights, Amazon RSUs, health insurance, long-term care insurance, long-term and short-term disability insurance, and life insurance. About Zoox Zoox is developing the first ground-up, fully autonomous vehicle fleet and the supporting ecosystem required to bring this technology to market. Sitting at the intersection of robotics, machine learning, and design, Zoox aims to provide the next generation of mobility-as-a-service in urban environments. We're looking for top talent that shares our passion and wants to be part of a fast-moving and highly execution-oriented team. Follow us on LinkedIn Accommodations If you need an accommodation to participate in the application or interview process please reach out to or your assigned recruiter. A Final Note: You do not need to match every listed expectation to apply for this position. Here at Zoox, we know that diverse perspectives foster the innovation we need to be successful, and we are committed to building a team that encompasses a variety of backgrounds, experiences, and skills. We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Network & Security Engineer
Citadel Completions LLC Dallas, Texas
Job Description Job Description Purpose Information technology is foundational to how Citadel Aviation operates at every site, from the systems that move work across the hangar floor and the shops to the platforms that support administrative staff. Secure, reliable network and identity infrastructure enable Citadel to operate without interruption, protect its work and its people, and meet its obligations to customers and partners. This role owns the design, operation, and security of Citadel's network and identity infrastructure across every Citadel site: reliable connectivity, a hardened identity platform, and a security posture that scales with the business. The role serves as Citadel's internal technical counterpart to the company's security SOC and managed detection and response (MDR) provider, partners with IT leadership and peers across IT and the business, owns assigned IT projects, and is accountable for the reliability of the network and the strength of the security posture across every site. Environment The technology stack includes Palo Alto next-generation firewalls, Cisco switching, Meraki wireless, Microsoft 365 with Entra ID for identity, Microsoft Defender for Endpoint and Intune for endpoint security and management, Tenable for vulnerability management, and KnowBe4 for security awareness. Security operations are delivered in partnership with an external SOC and MDR provider. Essential Job Functions Own the design, operation, and security of Citadel's network infrastructure across all sites. Maintain firewalls, switching, wireless, ISP connectivity, and backup connectivity. Design and implement upgrades to support growth, lead network design and turn-up for new Citadel facilities, and maintain secure connectivity between sites, between sites and the cloud, and for remote users. Own the design, operation, and security of Citadel's voice and unified communications infrastructure, including the company's calling system, VOIP infrastructure, and integration with Microsoft 365 communications. Maintain consistent network and security service quality across all Citadel sites. Travel between sites is heavier during the initial standardization phase across existing sites and during turn-up of new sites, and lighter once the environment reaches steady state. Perform in line with established KPIs and service-level targets, including network availability, security patch SLA, mean time to remediate vulnerabilities, mean time to respond to security incidents, and related measures. Track and report performance regularly to IT leadership. Serve as the internal technical counterpart to the company's security SOC and MDR provider, who operate detection, monitoring, and response. Partner closely on detection tuning, alert triage, investigation, and remediation. Own endpoint security policy across the Microsoft 365 platform, including Microsoft Defender for Endpoint configuration, conditional access, identity hardening, and Intune security baselines. Partner with the IT manager and the support team on day-to-day operation and enforcement. Own technical email security controls, including anti-phishing, anti-malware, secure transport, and tenant security configuration. Partner with the IT manager on user-facing reporting and response workflows. Run Citadel's vulnerability management process in partnership with the MDR provider. Operate scanning tooling, prioritize findings, and drive remediation across the IT organization. Own identity and access management hardening, including multi-factor authentication, conditional access policy, privileged access controls, and account lifecycle hygiene. Set program direction and content for Citadel's cybersecurity awareness program, including training plans, phishing simulation strategy, and ongoing user education topics. Partner with the IT manager, who runs the user-facing activities and reporting. Conduct third-party security review of new vendors, software platforms, and integrations before they enter the environment. Assess data handling, integration security, and ongoing risk; track approval and remediation. Coordinate Citadel's response to external security assessments, including penetration testing, cyber insurance reviews, customer security questionnaires, and regulatory inquiries. Scope engagements, work with vendors, maintain evidence, and track remediation. Deliver assigned IT projects within networking and security, and contribute to broader IT initiatives. Coordinate with IT leadership and peers, and engage external specialists and contractors as needed. Partner with IT leadership and peers in infrastructure, support, and software development on initiatives originating in those service lines. Contribute network and security expertise to keep delivery on track. Own vendor relationships within the network and security portfolio, including ISPs, network hardware, security tooling, and specialized contractors. Take on broader IT vendor relationships as assigned. Own the network and security operating budget, with broader budget scope as assigned. Track expenses, project upcoming needs, and provide input on annual IT budget planning. Own the on-call rotation for network and security incidents. Drive diagnosis, coordinate internal and external resources, and engage directly in resolution. Own incident communication for network and security events. Notify IT leadership and impacted business stakeholders, provide regular status updates throughout an incident, and deliver post-incident summaries with root cause and follow-up actions. Conduct periodic internal security audits across user access, identity hygiene, configuration baselines, vulnerability posture, and policy adherence. Remediate findings in partnership with the IT manager. Maintain and enforce IT network and security policies, procedures, runbooks, technical documentation, and asset inventory. Contribute to the creation and modification of policies as needed. Identify and propose improvements in network design, security posture, monitoring coverage, and tool consolidation. Deliver approved initiatives. Non-Essential Functions Running cables and installing hardware. Other duties as assigned. Minimum Qualifications or Experience Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Network Engineering, or a related technical discipline. Equivalent professional experience considered in lieu of degree. 5+ years of progressive experience in enterprise network engineering and information security. Hands-on experience with endpoint security platforms, including Microsoft Defender for Endpoint and modern identity and access management (Microsoft Entra ID, conditional access, multi-factor authentication). Experience operating in partnership with a managed detection and response (MDR) provider or security operations center (SOC). Experience with vulnerability management, including scanning tooling (Tenable Nessus or comparable), prioritization, and driving remediation across an organization. Experience operating in an environment with regular external security assessments (penetration testing, cyber insurance reviews, customer security audits) and remediating findings under deadline. Experience supporting multi-site operations or production environments where uptime, security, and consistency of service are operational requirements. Experience delivering IT projects from scope through completion, including scheduling, vendor coordination, and budget tracking. Demonstrated ability to communicate technical concepts clearly to non-technical business stakeholders and to senior leadership. Demonstrated experience adhering to and enforcing security best practices across network, endpoint, and identity domains. Preferred Qualifications or Experience Experience in aviation, aerospace, manufacturing, MRO, or other regulated operational environments. Hands-on experience with endpoint security platforms, including Microsoft Defender for Endpoint and modern identity and access management (Microsoft Entra ID, conditional access, multi-factor authentication). Active IT industry certifications such as CompTIA Security+ or Network+, Cisco CCNA / CCNP, Palo Alto PCNSA / PCNSE, Microsoft Security or Identity certifications, CISSP, GIAC, or comparable. Experience designing and bringing up network infrastructure at new sites or facilities. Experience with SD-WAN, zero-trust architecture, network segmentation, or related modern network design patterns. Familiarity with security frameworks (NIST, CIS) and audit or compliance work. Experience with security awareness platforms (KnowBe4 or comparable). Experience administering identity and access controls in a hybrid or cloud-first environment. Experience with VOIP or unified communications infrastructure. Supervisory Responsibilities This position has no direct reports. Coordinates day-to-day with external network and security contractors, managed-service providers, and the company's SOC and MDR partner. Provides technical guidance and security expertise to IT team peers and to business stakeholders as needed. Knowledge, Skills, and Other Attributes Deep technical expertise across enterprise networking (firewalls, switching, wireless, routing) and information security (endpoint, identity, vulnerability management, security monitoring). . click apply for full job details
09/15/2026
Full time
Job Description Job Description Purpose Information technology is foundational to how Citadel Aviation operates at every site, from the systems that move work across the hangar floor and the shops to the platforms that support administrative staff. Secure, reliable network and identity infrastructure enable Citadel to operate without interruption, protect its work and its people, and meet its obligations to customers and partners. This role owns the design, operation, and security of Citadel's network and identity infrastructure across every Citadel site: reliable connectivity, a hardened identity platform, and a security posture that scales with the business. The role serves as Citadel's internal technical counterpart to the company's security SOC and managed detection and response (MDR) provider, partners with IT leadership and peers across IT and the business, owns assigned IT projects, and is accountable for the reliability of the network and the strength of the security posture across every site. Environment The technology stack includes Palo Alto next-generation firewalls, Cisco switching, Meraki wireless, Microsoft 365 with Entra ID for identity, Microsoft Defender for Endpoint and Intune for endpoint security and management, Tenable for vulnerability management, and KnowBe4 for security awareness. Security operations are delivered in partnership with an external SOC and MDR provider. Essential Job Functions Own the design, operation, and security of Citadel's network infrastructure across all sites. Maintain firewalls, switching, wireless, ISP connectivity, and backup connectivity. Design and implement upgrades to support growth, lead network design and turn-up for new Citadel facilities, and maintain secure connectivity between sites, between sites and the cloud, and for remote users. Own the design, operation, and security of Citadel's voice and unified communications infrastructure, including the company's calling system, VOIP infrastructure, and integration with Microsoft 365 communications. Maintain consistent network and security service quality across all Citadel sites. Travel between sites is heavier during the initial standardization phase across existing sites and during turn-up of new sites, and lighter once the environment reaches steady state. Perform in line with established KPIs and service-level targets, including network availability, security patch SLA, mean time to remediate vulnerabilities, mean time to respond to security incidents, and related measures. Track and report performance regularly to IT leadership. Serve as the internal technical counterpart to the company's security SOC and MDR provider, who operate detection, monitoring, and response. Partner closely on detection tuning, alert triage, investigation, and remediation. Own endpoint security policy across the Microsoft 365 platform, including Microsoft Defender for Endpoint configuration, conditional access, identity hardening, and Intune security baselines. Partner with the IT manager and the support team on day-to-day operation and enforcement. Own technical email security controls, including anti-phishing, anti-malware, secure transport, and tenant security configuration. Partner with the IT manager on user-facing reporting and response workflows. Run Citadel's vulnerability management process in partnership with the MDR provider. Operate scanning tooling, prioritize findings, and drive remediation across the IT organization. Own identity and access management hardening, including multi-factor authentication, conditional access policy, privileged access controls, and account lifecycle hygiene. Set program direction and content for Citadel's cybersecurity awareness program, including training plans, phishing simulation strategy, and ongoing user education topics. Partner with the IT manager, who runs the user-facing activities and reporting. Conduct third-party security review of new vendors, software platforms, and integrations before they enter the environment. Assess data handling, integration security, and ongoing risk; track approval and remediation. Coordinate Citadel's response to external security assessments, including penetration testing, cyber insurance reviews, customer security questionnaires, and regulatory inquiries. Scope engagements, work with vendors, maintain evidence, and track remediation. Deliver assigned IT projects within networking and security, and contribute to broader IT initiatives. Coordinate with IT leadership and peers, and engage external specialists and contractors as needed. Partner with IT leadership and peers in infrastructure, support, and software development on initiatives originating in those service lines. Contribute network and security expertise to keep delivery on track. Own vendor relationships within the network and security portfolio, including ISPs, network hardware, security tooling, and specialized contractors. Take on broader IT vendor relationships as assigned. Own the network and security operating budget, with broader budget scope as assigned. Track expenses, project upcoming needs, and provide input on annual IT budget planning. Own the on-call rotation for network and security incidents. Drive diagnosis, coordinate internal and external resources, and engage directly in resolution. Own incident communication for network and security events. Notify IT leadership and impacted business stakeholders, provide regular status updates throughout an incident, and deliver post-incident summaries with root cause and follow-up actions. Conduct periodic internal security audits across user access, identity hygiene, configuration baselines, vulnerability posture, and policy adherence. Remediate findings in partnership with the IT manager. Maintain and enforce IT network and security policies, procedures, runbooks, technical documentation, and asset inventory. Contribute to the creation and modification of policies as needed. Identify and propose improvements in network design, security posture, monitoring coverage, and tool consolidation. Deliver approved initiatives. Non-Essential Functions Running cables and installing hardware. Other duties as assigned. Minimum Qualifications or Experience Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Network Engineering, or a related technical discipline. Equivalent professional experience considered in lieu of degree. 5+ years of progressive experience in enterprise network engineering and information security. Hands-on experience with endpoint security platforms, including Microsoft Defender for Endpoint and modern identity and access management (Microsoft Entra ID, conditional access, multi-factor authentication). Experience operating in partnership with a managed detection and response (MDR) provider or security operations center (SOC). Experience with vulnerability management, including scanning tooling (Tenable Nessus or comparable), prioritization, and driving remediation across an organization. Experience operating in an environment with regular external security assessments (penetration testing, cyber insurance reviews, customer security audits) and remediating findings under deadline. Experience supporting multi-site operations or production environments where uptime, security, and consistency of service are operational requirements. Experience delivering IT projects from scope through completion, including scheduling, vendor coordination, and budget tracking. Demonstrated ability to communicate technical concepts clearly to non-technical business stakeholders and to senior leadership. Demonstrated experience adhering to and enforcing security best practices across network, endpoint, and identity domains. Preferred Qualifications or Experience Experience in aviation, aerospace, manufacturing, MRO, or other regulated operational environments. Hands-on experience with endpoint security platforms, including Microsoft Defender for Endpoint and modern identity and access management (Microsoft Entra ID, conditional access, multi-factor authentication). Active IT industry certifications such as CompTIA Security+ or Network+, Cisco CCNA / CCNP, Palo Alto PCNSA / PCNSE, Microsoft Security or Identity certifications, CISSP, GIAC, or comparable. Experience designing and bringing up network infrastructure at new sites or facilities. Experience with SD-WAN, zero-trust architecture, network segmentation, or related modern network design patterns. Familiarity with security frameworks (NIST, CIS) and audit or compliance work. Experience with security awareness platforms (KnowBe4 or comparable). Experience administering identity and access controls in a hybrid or cloud-first environment. Experience with VOIP or unified communications infrastructure. Supervisory Responsibilities This position has no direct reports. Coordinates day-to-day with external network and security contractors, managed-service providers, and the company's SOC and MDR partner. Provides technical guidance and security expertise to IT team peers and to business stakeholders as needed. Knowledge, Skills, and Other Attributes Deep technical expertise across enterprise networking (firewalls, switching, wireless, routing) and information security (endpoint, identity, vulnerability management, security monitoring). . click apply for full job details
Senior Security Engineer, Infrastructure & Network Security
Metropolis Acton, California
Job Description Job Description Who we are The real world is the next frontier, and at Metropolis, we are creating the artificial intelligence to make it responsive. We are pioneering the Recognition Economy - a future where mundane repetition disappears and being known unlocks access, comfort and belonging everywhere you go. From transforming parking into a seamless drive-in, drive-out experience for millions of Members to expanding our intelligence layer across retail and hospitality, we are building a world that feels instinctive and magical. The future isn't coming; it's here, and we need builders, innovators and problem solvers to help us create it. Who you are Metropolis is seeking a Senior Security Engineer to establish and lead a dedicated infrastructure and network security engineering function within our Corporate IT and Information Security organization. In this senior technical role, you will design, build, and manage a dedicated AWS environment to power our security tooling, automation, and operational infrastructure, while also supporting our expanding Oracle Cloud Infrastructure footprint. You will drive enterprise network security initiatives-including firewalls, segmentation, WAF technologies, and zero-trust architectures-to protect our corporate office networks and remote access environments. Collaborating closely with Corporate IT, Network Engineering, Central Cloud Infrastructure, and platform engineering teams, you will deliver resilient security infrastructure that safeguards our expanding technology ecosystem. What you'll do Design, build, and manage a dedicated AWS environment owned by Corporate IT and Information Security to support security tooling, automation, and operational workloads Support Oracle Cloud Infrastructure environments as part of broader enterprise transformation initiatives Lead enterprise network engineering and network security initiatives across corporate office networks, firewalls, segmentation, and wireless environments Implement and manage VPN, remote access, WAF technologies, and secure connectivity architectures Drive zero-trust initiatives and enhance enterprise network visibility and monitoring Manage identity, access, endpoint, and server security platforms across the enterprise Develop infrastructure-as-code and cloud automation to scale security operations infrastructure Execute vulnerability management programs and establish enterprise infrastructure hardening and operational resiliency Provide detection engineering and incident response support across security platforms Partner closely across Corporate IT, Network Engineering, Central Cloud Infrastructure, Enterprise Systems, and platform engineering teams What we're looking for Demonstrate strong AWS and cloud security experience Exhibit strong networking and network security experience Show experience with enterprise identity systems and access management Display experience with security engineering infrastructure and automation Support hybrid enterprise and cloud-native environments Utilize modern infrastructure and security tooling Maintain familiarity with regulated environments such as PCI and SOC Possess experience with scripting and programming Experience leveraging AI tools to transform static workflows into responsive, high-output processes While not required, these are a plus: Use Python as the preferred language for scripting and programming 4 Days in Office: Metropolis values in-person collaboration to drive innovation, strengthen culture, and enhance the Member experience. Our corporate team members hold to our office-first model, which requires employees to be on-site at least four days a week, fostering organic interactions that spark creativity and connection When you join Metropolis, you'll join a team of world-class product leaders and engineers, building an ecosystem of technologies at the intersection of parking, mobility, and real estate. Our goal is to build an inclusive culture where everyone has a voice and the best idea wins. You will play a key role in building and maintaining this culture as our organization grows. The anticipated base salary for this position is $160,000.00 USD to $215,000.00 USD annually. The actual base salary offered is determined by a number of variables, including, as appropriate, the applicant's qualifications for the position, years of relevant experience, distinctive skills, level of education attained, certifications or other professional licenses held, and the location of residence and/or place of employment. Base salary is one component of Metropolis's total compensation package, which may also include access to or eligibility for healthcare benefits, a 401(k) plan, short-term and long-term disability coverage, basic life insurance, a lucrative stock option plan, bonus plans and more. Metropolis may utilize an automated employment decision tool (AEDT) to assess or evaluate your candidacy for employment or promotion. AEDTs are used to assist in assessing a candidate's application relative to the required job qualifications and responsibilities listed in the job posting. As part of this process, Metropolis retains data relevant to your candidacy, including personal information, for a period that is reasonably necessary for the use of the tool. If you are hired for the position, your data may become part of your employee records. Metropolis Technologies is an equal opportunity employer. We make all hiring decisions based on merit, qualifications, and business needs, without regard to race, color, religion, sex (including gender identity, sexual orientation, or pregnancy), national origin, disability, veteran status, or any other protected characteristic under federal, state, or local law.
09/15/2026
Full time
Job Description Job Description Who we are The real world is the next frontier, and at Metropolis, we are creating the artificial intelligence to make it responsive. We are pioneering the Recognition Economy - a future where mundane repetition disappears and being known unlocks access, comfort and belonging everywhere you go. From transforming parking into a seamless drive-in, drive-out experience for millions of Members to expanding our intelligence layer across retail and hospitality, we are building a world that feels instinctive and magical. The future isn't coming; it's here, and we need builders, innovators and problem solvers to help us create it. Who you are Metropolis is seeking a Senior Security Engineer to establish and lead a dedicated infrastructure and network security engineering function within our Corporate IT and Information Security organization. In this senior technical role, you will design, build, and manage a dedicated AWS environment to power our security tooling, automation, and operational infrastructure, while also supporting our expanding Oracle Cloud Infrastructure footprint. You will drive enterprise network security initiatives-including firewalls, segmentation, WAF technologies, and zero-trust architectures-to protect our corporate office networks and remote access environments. Collaborating closely with Corporate IT, Network Engineering, Central Cloud Infrastructure, and platform engineering teams, you will deliver resilient security infrastructure that safeguards our expanding technology ecosystem. What you'll do Design, build, and manage a dedicated AWS environment owned by Corporate IT and Information Security to support security tooling, automation, and operational workloads Support Oracle Cloud Infrastructure environments as part of broader enterprise transformation initiatives Lead enterprise network engineering and network security initiatives across corporate office networks, firewalls, segmentation, and wireless environments Implement and manage VPN, remote access, WAF technologies, and secure connectivity architectures Drive zero-trust initiatives and enhance enterprise network visibility and monitoring Manage identity, access, endpoint, and server security platforms across the enterprise Develop infrastructure-as-code and cloud automation to scale security operations infrastructure Execute vulnerability management programs and establish enterprise infrastructure hardening and operational resiliency Provide detection engineering and incident response support across security platforms Partner closely across Corporate IT, Network Engineering, Central Cloud Infrastructure, Enterprise Systems, and platform engineering teams What we're looking for Demonstrate strong AWS and cloud security experience Exhibit strong networking and network security experience Show experience with enterprise identity systems and access management Display experience with security engineering infrastructure and automation Support hybrid enterprise and cloud-native environments Utilize modern infrastructure and security tooling Maintain familiarity with regulated environments such as PCI and SOC Possess experience with scripting and programming Experience leveraging AI tools to transform static workflows into responsive, high-output processes While not required, these are a plus: Use Python as the preferred language for scripting and programming 4 Days in Office: Metropolis values in-person collaboration to drive innovation, strengthen culture, and enhance the Member experience. Our corporate team members hold to our office-first model, which requires employees to be on-site at least four days a week, fostering organic interactions that spark creativity and connection When you join Metropolis, you'll join a team of world-class product leaders and engineers, building an ecosystem of technologies at the intersection of parking, mobility, and real estate. Our goal is to build an inclusive culture where everyone has a voice and the best idea wins. You will play a key role in building and maintaining this culture as our organization grows. The anticipated base salary for this position is $160,000.00 USD to $215,000.00 USD annually. The actual base salary offered is determined by a number of variables, including, as appropriate, the applicant's qualifications for the position, years of relevant experience, distinctive skills, level of education attained, certifications or other professional licenses held, and the location of residence and/or place of employment. Base salary is one component of Metropolis's total compensation package, which may also include access to or eligibility for healthcare benefits, a 401(k) plan, short-term and long-term disability coverage, basic life insurance, a lucrative stock option plan, bonus plans and more. Metropolis may utilize an automated employment decision tool (AEDT) to assess or evaluate your candidacy for employment or promotion. AEDTs are used to assist in assessing a candidate's application relative to the required job qualifications and responsibilities listed in the job posting. As part of this process, Metropolis retains data relevant to your candidacy, including personal information, for a period that is reasonably necessary for the use of the tool. If you are hired for the position, your data may become part of your employee records. Metropolis Technologies is an equal opportunity employer. We make all hiring decisions based on merit, qualifications, and business needs, without regard to race, color, religion, sex (including gender identity, sexual orientation, or pregnancy), national origin, disability, veteran status, or any other protected characteristic under federal, state, or local law.
Senior Security Engineer, Infrastructure & Network Security
Metropolis New York, New York
Job Description Job Description Who we are The real world is the next frontier, and at Metropolis, we are creating the artificial intelligence to make it responsive. We are pioneering the Recognition Economy - a future where mundane repetition disappears and being known unlocks access, comfort and belonging everywhere you go. From transforming parking into a seamless drive-in, drive-out experience for millions of Members to expanding our intelligence layer across retail and hospitality, we are building a world that feels instinctive and magical. The future isn't coming; it's here, and we need builders, innovators and problem solvers to help us create it. Who you are Metropolis is seeking a Senior Security Engineer to establish and lead a dedicated infrastructure and network security engineering function within our Corporate IT and Information Security organization. In this senior technical role, you will design, build, and manage a dedicated AWS environment to power our security tooling, automation, and operational infrastructure, while also supporting our expanding Oracle Cloud Infrastructure footprint. You will drive enterprise network security initiatives-including firewalls, segmentation, WAF technologies, and zero-trust architectures-to protect our corporate office networks and remote access environments. Collaborating closely with Corporate IT, Network Engineering, Central Cloud Infrastructure, and platform engineering teams, you will deliver resilient security infrastructure that safeguards our expanding technology ecosystem. What you'll do Design, build, and manage a dedicated AWS environment owned by Corporate IT and Information Security to support security tooling, automation, and operational workloads Support Oracle Cloud Infrastructure environments as part of broader enterprise transformation initiatives Lead enterprise network engineering and network security initiatives across corporate office networks, firewalls, segmentation, and wireless environments Implement and manage VPN, remote access, WAF technologies, and secure connectivity architectures Drive zero-trust initiatives and enhance enterprise network visibility and monitoring Manage identity, access, endpoint, and server security platforms across the enterprise Develop infrastructure-as-code and cloud automation to scale security operations infrastructure Execute vulnerability management programs and establish enterprise infrastructure hardening and operational resiliency Provide detection engineering and incident response support across security platforms Partner closely across Corporate IT, Network Engineering, Central Cloud Infrastructure, Enterprise Systems, and platform engineering teams What we're looking for Demonstrate strong AWS and cloud security experience Exhibit strong networking and network security experience Show experience with enterprise identity systems and access management Display experience with security engineering infrastructure and automation Support hybrid enterprise and cloud-native environments Utilize modern infrastructure and security tooling Maintain familiarity with regulated environments such as PCI and SOC Possess experience with scripting and programming Experience leveraging AI tools to transform static workflows into responsive, high-output processes While not required, these are a plus: Use Python as the preferred language for scripting and programming 4 Days in Office: Metropolis values in-person collaboration to drive innovation, strengthen culture, and enhance the Member experience. Our corporate team members hold to our office-first model, which requires employees to be on-site at least four days a week, fostering organic interactions that spark creativity and connection When you join Metropolis, you'll join a team of world-class product leaders and engineers, building an ecosystem of technologies at the intersection of parking, mobility, and real estate. Our goal is to build an inclusive culture where everyone has a voice and the best idea wins. You will play a key role in building and maintaining this culture as our organization grows. The anticipated base salary for this position is $165,000.00 USD to $215,000.00 USD annually. The actual base salary offered is determined by a number of variables, including, as appropriate, the applicant's qualifications for the position, years of relevant experience, distinctive skills, level of education attained, certifications or other professional licenses held, and the location of residence and/or place of employment. Base salary is one component of Metropolis's total compensation package, which may also include access to or eligibility for healthcare benefits, a 401(k) plan, short-term and long-term disability coverage, basic life insurance, a lucrative stock option plan, bonus plans and more. Metropolis may utilize an automated employment decision tool (AEDT) to assess or evaluate your candidacy for employment or promotion. AEDTs are used to assist in assessing a candidate's application relative to the required job qualifications and responsibilities listed in the job posting. As part of this process, Metropolis retains data relevant to your candidacy, including personal information, for a period that is reasonably necessary for the use of the tool. If you are hired for the position, your data may become part of your employee records. Metropolis Technologies is an equal opportunity employer. We make all hiring decisions based on merit, qualifications, and business needs, without regard to race, color, religion, sex (including gender identity, sexual orientation, or pregnancy), national origin, disability, veteran status, or any other protected characteristic under federal, state, or local law.
09/15/2026
Full time
Job Description Job Description Who we are The real world is the next frontier, and at Metropolis, we are creating the artificial intelligence to make it responsive. We are pioneering the Recognition Economy - a future where mundane repetition disappears and being known unlocks access, comfort and belonging everywhere you go. From transforming parking into a seamless drive-in, drive-out experience for millions of Members to expanding our intelligence layer across retail and hospitality, we are building a world that feels instinctive and magical. The future isn't coming; it's here, and we need builders, innovators and problem solvers to help us create it. Who you are Metropolis is seeking a Senior Security Engineer to establish and lead a dedicated infrastructure and network security engineering function within our Corporate IT and Information Security organization. In this senior technical role, you will design, build, and manage a dedicated AWS environment to power our security tooling, automation, and operational infrastructure, while also supporting our expanding Oracle Cloud Infrastructure footprint. You will drive enterprise network security initiatives-including firewalls, segmentation, WAF technologies, and zero-trust architectures-to protect our corporate office networks and remote access environments. Collaborating closely with Corporate IT, Network Engineering, Central Cloud Infrastructure, and platform engineering teams, you will deliver resilient security infrastructure that safeguards our expanding technology ecosystem. What you'll do Design, build, and manage a dedicated AWS environment owned by Corporate IT and Information Security to support security tooling, automation, and operational workloads Support Oracle Cloud Infrastructure environments as part of broader enterprise transformation initiatives Lead enterprise network engineering and network security initiatives across corporate office networks, firewalls, segmentation, and wireless environments Implement and manage VPN, remote access, WAF technologies, and secure connectivity architectures Drive zero-trust initiatives and enhance enterprise network visibility and monitoring Manage identity, access, endpoint, and server security platforms across the enterprise Develop infrastructure-as-code and cloud automation to scale security operations infrastructure Execute vulnerability management programs and establish enterprise infrastructure hardening and operational resiliency Provide detection engineering and incident response support across security platforms Partner closely across Corporate IT, Network Engineering, Central Cloud Infrastructure, Enterprise Systems, and platform engineering teams What we're looking for Demonstrate strong AWS and cloud security experience Exhibit strong networking and network security experience Show experience with enterprise identity systems and access management Display experience with security engineering infrastructure and automation Support hybrid enterprise and cloud-native environments Utilize modern infrastructure and security tooling Maintain familiarity with regulated environments such as PCI and SOC Possess experience with scripting and programming Experience leveraging AI tools to transform static workflows into responsive, high-output processes While not required, these are a plus: Use Python as the preferred language for scripting and programming 4 Days in Office: Metropolis values in-person collaboration to drive innovation, strengthen culture, and enhance the Member experience. Our corporate team members hold to our office-first model, which requires employees to be on-site at least four days a week, fostering organic interactions that spark creativity and connection When you join Metropolis, you'll join a team of world-class product leaders and engineers, building an ecosystem of technologies at the intersection of parking, mobility, and real estate. Our goal is to build an inclusive culture where everyone has a voice and the best idea wins. You will play a key role in building and maintaining this culture as our organization grows. The anticipated base salary for this position is $165,000.00 USD to $215,000.00 USD annually. The actual base salary offered is determined by a number of variables, including, as appropriate, the applicant's qualifications for the position, years of relevant experience, distinctive skills, level of education attained, certifications or other professional licenses held, and the location of residence and/or place of employment. Base salary is one component of Metropolis's total compensation package, which may also include access to or eligibility for healthcare benefits, a 401(k) plan, short-term and long-term disability coverage, basic life insurance, a lucrative stock option plan, bonus plans and more. Metropolis may utilize an automated employment decision tool (AEDT) to assess or evaluate your candidacy for employment or promotion. AEDTs are used to assist in assessing a candidate's application relative to the required job qualifications and responsibilities listed in the job posting. As part of this process, Metropolis retains data relevant to your candidacy, including personal information, for a period that is reasonably necessary for the use of the tool. If you are hired for the position, your data may become part of your employee records. Metropolis Technologies is an equal opportunity employer. We make all hiring decisions based on merit, qualifications, and business needs, without regard to race, color, religion, sex (including gender identity, sexual orientation, or pregnancy), national origin, disability, veteran status, or any other protected characteristic under federal, state, or local law.
Network Security Engineer
Woods Oviatt Gilman LLP Rochester, New York
Job Description Job Description Job Title: Network Security Engineer Department: Information Technology Location: Rochester, NY Classification: Exempt Reports To: Director of Information Technology Please note: Candidates must be authorized to work in the United States and able to work onsite in the Rochester, NY office. Sponsorship is not available for this position. Company Overview: Woods Oviatt Gilman, LLP is a leading and reputable full-service law firm dedicated to providing exceptional legal services to our clients. With a team of highly skilled and experienced attorneys, we strive to deliver comprehensive and effective solutions to meet the diverse needs of our clients. Our headquarters is in Rochester, NY with additional offices in Albany and Buffalo, NY. We foster a collaborative and inclusive work environment where every team member is valued and respected. We encourage open communication, teamwork, and professional growth. Our firm promotes a healthy work-life balance and supports the well-being of our employees. Position Summary: The Network Security Engineer is a hands-on technical role responsible for implementing, configuring, and maintaining the firm's security controls across a hybrid environment, including FortiGate firewalls, endpoint protection, cloud email and Microsoft 365, Intune-managed devices, and a co-managed monitoring and detection service. The Engineer works under the direction of the Director of Information Technology, who sets security policy and priorities for the department, and provides the technical assessment, recommendations, and documentation that support those decisions. Because the firm safeguards confidential and privileged client information, this position calls for strong technical skill, sound judgment, discretion, and clear communication with both the IT team and firm personnel. Duties and Responsibilities: Network and Perimeter Security Administer, tune, and monitor FortiGate firewalls, including security policies, VPN configuration, intrusion prevention, web and content filtering, and logging Implement and maintain network segmentation, secure remote access, and wireless security across firm locations, in line with the department's standards Maintain secure connectivity for remote and hybrid users, including VPN and conditional access Conduct scheduled reviews of firewall rules and network configurations, recommend changes to the Director of Information Technology, and maintain accurate network security documentation Endpoint, Identity, and Email Security Administer the firm's endpoint protection platforms, including CrowdStrike and Microsoft endpoint protection, covering policy configuration, detection review, containment actions, and agent coverage Configure and maintain device compliance, configuration, and application deployment through Microsoft Intune in a hybrid environment, including full-disk encryption and recovery key handling Configure and maintain identity and access controls across Microsoft Entra ID and on-premises Active Directory, including multifactor authentication, conditional access, and privileged account settings, and perform periodic access reviews Configure and maintain security settings for cloud email and collaboration, including mail flow and filtering rules, phishing and malware defenses, email authentication records, and Microsoft 365 security configuration Perform vulnerability and patch management across servers, endpoints, and network devices, including scanning, prioritizing findings, tracking remediation, and reporting status to the Director of Information Technology Monitoring, Detection, and Incident Response Serve as the day-to-day technical contact for the firm's managed monitoring service, triaging alerts, validating findings, and carrying issues through to resolution Investigate security events and perform containment, eradication, and recovery steps in accordance with the firm's incident response procedures, escalating promptly to the Director of Information Technology Contribute to the development, maintenance, and testing of the firm's incident response plan, including participation in tabletop exercises Verify that backup, recovery, and business continuity controls are functioning and tested, and support the department's disaster recovery planning Security Program Support, Privacy, and Compliance Provide technical evaluation and recommendations to support the department's selection and adoption of a recognized security framework such as the NIST Cybersecurity Framework, CIS Controls, or ISO 27001 Implement and maintain the technical controls that support the framework, and assist in assessing and reporting the firm's posture against it Assist the Director of Information Technology in drafting and maintaining information security policies, standards, and procedures, and implement the technical measures that carry them out Maintain security documentation, control evidence, and a working risk log, and recommend remediation priorities to the Director of Information Technology Support compliance with applicable privacy and data protection obligations, including the New York SHIELD Act and other state privacy requirements, and requirements applicable to regulated client data such as protected health information Prepare technical responses and supporting documentation for client security requirements, including outside counsel guidelines, security questionnaires, and client and third-party audits, and complete remediation items assigned by the Director of Information Technology Support obligations arising from clients in regulated industries, including financial services requirements such as NYDFS Part 500 as applied to the firm through client agreements Perform technical security reviews of vendors, applications, and services under consideration, and provide findings and recommendations to the Director of Information Technology Assist with independent assessments, including penetration testing and external audits, and complete assigned remediation work Awareness and Collaboration Administer the firm's security awareness program, including training delivery, phishing simulations, and user communication developed with the Director of Information Technology Partner with the IT team on secure configuration, change management, and project work, and provide technical guidance to service desk staff on security escalations Report on control status, vulnerabilities, incidents, and open remediation items to the Director of Information Technology Maintain current knowledge of emerging threats, vulnerabilities, and security technologies relevant to the legal industry, and share findings with the department Technical Skills: Required Hands-on administration of FortiGate firewalls, including policy management, VPN, intrusion prevention, and content filtering Endpoint detection and response administration, ideally CrowdStrike Falcon, and familiarity with Microsoft endpoint protection Microsoft 365 security administration, including cloud email protection, mail flow and filtering, phishing defense, and email authentication using SPF, DKIM, and DMARC Identity and access administration across Microsoft Entra ID and on-premises Active Directory in a hybrid configuration, including multifactor authentication and conditional access Microsoft Intune administration, including device compliance and configuration, application deployment, and device encryption in a hybrid environment Solid networking fundamentals, including TCP/IP, routing and switching, VLANs, DNS, DHCP, segmentation, and wireless security Vulnerability management and patch management practice, including scanning, prioritization, and remediation tracking Security monitoring and log analysis, and experience working with a managed detection and response or co-managed SOC provider Working familiarity with a recognized security framework such as the NIST Cybersecurity Framework, CIS Controls, or ISO 27001, and experience implementing controls in support of one Familiarity with privacy and data protection requirements, including state breach notification obligations and handling of regulated data Ability to produce clear technical documentation, control evidence, risk write-ups, and status reporting for both technical and non-technical readers Preferred Prior experience in a law firm or other professional services environment, including familiarity with outside counsel guidelines and client security audits Experience preparing responses to client security questionnaires and third-party risk assessments Azure or other cloud security administration PowerShell or comparable scripting for automation and reporting Experience with data loss prevention, email encryption, or information rights management Experience with security awareness platforms and phishing simulation tools Familiarity with SD-WAN, zero trust, or secure access service edge architectures Relevant certifications such as Fortinet NSE, CompTIA Security+, GIAC credentials, Microsoft SC-200 or SC-300, CISSP, or CISM Qualifications and Competencies: Strong analytical and problem-solving skills, with sound technical judgment in assessing and prioritizing risk . click apply for full job details
09/15/2026
Full time
Job Description Job Description Job Title: Network Security Engineer Department: Information Technology Location: Rochester, NY Classification: Exempt Reports To: Director of Information Technology Please note: Candidates must be authorized to work in the United States and able to work onsite in the Rochester, NY office. Sponsorship is not available for this position. Company Overview: Woods Oviatt Gilman, LLP is a leading and reputable full-service law firm dedicated to providing exceptional legal services to our clients. With a team of highly skilled and experienced attorneys, we strive to deliver comprehensive and effective solutions to meet the diverse needs of our clients. Our headquarters is in Rochester, NY with additional offices in Albany and Buffalo, NY. We foster a collaborative and inclusive work environment where every team member is valued and respected. We encourage open communication, teamwork, and professional growth. Our firm promotes a healthy work-life balance and supports the well-being of our employees. Position Summary: The Network Security Engineer is a hands-on technical role responsible for implementing, configuring, and maintaining the firm's security controls across a hybrid environment, including FortiGate firewalls, endpoint protection, cloud email and Microsoft 365, Intune-managed devices, and a co-managed monitoring and detection service. The Engineer works under the direction of the Director of Information Technology, who sets security policy and priorities for the department, and provides the technical assessment, recommendations, and documentation that support those decisions. Because the firm safeguards confidential and privileged client information, this position calls for strong technical skill, sound judgment, discretion, and clear communication with both the IT team and firm personnel. Duties and Responsibilities: Network and Perimeter Security Administer, tune, and monitor FortiGate firewalls, including security policies, VPN configuration, intrusion prevention, web and content filtering, and logging Implement and maintain network segmentation, secure remote access, and wireless security across firm locations, in line with the department's standards Maintain secure connectivity for remote and hybrid users, including VPN and conditional access Conduct scheduled reviews of firewall rules and network configurations, recommend changes to the Director of Information Technology, and maintain accurate network security documentation Endpoint, Identity, and Email Security Administer the firm's endpoint protection platforms, including CrowdStrike and Microsoft endpoint protection, covering policy configuration, detection review, containment actions, and agent coverage Configure and maintain device compliance, configuration, and application deployment through Microsoft Intune in a hybrid environment, including full-disk encryption and recovery key handling Configure and maintain identity and access controls across Microsoft Entra ID and on-premises Active Directory, including multifactor authentication, conditional access, and privileged account settings, and perform periodic access reviews Configure and maintain security settings for cloud email and collaboration, including mail flow and filtering rules, phishing and malware defenses, email authentication records, and Microsoft 365 security configuration Perform vulnerability and patch management across servers, endpoints, and network devices, including scanning, prioritizing findings, tracking remediation, and reporting status to the Director of Information Technology Monitoring, Detection, and Incident Response Serve as the day-to-day technical contact for the firm's managed monitoring service, triaging alerts, validating findings, and carrying issues through to resolution Investigate security events and perform containment, eradication, and recovery steps in accordance with the firm's incident response procedures, escalating promptly to the Director of Information Technology Contribute to the development, maintenance, and testing of the firm's incident response plan, including participation in tabletop exercises Verify that backup, recovery, and business continuity controls are functioning and tested, and support the department's disaster recovery planning Security Program Support, Privacy, and Compliance Provide technical evaluation and recommendations to support the department's selection and adoption of a recognized security framework such as the NIST Cybersecurity Framework, CIS Controls, or ISO 27001 Implement and maintain the technical controls that support the framework, and assist in assessing and reporting the firm's posture against it Assist the Director of Information Technology in drafting and maintaining information security policies, standards, and procedures, and implement the technical measures that carry them out Maintain security documentation, control evidence, and a working risk log, and recommend remediation priorities to the Director of Information Technology Support compliance with applicable privacy and data protection obligations, including the New York SHIELD Act and other state privacy requirements, and requirements applicable to regulated client data such as protected health information Prepare technical responses and supporting documentation for client security requirements, including outside counsel guidelines, security questionnaires, and client and third-party audits, and complete remediation items assigned by the Director of Information Technology Support obligations arising from clients in regulated industries, including financial services requirements such as NYDFS Part 500 as applied to the firm through client agreements Perform technical security reviews of vendors, applications, and services under consideration, and provide findings and recommendations to the Director of Information Technology Assist with independent assessments, including penetration testing and external audits, and complete assigned remediation work Awareness and Collaboration Administer the firm's security awareness program, including training delivery, phishing simulations, and user communication developed with the Director of Information Technology Partner with the IT team on secure configuration, change management, and project work, and provide technical guidance to service desk staff on security escalations Report on control status, vulnerabilities, incidents, and open remediation items to the Director of Information Technology Maintain current knowledge of emerging threats, vulnerabilities, and security technologies relevant to the legal industry, and share findings with the department Technical Skills: Required Hands-on administration of FortiGate firewalls, including policy management, VPN, intrusion prevention, and content filtering Endpoint detection and response administration, ideally CrowdStrike Falcon, and familiarity with Microsoft endpoint protection Microsoft 365 security administration, including cloud email protection, mail flow and filtering, phishing defense, and email authentication using SPF, DKIM, and DMARC Identity and access administration across Microsoft Entra ID and on-premises Active Directory in a hybrid configuration, including multifactor authentication and conditional access Microsoft Intune administration, including device compliance and configuration, application deployment, and device encryption in a hybrid environment Solid networking fundamentals, including TCP/IP, routing and switching, VLANs, DNS, DHCP, segmentation, and wireless security Vulnerability management and patch management practice, including scanning, prioritization, and remediation tracking Security monitoring and log analysis, and experience working with a managed detection and response or co-managed SOC provider Working familiarity with a recognized security framework such as the NIST Cybersecurity Framework, CIS Controls, or ISO 27001, and experience implementing controls in support of one Familiarity with privacy and data protection requirements, including state breach notification obligations and handling of regulated data Ability to produce clear technical documentation, control evidence, risk write-ups, and status reporting for both technical and non-technical readers Preferred Prior experience in a law firm or other professional services environment, including familiarity with outside counsel guidelines and client security audits Experience preparing responses to client security questionnaires and third-party risk assessments Azure or other cloud security administration PowerShell or comparable scripting for automation and reporting Experience with data loss prevention, email encryption, or information rights management Experience with security awareness platforms and phishing simulation tools Familiarity with SD-WAN, zero trust, or secure access service edge architectures Relevant certifications such as Fortinet NSE, CompTIA Security+, GIAC credentials, Microsoft SC-200 or SC-300, CISSP, or CISM Qualifications and Competencies: Strong analytical and problem-solving skills, with sound technical judgment in assessing and prioritizing risk . click apply for full job details
Cybersecurity Engineer (On-Site)
Middlesex Savings Bank Westborough, Massachusetts
OverviewThe cybersecurity engineer has a dual role in the Bank: a responsibility for architecting, building, and maintaining secure environments and applications that are designed to protect the Bank's networks, data and digital assets from risk. In addition, a responsibility for monitoring, detecting, and responding to security related risks. Their primary focus is strengthening defenses, identifying vulnerabilities and weaknesses, responding to threats, and implementing measures to continually strengthen the Banks security posture. Please note: New hires work on-site in the Massachusetts office for 90 days before transitioning to a hybrid or remote schedule. Responsibilities Threat Hunting, Monitoring, Detection, and Response: Monitor security alerts and dashboards (SIEM, Vulnerability Management etc.) for suspicious activity. Triage and respond to security incidents. Escalate to senior analysts or the incident response team when necessary. Investigate and document security observations/incidents, ensuring resolution. Analyze logs, network traffic, and endpoint activity for signs for malicious behavior. Perform regular vulnerability assessments and prioritize risk within the network, system, and applications. Create formal incidents and support the investigation of such incidents. Conduct Security Assessments: Perform regular security audits, vulnerability assessments, and penetration testing to identify and mitigate potential risks. Correlate telemetry data from security systems to identity cyber threats, risk patterns, and control weaknesses. System & Security Application Administration: Implementation, secure configuration, and ongoing management of the Bank's security environments and applications. Examples of systems/functions a Cyber Security Engineer may be responsible for are firewall management, IDS/IPS, perimeter security, protective DNS, vulnerability detection/response, secure email and spam protection, application whitelisting, remote access, etc.). Server ownership - building, hardening, securing, and ongoing management of assigned server assets. Identifying and mitigating vulnerabilities on assigned assets. Ensures assigned systems and required data is backed up successfully. Ensures adherence to IT security control requirements. Security Application ownership Effective configuration of application functionality, detection, and mitigation abilities. Identifying and mitigating vulnerabilities on assigned applications. Review system, application, and security logs across assigned systems to ensure that all are functional and secure. Manages and leverages third party vendor relationships as required. Participates in the planning and execution of the Business Continuity and Disaster Recovery Plan. Ensures assigned systems and applications are prepared for planned or unplanned DR failover. Manages and communicates system and applications changes using the change management process. Track and understand emerging security practices and threats. Leverage this knowledge to improve security configurations across the enterprise and hunt for potential or active threats.RequirementsEducation Bachelor's Degree in computer science, information systems or equivalent work experience is requiredWork Experience Experience managing and securing Microsoft Windows or Linux is is required 5+ years experience supporting security components and applying security best practices across an enterprise application/network infrastructure is requiredKnowledge, Skills, and Abilities Working knowledge of IT security controls and how to manage their effectiveness. Strong understanding of cybersecurity protocols, including intrusion detection systems, firewalls, patch management, and vulnerability management. Formal technical training on Microsoft technologies, Network Operating Systems and Internet perimeter components required. Working knowledge of CIS Top 18 Controls or alternative security frameworks. Certified Information Systems Security Professional (CISSP) desired but not required. An ability to perform independent analysis of complex problems and distill relevant findings and root causes Must possess excellent analytical, organizational and documentation skills. Experience analyzing and interpreting alert notifications from organizations such as FS-ISAC and CERN Candidates for this position must be authorized to work in the United States on a full time basis for any employer without restriction Visa Sponsorship will not be provided for this position Valid Drivers License required No relocation assistance is provided.Licenses and Certifications Industry standard certification required in a technical discipline to include one of the following Network Operating System (Microsoft), or Network infrastructure, or Information Security. RequiredExpected Pay RangeThe expected annual pay range for this role is $76,463 to $135,731. This pay range is the annual salary we in good faith expect to pay for this role at the time of posting. Actual compensation paid may fluctuate higher or lower than the posted range and the range may be modified in the future due to several factors including, but not limited to, relevant experience, certifications, and qualifications, internal equity, adjustments to the requirements and responsibilities of the job, business needs, and economic and market data.EEO StatementMiddlesex Savings Bank is an Equal Opportunity Employer/protected Veterans/Individuals with Disabilities
09/15/2026
OverviewThe cybersecurity engineer has a dual role in the Bank: a responsibility for architecting, building, and maintaining secure environments and applications that are designed to protect the Bank's networks, data and digital assets from risk. In addition, a responsibility for monitoring, detecting, and responding to security related risks. Their primary focus is strengthening defenses, identifying vulnerabilities and weaknesses, responding to threats, and implementing measures to continually strengthen the Banks security posture. Please note: New hires work on-site in the Massachusetts office for 90 days before transitioning to a hybrid or remote schedule. Responsibilities Threat Hunting, Monitoring, Detection, and Response: Monitor security alerts and dashboards (SIEM, Vulnerability Management etc.) for suspicious activity. Triage and respond to security incidents. Escalate to senior analysts or the incident response team when necessary. Investigate and document security observations/incidents, ensuring resolution. Analyze logs, network traffic, and endpoint activity for signs for malicious behavior. Perform regular vulnerability assessments and prioritize risk within the network, system, and applications. Create formal incidents and support the investigation of such incidents. Conduct Security Assessments: Perform regular security audits, vulnerability assessments, and penetration testing to identify and mitigate potential risks. Correlate telemetry data from security systems to identity cyber threats, risk patterns, and control weaknesses. System & Security Application Administration: Implementation, secure configuration, and ongoing management of the Bank's security environments and applications. Examples of systems/functions a Cyber Security Engineer may be responsible for are firewall management, IDS/IPS, perimeter security, protective DNS, vulnerability detection/response, secure email and spam protection, application whitelisting, remote access, etc.). Server ownership - building, hardening, securing, and ongoing management of assigned server assets. Identifying and mitigating vulnerabilities on assigned assets. Ensures assigned systems and required data is backed up successfully. Ensures adherence to IT security control requirements. Security Application ownership Effective configuration of application functionality, detection, and mitigation abilities. Identifying and mitigating vulnerabilities on assigned applications. Review system, application, and security logs across assigned systems to ensure that all are functional and secure. Manages and leverages third party vendor relationships as required. Participates in the planning and execution of the Business Continuity and Disaster Recovery Plan. Ensures assigned systems and applications are prepared for planned or unplanned DR failover. Manages and communicates system and applications changes using the change management process. Track and understand emerging security practices and threats. Leverage this knowledge to improve security configurations across the enterprise and hunt for potential or active threats.RequirementsEducation Bachelor's Degree in computer science, information systems or equivalent work experience is requiredWork Experience Experience managing and securing Microsoft Windows or Linux is is required 5+ years experience supporting security components and applying security best practices across an enterprise application/network infrastructure is requiredKnowledge, Skills, and Abilities Working knowledge of IT security controls and how to manage their effectiveness. Strong understanding of cybersecurity protocols, including intrusion detection systems, firewalls, patch management, and vulnerability management. Formal technical training on Microsoft technologies, Network Operating Systems and Internet perimeter components required. Working knowledge of CIS Top 18 Controls or alternative security frameworks. Certified Information Systems Security Professional (CISSP) desired but not required. An ability to perform independent analysis of complex problems and distill relevant findings and root causes Must possess excellent analytical, organizational and documentation skills. Experience analyzing and interpreting alert notifications from organizations such as FS-ISAC and CERN Candidates for this position must be authorized to work in the United States on a full time basis for any employer without restriction Visa Sponsorship will not be provided for this position Valid Drivers License required No relocation assistance is provided.Licenses and Certifications Industry standard certification required in a technical discipline to include one of the following Network Operating System (Microsoft), or Network infrastructure, or Information Security. RequiredExpected Pay RangeThe expected annual pay range for this role is $76,463 to $135,731. This pay range is the annual salary we in good faith expect to pay for this role at the time of posting. Actual compensation paid may fluctuate higher or lower than the posted range and the range may be modified in the future due to several factors including, but not limited to, relevant experience, certifications, and qualifications, internal equity, adjustments to the requirements and responsibilities of the job, business needs, and economic and market data.EEO StatementMiddlesex Savings Bank is an Equal Opportunity Employer/protected Veterans/Individuals with Disabilities
Leidos
Cyber Fusion and Threats Analyst
Leidos Odenton, Maryland
Leidos is seeking a Cyber Fusion and Threats Analyst to protect mission-critical systems for government and commercial clients. In this hybrid role near Reston, VA, you will analyze security events, correlate threat intelligence, and respond to complex cyber incidents in a collaborative fusion center environment. Responsibilities include triage, containment, and remediation support; developing threat reports and IOCs; and refining detection content and playbooks. You'll work with cross-functional teams, leverage advanced tools, and stay current on adversary TTPs to support national security and critical infrastructure missions. Responsibilities Monitor and analyze security events from multiple sources to identify cyber threats and intrusions. Correlate intelligence, logs, and network data to build a comprehensive threat picture. Conduct incident triage, containment, and remediation in coordination with SOC and engineering teams. Produce threat reports, indicators of compromise, and recommendations for risk mitigation. Support development and tuning of detection rules, playbooks, and automation workflows. Collaborate with government and commercial stakeholders to support mission-critical operations. Stay current on adversary TTPs, emerging vulnerabilities, and cyber defense best practices. Required Skills Security Incident and Event Monitoring (SIEM) Network traffic analysis Threat intelligence analysis Incident response and containment Endpoint detection and response (EDR) Writing and tuning detection rules (e.g., SIEM queries) Malware and IOC analysis Scripting/automation (e.g., Python, Power Shell) Knowledge of MITRE ATT&CK framework Vulnerability assessment and risk prioritization
09/14/2026
Full time
Leidos is seeking a Cyber Fusion and Threats Analyst to protect mission-critical systems for government and commercial clients. In this hybrid role near Reston, VA, you will analyze security events, correlate threat intelligence, and respond to complex cyber incidents in a collaborative fusion center environment. Responsibilities include triage, containment, and remediation support; developing threat reports and IOCs; and refining detection content and playbooks. You'll work with cross-functional teams, leverage advanced tools, and stay current on adversary TTPs to support national security and critical infrastructure missions. Responsibilities Monitor and analyze security events from multiple sources to identify cyber threats and intrusions. Correlate intelligence, logs, and network data to build a comprehensive threat picture. Conduct incident triage, containment, and remediation in coordination with SOC and engineering teams. Produce threat reports, indicators of compromise, and recommendations for risk mitigation. Support development and tuning of detection rules, playbooks, and automation workflows. Collaborate with government and commercial stakeholders to support mission-critical operations. Stay current on adversary TTPs, emerging vulnerabilities, and cyber defense best practices. Required Skills Security Incident and Event Monitoring (SIEM) Network traffic analysis Threat intelligence analysis Incident response and containment Endpoint detection and response (EDR) Writing and tuning detection rules (e.g., SIEM queries) Malware and IOC analysis Scripting/automation (e.g., Python, Power Shell) Knowledge of MITRE ATT&CK framework Vulnerability assessment and risk prioritization

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board