Duration: 24 Months, extension possible based on needs and performance
Location: Brooklyn, NY 11201 (Onsite)
Job Title: Network Security Engineer
Job Summary:
OUTLINE OF RESPONSIBILITIES
- Work with IT Security team and Cyber Command to investigate and respond to detected vulnerabilities and to ensure all environments are appropriately patched in a timely manner.
- Responsible for using tools such as Splunk to correlate event or incident data to identify specific vulnerabilities and make recommendations that enable expeditious remediation.
- Assist with planning, implementing, upgrading, or monitoring security measures for the protection of computer networks, systems, and information.
- Troubleshoot and recommend improvements to network including operating systems and related software and provides tactical and strategic input to overall network planning and related projects.
- Isolates and resolves network problems in a timely manner.
- Provide solution design and operational support of Cisco ASA and FirePOWER (FMC/FTD/FXOS) network firewalls including AnyConnect remote access VPNs as well as isakmp/IKEv2/VTI/IPSEC/GRE site-to-site tunnels.
- Collaborating with applications and support teams on design and implementation of application load balancing solutions (F5, Avi Networks/NSX Load Balancer).
- Configuration of Cisco Identity Services Engine (ISE) for identity and access control.
- Management of Azure/AWS cloud networks and firewalls.
- Working closely with security team on Zscaler policy management and report generation.
- Using tools (e.g., Netscout, Wireshark, tcpdump) to perform packet-level analysis for monitoring for security risks and troubleshooting network traffic.
- Responsible for working with vendors and resolving network outages in a timely fashion in order to meet internal SLAs and / or Metrics.
- Creating and updating Standard Operating Procedures, network documentation and diagrams using Visio/Lucidchart.
MANDATORY MINIMUM QUALIFICATIONS
The successful candidate must have minimally achieved the following level of experience:
10+ years of experience in in network security (Cisco ASA & Firepower)
5+ years of experience with F5 load balancing (LTM, GTM, BIG-IQ)
5+ years of packet analysis to resolve complex technical issues.
5+ years of experience in configuring and troubleshooting Cisco routers and L2/L3 switches
5+ years of experience routing protocols such as, BGP, OSPF, EIGRP, etc.
Cisco CCNA, CCNP, CompTIA Security+ or other related industry security certifications
PREFERABLE QUALIFICATIONS
Prior education industry/project experience
Must be a self-starter and be able to work well independently and in a team
Excellent oral and written communication skills; ability to communicate in a credible and confident manner at all levels in the organization especially on technical issues to a non-technical audience.
Detailed and process-oriented
Experience in VMware NSX and NSX Advanced Load Balancer
Experience using Splunk SIEM and Splunk Processing Language (SPL)
Experience Azure/AWS cloud infrastructure and Express Route
Experience in implementing network security best practices
2 Professional reference