1

Network Segmentation Jobs in Kentucky (NOW HIRING)

$120 - $180/hr

This position offers the opportunity to work with modern technologies including Cisco, Meraki, Arista, VMware, Microsoft Azure, SD-WAN, network segmentation, Zero Trust principles, EntraID, MS365 and ...

$90 - $120/hr

Primary responsibilities include ownership of enterprise firewall services, network security segmentation, VPN and Network Access Control (NAC) security services, security event monitoring within the ...

$108 - $138/hr

Implement and maintain firewall policies, VPN access, NAT rules, network segmentation, and secure network configuration practices. * Support manufacturing, warehouse, distribution, and OT network ...

$104 - $218/hr

Configure and maintain network routing, switching, VPN connectivity, network segmentation, quality of service (QoS), and high-availability solutions. * Deploy, administer, and optimize enterprise ...

$120 - $180/hr

Design enterprise network segmentation strategies, including macro- and micro-segmentation. * Design and deploy Palo Alto Networks Next-Generation Firewall architectures. * Establish standards and ...

$110 - $150/hr

Operate and administer Nozomi Networks Guardian sensors across OT network segments for asset visibility and threat detection. * Utilize Nozomi Vantage for centralized management, dashboarding, and ...

$140 - $190/hr

Provide advanced technical guidance on routing protocols, network segmentation, and secure connectivity * Document network changes, configurations, and best practices Requirements for the Network ...

$140 - $160/hr

Apply NAC, segmentation, Zero Trust, and secure network-access principles across enterprise environments. Firewall Administration * Administer and secure Palo Alto Networks next-generation firewalls ...

$140 - $210/hr

This role oversees the design and enforcement of network security controls, including segmentation and micro-segmentation strategies, edge security, and infrastructure hardening initiatives. The ...

$90 - $130/hr

Implement and maintain network segmentation between enterprise IT and OT environments * Support secure remote access solutions for employees, contractors, vendors, and operational personnel

Sr. OT Network Engineer

Georgetown, KY · On-site

$93K - $128K/yr

OT cybersecurity requirements are incorporated into network solutions, including segmentation, IDMZ, and access control practices. * escalation support for network incidents and coordinate issue ...

$110 - $160/hr

Partner with Information Security and IT leadership on segmentation, Zero Trust initiatives, compliance requirements, and risk management. * Drive network automation and operational efficiency ...

$90 - $140/hr

Lead network planning and deployment for greenfield and brownfield projects, including site LAN/WAN, VLANs, routing, and segmentation * Configure and support industrial switches, routers, firewalls ...

next page

Showing results 1-20

Network Segmentation information

What is network segmentation?

Network segmentation is the practice of dividing a computer network into smaller, isolated subnetworks to improve security and performance. By separating systems and data, organizations can limit the spread of cyber threats and control user access to sensitive information. This approach helps contain breaches, simplifies compliance, and enhances the efficiency of network management. Common techniques include using VLANs, firewalls, and access control lists to enforce boundaries between segments.

What are the key skills and qualifications needed to thrive in a network segmentation role, and why are they important?

To thrive in a Network Segmentation role, you need a solid understanding of networking concepts, security best practices, and experience with firewalls and VLAN configuration, often supported by certifications like CCNA or CISSP. Familiarity with tools such as network monitoring systems, segmentation platforms, and security information and event management (SIEM) solutions is typically required. Strong analytical thinking, attention to detail, and effective communication are essential soft skills for collaborating with IT teams and identifying security gaps. These skills ensure that network environments are properly segmented to minimize security risks and maintain organizational compliance.

What are some common challenges faced by professionals working in network segmentation roles, and how can they be addressed?

Professionals in network segmentation roles often encounter challenges such as effectively balancing security with business operations, managing legacy systems, and ensuring seamless communication between segmented zones. Addressing these challenges typically involves working closely with IT and business units to understand critical workflows, implementing robust access controls and monitoring, and regularly updating segmentation policies to adapt to organizational changes. Staying current with industry best practices and leveraging automation tools can also help streamline the process and minimize human error.

What is the difference between Network Segmentation vs Network Security Engineer?

AspectNetwork SegmentationNetwork Security Engineer
Primary FocusDividing a network into segments to control trafficDesigning, implementing, and managing security measures
Required SkillsNetworking protocols, VLANs, firewallsFirewall configuration, intrusion detection, security policies
Work EnvironmentNetwork infrastructure, data centers, enterprise networksSecurity teams, IT departments, cybersecurity environments
CertificationsCCNA, CompTIA Network+CISSP, CEH, CompTIA Security+

Network segmentation involves dividing a network into smaller parts to improve performance and security, while a Network Security Engineer focuses on protecting the network through security measures. Both roles require networking knowledge, but their primary objectives differ: segmentation manages network structure, whereas security engineers safeguard it from threats.

What do you need for network segmentation?

A network segmentation specialist needs a clear understanding of network architecture, access controls, and security policies. They typically require knowledge of VLANs, firewalls, and network monitoring tools, along with relevant certifications like Cisco CCNA or CompTIA Security+. Proper planning and implementation skills are essential to effectively isolate network segments and enhance security.

What are popular job titles related to Network Segmentation jobs in Kentucky?

For Network Segmentation jobs in Kentucky, the most frequently searched job titles are:

Network Security Engineer (Network & Cybersecurity)

BakerRisk Europe, Ltd.

On-site

$120 - $180/hr

Other

Medical, Dental, Retirement, PTO

Posted 5 days ago


Job description

Career Opportunities withBaker Engineering and Risk Consultants, Inc.

A great place to work.

Careers At Baker Engineering and Risk Consultants, Inc.

Current job opportunities are posted here as they become available.

Network Security Engineer (Network & Cybersecurity)

Baker Engineering and Risk Consultants, Inc. (BakerRisk®) is a global provider of process safety and risk management services to companies in the petroleum and chemical industries, as well as engineering and testing services for government agencies and private companies involved with hazardous materials. Utilizing advanced methodologies and proprietary in-house tools, BakerRisk engineers assess the consequences and risks associated with potentially catastrophic events including explosions, fires, and toxic material releases.

Position Summary

BakerRisk is seeking a highly skilled and motivated Network Security Engineer, with strong networking fundamentals who has evolved into a cybersecurity-focused practitioner and is comfortable owning security operations, Microsoft identity security, and VMWare/Cloud networking in a small enterprise environment to join our Global Management Network team. This role is responsible for the design, implementation, administration, and security of BakerRisk's enterprise network infrastructure, cloud connectivity, cybersecurity policy implementation, tools & infrastructure.

The ideal candidate will possess strong experience with enterprise networking technologies, security architecture, firewalls, cloud networking, and security monitoring with a successful track record working in a team-oriented environment. This individual will play a key role in protecting critical business systems while supporting a reliable, scalable, and secure technology environment across multiple office locations, datacenters, and cloud platforms.

This position offers the opportunity to work with modern technologies including Cisco, Meraki, Arista, VMware, Microsoft Azure, SD-WAN, network segmentation, Zero Trust principles, EntraID, MS365 and enterprise cybersecurity solutions.

  • Design, implement, maintain, and troubleshoot enterprise LAN, WAN, wireless, and data center network infrastructure.
  • Configure and manage Cisco, Meraki, and Arista network devices.
  • Administer VPN technologies and secure remote access solutions.
  • Manage SD-WAN connectivity between offices, cloud environments, and datacenters.
  • Maintain IP address management (IPAM), network documentation, and infrastructure diagrams.
  • Monitor network performance and availability while proactively identifying capacity and reliability improvements.
  • Implement VMWare NSX, NSX-T

Cybersecurity & Network Protection

  • Serve as the primary technical owner for cybersecurity operations, security controls, and vulnerability management by designing, implementing, and continuously enhancing firewalls, IDS/IPS, network segmentation, Zero Trust architecture, and other security initiatives in partnership with IT management and architecture leadership.
  • Administer and maintain perimeter security devices and cloud security controls.
  • Support vulnerability management, remediation, and risk reduction initiatives.
  • Participate in incident detection, investigation, response, and recovery activities.
  • Monitor security alerts and work with internal stakeholders to address threats and vulnerabilities.
  • Implement security hardening standards across network and cloud platforms.
  • Assist with regulatory and compliance initiatives, including NIST 800-171, DFARS, cybersecurity assessments, and security audits.

Identity & Microsoft Security

  • Administer and secure Active Directory and Microsoft Entra ID environments.
  • Implement and support identity security controls including MFA, Conditional Access, privileged access management, and identity governance.
  • Support security, compliance, and operational controls across Microsoft 365 services including Exchange Online, Teams, SharePoint, and OneDrive.
  • Leverage Crowdstrike Falcon and related security platforms to improve detection, response, visibility, and risk reduction.
  • Partner with infrastructure teams to improve identity security posture and reduce organizational risk.
  • Design, configure, and manage MS365, Azure, & VCF networking and hybrid connectivity solutions, including virtual networks, VPNs, private connectivity, network segmentation, and secure integration between cloud and on-premises environments.
  • Implement and maintain cloud security architectures and controls that protect VCF, Azure, hybrid infrastructure, and business-critical services.
  • Collaborate with infrastructure and architecture teams to ensure secure, scalable, and resilient cloud and hybrid deployments.

Documentation & Operational Excellence

  • Develop and maintain detailed network diagrams, standards, procedures, and operational documentation within ManageEngine OpsManager.
  • Participate in change management and project planning activities.
  • Manage vendor relationships, support contracts, and technology evaluations.
  • Provide Tier III escalation support for complex networking and security issues.
  • Participate in an on-call rotation and support after-hours maintenance as needed.

Required Qualifications

  • 5+ years of enterprise network engineering experience.
  • Demonstrated ability to balance networking, cybersecurity, cloud technologies, operational support, documentation, and project work within a small or mid-sized IT organization.
  • Strong experience with Cisco networking technologies, including routing, switching, VPNs, firewalls, and network security controls.
  • Experience with Microsoft Azure networking, hybrid cloud connectivity, and secure integration between cloud and on-premises environments.
  • Experience supporting Active Directory and Microsoft Entra ID administration and security.
  • Experience implementing identity security controls, including Multi-Factor Authentication (MFA), Conditional Access, privileged access controls, and secure authentication practices.
  • Experience securing Microsoft 365 environments and cloud-based collaboration platforms.
  • Knowledge of network and cybersecurity principles, including Zero Trust, network segmentation, secure remote access, infrastructure hardening, and risk reduction.
  • Experience with security monitoring, vulnerability management, remediation planning, incident response, and cybersecurity operations.
  • Experience supporting cybersecurity compliance initiatives, security assessments, and NIST-based security frameworks.
  • Demonstrated ability to balance networking, cybersecurity, cloud technologies, operational support, documentation, and project work in a small or mid-sized IT organization.
  • Strong troubleshooting, analytical, documentation, verbal communication, and written communication skills.

Preferred Qualifications

  • Experience with Cisco Meraki and Arista networking platforms.
  • Experience with VMware networking technologies including NSX, network virtualization, distributed firewalling, overlay networking, logical routing, and micro-segmentation.
  • Experience with EDR CrowdStrike Falcon, Microsoft Defender, SIEM, IDS/IPS, and security monitoring platforms.
  • Familiarity with NIST Cybersecurity Framework, NIST 800-171, CMMC, and DFARS compliance requirements.
  • Experience supporting multi-site environments and datacenter operations.
  • Experience with scripting and automation using PowerShell, Python, & ManageEngine or similar tools.

Preferred Certifications

  • One or more of the following certifications is preferred:
  • CCNP Enterprise
  • CCNP Security
  • CISSP
  • CompTIA Security+
  • Microsoft Azure Security Engineer (AZ-500)
  • Palo Alto, Fortinet, or equivalent firewall certifications
  • VMWare vSphere or VCF Certification

What Success Looks Like

Within the first year, this individual will:

  • Strengthen BakerRisk's network security posture.
  • Improve visibility into network and security events.
  • Reduce organizational risk through improved segmentation and hardening.
  • Assist with and help drive cybersecurity compliance initiatives including NIST 800-171, DFARS, CMMC readiness activities, security assessments, remediation planning, and audit preparation.
  • Help modernize network and cloud infrastructure while maintaining high availability and performance.

BakerRisk offers a competitive salary and benefit package including holiday, vacation and sick leave pay, medical/dental insurance, 401(k), Employee Stock Ownership Plan (ESOP), and potential for a year-end bonus. Position and pay DOE.

BakerRisk® is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law.

Additional Information: For additional information, please see our website at www.BakerRisk.com

#J-18808-Ljbffr