Impress employers and recruiters.
Choose from hundreds of resume examples.

Impress employers and recruiters.
Choose from hundreds of resume examples.
Tailor your resume to this Network Security Engineer role.
Rezi rewrites your resume against Woods Oviatt Gilman LLP's job description. Free.

Tailor your resume to this Network Security Engineer role.
Rezi rewrites your resume against Woods Oviatt Gilman LLP's job description. Free.
Don't guess if your resume is good enough.
See how it scores against the Network Security Engineer posting at Woods Oviatt Gilman LLP — free, in seconds.

Don't guess if your resume is good enough.
See how it scores against the Network Security Engineer posting at Woods Oviatt Gilman LLP — free, in seconds.
About the Role
The Network Security Engineer is a hands-on technical role responsible for implementing, configuring, and maintaining the firm's security controls across a hybrid environment. This role supports the Director of Information Technology by providing technical assessment, recommendations, and documentation for security policy and priorities. The position requires strong technical skill, sound judgment, discretion, and clear communication due to the firm's safeguarding of confidential client information.
Responsibilities
- Administer, tune, and monitor FortiGate firewalls, including security policies, VPN configuration, intrusion prevention, web and content filtering, and logging.
- Implement and maintain network segmentation, secure remote access, and wireless security across firm locations.
- Maintain secure connectivity for remote and hybrid users, including VPN and conditional access.
- Conduct scheduled reviews of firewall rules and network configurations, recommend changes, and maintain accurate network security documentation.
- Administer endpoint protection platforms, including policy configuration, detection review, containment actions, and agent coverage.
- Configure and maintain device compliance, configuration, and application deployment through Microsoft Intune.
- Configure and maintain identity and access controls across Microsoft Entra ID and on-premises Active Directory.
- Configure and maintain security settings for cloud email and collaboration.
- Perform vulnerability and patch management across servers, endpoints, and network devices.
- Serve as the day-to-day technical contact for the firm's managed monitoring service, triaging alerts and validating findings.
- Investigate security events and perform containment, eradication, and recovery steps.
- Contribute to the development, maintenance, and testing of the firm's incident response plan.
- Verify that backup, recovery, and business continuity controls are functioning and tested.
- Provide technical evaluation and recommendations to support the selection and adoption of a recognized security framework.
- Implement and maintain the technical controls that support the framework, and assist in assessing and reporting the firm's posture against it.
- Assist in drafting and maintaining information security policies, standards, and procedures.
- Maintain security documentation, control evidence, and a working risk log.
- Support compliance with applicable privacy and data protection obligations.
- Prepare technical responses and supporting documentation for client security requirements.
- Support obligations arising from clients in regulated industries.
- Perform technical security reviews of vendors, applications, and services.
- Assist with independent assessments, including penetration testing and external audits.
- Administer the firm's security awareness program, including training delivery and phishing simulations.
- Partner with the IT team on secure configuration, change management, and project work.
- Provide technical guidance to service desk staff on security escalations.
- Report on control status, vulnerabilities, incidents, and open remediation items.
- Maintain current knowledge of emerging threats, vulnerabilities, and security technologies.
Requirements
- Hands-on administration of FortiGate firewalls, including policy management, VPN, intrusion prevention, and content filtering.
- Endpoint detection and response administration, ideally CrowdStrike Falcon, and familiarity with Microsoft endpoint protection.
- Microsoft 365 security administration, including cloud email protection, mail flow and filtering, phishing defense, and email authentication using SPF, DKIM, and DMARC.
- Identity and access administration across Microsoft Entra ID and on-premises Active Directory in a hybrid configuration, including multifactor authentication and conditional access.
- Microsoft Intune administration, including device compliance and configuration, application deployment, and device encryption in a hybrid environment.
- Solid networking fundamentals, including TCP/IP, routing and switching, VLANs, DNS, DHCP, segmentation, and wireless security.
- Vulnerability management and patch management practice, including scanning, prioritization, and remediation tracking.
- Security monitoring and log analysis, and experience working with a managed detection and response or co-managed SOC provider.
- Working familiarity with a recognized security framework such as the NIST Cybersecurity Framework, CIS Controls, or ISO 27001, and experience implementing controls in support of one.
- Familiarity with privacy and data protection requirements, including state breach notification obligations and handling of regulated data.
- Ability to produce clear technical documentation, control evidence, risk write-ups, and status reporting for both technical and non-technical readers.
- Prior experience in a law firm or other professional services environment, including familiarity with outside counsel guidelines and client security audits.
- Experience preparing responses to client security questionnaires and third-party risk assessments.
- Azure or other cloud security administration.
- PowerShell or comparable scripting for automation and reporting.
- Experience with data loss prevention, email encryption, or information rights management.
- Experience with security awareness platforms and phishing simulation tools.
- Familiarity with SD-WAN, zero trust, or secure access service edge architectures.
- Relevant certifications such as Fortinet NSE, CompTIA Security+, GIAC credentials, Microsoft SC-200 or SC-300, CISSP, or CISM.
- Strong analytical and problem-solving skills, with sound technical judgment in assessing and prioritizing risk.
- Ability to manage assigned technical work independently while escalating decisions and exceptions appropriately.
- Clear verbal and written communication, including the ability to explain security risks and requirements to attorneys, staff, and IT colleagues.
- Ability to weigh security requirements against practical business needs and recommend workable options.
- Ability to influence behavior and support change constructively and without confrontation.
- Highly organized and detail-oriented, and able to manage concurrent projects alongside daily operational work.
- Discretion and sound judgment in handling confidential and privileged information.
- Commitment to continued technical development in a rapidly changing field.
Skills
- FortiGate firewalls
- VPN configuration
- Intrusion prevention
- Web filtering
- Content filtering
- Network segmentation
- Secure remote access
- Wireless security
- Conditional access
- Endpoint protection
- CrowdStrike Falcon
- Microsoft endpoint protection
- Microsoft 365 security
- Cloud email protection
- Mail flow rules
- Phishing defense
- Email authentication (SPF, DKIM, DMARC)
- Microsoft Entra ID
- On-premises Active Directory
- Multifactor authentication
- Microsoft Intune
- Device compliance
- Application deployment
- Device encryption
- TCP/IP
- Routing
- Switching
- VLANs
- DNS
- DHCP
- Vulnerability management
- Patch management
- Security monitoring
- Log analysis
- Managed detection and response (MDR)
- NIST Cybersecurity Framework
- CIS Controls
- ISO 27001
- Privacy and data protection
- New York SHIELD Act
- Technical documentation
- Risk assessment
- Status reporting
- Outside counsel guidelines
- Client security audits
- Security questionnaires
- Third-party risk assessments
- Azure security
- Cloud security
- PowerShell scripting
- Data loss prevention (DLP)
- Email encryption
- Information rights management (IRM)
- Security awareness platforms
- Phishing simulation tools
- SD-WAN
- Zero trust
- Secure Access Service Edge (SASE)
- Fortinet NSE
- CompTIA Security+
- GIAC credentials
- Microsoft SC-200
- Microsoft SC-300
- CISSP
- CISM
- Analytical skills
- Problem-solving skills
- Technical judgment
- Independent work management
- Escalation management
- Verbal communication
- Written communication
- Business needs assessment
- Change management
- Organization
- Detail-orientation
- Project management
- Discretion
- Confidentiality
- Continuous learning
Location
- Rochester, NY
Work Type
- Hybrid
Experience Level
- Five or more years of hands-on experience in network security, information security, or systems and network engineering with substantial security responsibility.
Education Level
- Bachelor of Science in Information Technology, Cybersecurity, Computer Science, or a related field, or equivalent practical experience.
Salary/Compensations
- $100,000-$120,000 annually
About the Company
- Woods Oviatt Gilman, LLP is a leading and reputable full-service law firm dedicated to providing exceptional legal services to our clients.
- We foster a collaborative and inclusive work environment where every team member is valued and respected.
- We encourage open communication, teamwork, and professional growth.
- Our firm promotes a healthy work-life balance and supports the well-being of our employees.
Equal Opportunity
- Woods Oviatt Gilman LLP is an Equal Opportunity Employer.
- We value an open mind, dedication to work, and a collaborative spirit.
- We hire based on these qualities, a job’s requirements, our business needs, and an applicant’s qualifications.
- We do not tolerate discrimination or harassment of any kind—in the hiring process or in the workplace.
- We comply with the ADA and consider reasonable accommodation measures that may be necessary for eligible applicants/employees to perform essential functions.
- We participate in E-Verify.
- We will provide the federal government with employees’ Form I-9 information to confirm authorization to work in the U.S.
- We will only use E-Verify once an employee has accepted a job offer and completed Form I-9.