Network Security Engineer
Listed on 2026-09-14
-
IT/Tech
Cybersecurity, Network Security, Systems Administrator
Job Title: Network Security Engineer
Department: Information Technology
Location: Rochester, NY
Classification: Exempt
Reports To: Director of Information Technology
Company Overview:
Woods Oviatt Gilman, LLP is a leading and reputable full‑service law firm dedicated to providing exceptional legal services to our clients. With a team of highly skilled and experienced attorneys, we strive to deliver comprehensive and effective solutions to meet the diverse needs of our clients. Our headquarters is in Rochester, NY with additional offices in Albany and Buffalo, NY.
We foster a collaborative and inclusive work environment where every team member is valued and respected. We encourage open communication, teamwork, and professional growth. Our firm promotes a healthy work‑life balance and supports the well‑being of our employees.
Position Summary:
The Network Security Engineer is a hands‑on technical role responsible for implementing, configuring, and maintaining the firm's security controls across a hybrid environment, including Forti Gate firewalls, endpoint protection, cloud email and Microsoft 365, Intune‑managed devices, and a co‑managed monitoring and detection service. The Engineer works under the direction of the Director of Information Technology, who sets security policy and priorities for the department, and provides the technical assessment, recommendations, and documentation that support those decisions.
Because the firm safeguards confidential and privileged client information, this position calls for strong technical skill, sound judgment, discretion, and clear communication with both the IT team and firm personnel.
Duties and Responsibilities:
Network and Perimeter Security
- Administer, tune, and monitor Forti Gate firewalls, including security policies, VPN configuration, intrusion prevention, web and content filtering, and logging
- Implement and maintain network segmentation, secure remote access, and wireless security across firm locations, in line with the department's standards
- Maintain secure connectivity for remote and hybrid users, including VPN and conditional access
- Conduct scheduled reviews of firewall rules and network configurations, recommend changes to the Director of Information Technology, and maintain accurate network security documentation
Endpoint, Identity, and Email Security
- Administer the firm's endpoint protection platforms, including Crowd Strike and Microsoft endpoint protection, covering policy configuration, detection review, containment actions, and agent coverage
- Configure and maintain device compliance, configuration, and application deployment through Microsoft Intune in a hybrid environment, including full‑disk encryption and recovery key handling
- Configure and maintain identity and access controls across Microsoft Entra on‑premises Active Directory, including multifactor authentication, conditional access, and privileged account settings, and perform periodic access reviews
- Configure and maintain security settings for cloud email and collaboration, including mail flow and filtering rules, phishing and malware defenses, email authentication records, and Microsoft 365 security configuration
- Perform vulnerability and patch management across servers, endpoints, and network devices, including scanning, prioritizing findings, tracking remediation, and reporting status to the Director of Information Technology
Monitoring, Detection, and Incident Response
- Serve as the day‑to‑day technical contact for the firm's managed monitoring service, triaging alerts, validating findings, and carrying issues through to resolution
- Investigate security events and perform containment, eradication, and recovery steps in accordance with the firm's incident response procedures, escalating…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).