Network Security Engineer

Woods Oviatt Gilman LLPRochester, NY
$100,000 - $120,000Hybrid

About The Position

The Network Security Engineer is a hands-on technical role responsible for implementing, configuring, and maintaining the firm's security controls across a hybrid environment, including FortiGate firewalls, endpoint protection, cloud email and Microsoft 365, Intune-managed devices, and a co-managed monitoring and detection service. The Engineer works under the direction of the Director of Information Technology, who sets security policy and priorities for the department, and provides the technical assessment, recommendations, and documentation that support those decisions. Because the firm safeguards confidential and privileged client information, this position calls for strong technical skill, sound judgment, discretion, and clear communication with both the IT team and firm personnel.

Requirements

  • Hands-on administration of FortiGate firewalls, including policy management, VPN, intrusion prevention, and content filtering
  • Endpoint detection and response administration, ideally CrowdStrike Falcon, and familiarity with Microsoft endpoint protection
  • Microsoft 365 security administration, including cloud email protection, mail flow and filtering, phishing defense, and email authentication using SPF, DKIM, and DMARC
  • Identity and access administration across Microsoft Entra ID and on-premises Active Directory in a hybrid configuration, including multifactor authentication and conditional access
  • Microsoft Intune administration, including device compliance and configuration, application deployment, and device encryption in a hybrid environment
  • Solid networking fundamentals, including TCP/IP, routing and switching, VLANs, DNS, DHCP, segmentation, and wireless security
  • Vulnerability management and patch management practice, including scanning, prioritization, and remediation tracking
  • Security monitoring and log analysis, and experience working with a managed detection and response or co-managed SOC provider
  • Working familiarity with a recognized security framework such as the NIST Cybersecurity Framework, CIS Controls, or ISO 27001, and experience implementing controls in support of one
  • Familiarity with privacy and data protection requirements, including state breach notification obligations and handling of regulated data
  • Ability to produce clear technical documentation, control evidence, risk write-ups, and status reporting for both technical and non-technical readers
  • Strong analytical and problem-solving skills, with sound technical judgment in assessing and prioritizing risk
  • Ability to manage assigned technical work independently while escalating decisions and exceptions appropriately
  • Clear verbal and written communication, including the ability to explain security risks and requirements to attorneys, staff, and IT colleagues
  • Ability to weigh security requirements against practical business needs and recommend workable options
  • Ability to influence behavior and support change constructively and without confrontation
  • Highly organized and detail-oriented, and able to manage concurrent projects alongside daily operational work
  • Discretion and sound judgment in handling confidential and privileged information
  • Commitment to continued technical development in a rapidly changing field
  • Bachelor of Science in Information Technology, Cybersecurity, Computer Science, or a related field, or equivalent practical experience
  • Five or more years of hands-on experience in network security, information security, or systems and network engineering with substantial security responsibility
  • Experience implementing security controls in support of a security framework, and exposure to policy, compliance, or audit support work

Nice To Haves

  • Prior experience in a law firm or other professional services environment, including familiarity with outside counsel guidelines and client security audits
  • Experience preparing responses to client security questionnaires and third-party risk assessments
  • Azure or other cloud security administration
  • PowerShell or comparable scripting for automation and reporting
  • Experience with data loss prevention, email encryption, or information rights management
  • Experience with security awareness platforms and phishing simulation tools
  • Familiarity with SD-WAN, zero trust, or secure access service edge architectures
  • Relevant certifications such as Fortinet NSE, CompTIA Security+, GIAC credentials, Microsoft SC-200 or SC-300, CISSP, or CISM

Responsibilities

  • Administer, tune, and monitor FortiGate firewalls, including security policies, VPN configuration, intrusion prevention, web and content filtering, and logging
  • Implement and maintain network segmentation, secure remote access, and wireless security across firm locations, in line with the department's standards
  • Maintain secure connectivity for remote and hybrid users, including VPN and conditional access
  • Conduct scheduled reviews of firewall rules and network configurations, recommend changes to the Director of Information Technology, and maintain accurate network security documentation
  • Administer the firm's endpoint protection platforms, including CrowdStrike and Microsoft endpoint protection, covering policy configuration, detection review, containment actions, and agent coverage
  • Configure and maintain device compliance, configuration, and application deployment through Microsoft Intune in a hybrid environment, including full-disk encryption and recovery key handling
  • Configure and maintain identity and access controls across Microsoft Entra ID and on-premises Active Directory, including multifactor authentication, conditional access, and privileged account settings, and perform periodic access reviews
  • Configure and maintain security settings for cloud email and collaboration, including mail flow and filtering rules, phishing and malware defenses, email authentication records, and Microsoft 365 security configuration
  • Perform vulnerability and patch management across servers, endpoints, and network devices, including scanning, prioritizing findings, tracking remediation, and reporting status to the Director of Information Technology
  • Serve as the day-to-day technical contact for the firm's managed monitoring service, triaging alerts, validating findings, and carrying issues through to resolution
  • Investigate security events and perform containment, eradication, and recovery steps in accordance with the firm's incident response procedures, escalating promptly to the Director of Information Technology
  • Contribute to the development, maintenance, and testing of the firm's incident response plan, including participation in tabletop exercises
  • Verify that backup, recovery, and business continuity controls are functioning and tested, and support the department's disaster recovery planning
  • Provide technical evaluation and recommendations to support the department's selection and adoption of a recognized security framework such as the NIST Cybersecurity Framework, CIS Controls, or ISO 27001
  • Implement and maintain the technical controls that support the framework, and assist in assessing and reporting the firm's posture against it
  • Assist the Director of Information Technology in drafting and maintaining information security policies, standards, and procedures, and implement the technical measures that carry them out
  • Maintain security documentation, control evidence, and a working risk log, and recommend remediation priorities to the Director of Information Technology
  • Support compliance with applicable privacy and data protection obligations, including the New York SHIELD Act and other state privacy requirements, and requirements applicable to regulated client data such as protected health information
  • Prepare technical responses and supporting documentation for client security requirements, including outside counsel guidelines, security questionnaires, and client and third-party audits, and complete remediation items assigned by the Director of Information Technology
  • Support obligations arising from clients in regulated industries, including financial services requirements such as NYDFS Part 500 as applied to the firm through client agreements
  • Perform technical security reviews of vendors, applications, and services under consideration, and provide findings and recommendations to the Director of Information Technology
  • Assist with independent assessments, including penetration testing and external audits, and complete assigned remediation work
  • Administer the firm's security awareness program, including training delivery, phishing simulations, and user communication developed with the Director of Information Technology
  • Partner with the IT team on secure configuration, change management, and project work, and provide technical guidance to service desk staff on security escalations
  • Report on control status, vulnerabilities, incidents, and open remediation items to the Director of Information Technology
  • Maintain current knowledge of emerging threats, vulnerabilities, and security technologies relevant to the legal industry, and share findings with the department

Benefits

  • health_insurance
  • dental_insurance
  • vision_insurance
  • life_insurance
  • disability_insurance
  • 401k
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service