Senior Information Technology Engineer, IT Security (IT/OT Firewall Administration)

East Bay Municipal Utility DistrictOakland, CA
Hybrid

About The Position

The East Bay Municipal Utility District’s (EBMUD) Information Systems Department is currently seeking a Senior Information Technology Engineer with deep experience administering firewalls in mission-critical, highly available enterprise environments. The role focuses on securing both internal and perimeter networks, supporting business continuity and strengthening cyber resilience across business networks (IT) and operational technology networks (OT) and the implementation and oversight of cybersecurity policies, standards, and best practices. Applicants must reside within commuting distance of EBMUD’s Oakland, CA Administration building. This is a hybrid position which requires office presence in accordance with EBMUD’s telecommuting guidelines (minimum 2-day per week physical office presence currently required but is subject to change). Telecommuting policies are subject to change. EBMUD will not provide relocation assistance. We are seeking candidates with advanced IT/OT security experience and skills.

Requirements

  • At least five years of hands-on experience administering firewalls in enterprise-scale, high-availability production environments, including policy management, troubleshooting, and rule lifecycle maintenance.
  • Experience with enterprise-grade firewalls: e.g. Palo Alto Networks, Cisco, FortiNet, Checkpoint.
  • Expertise in troubleshooting network issues.
  • Solid understanding of TCP/IP protocols.
  • Experience configuring, supporting and managing routing- BGP, OSPF, EIGRP, static.
  • Experience with analyzing firewall logs and packet captures.
  • Experience managing virtual firewalls in AWS, Azure and/or GCP.
  • Understanding of IAAS concepts.
  • Experience implementing and supporting ssl-inspection in a production environment.
  • Experience managing VPN’s: IPSEC site to site and end user remote access.
  • Ability to communicate complex topics to non-technical users.
  • Ability and willingness to share knowledge and information with others.
  • Ability to create documentation detailing implementation steps, tracking changes.
  • Ability to work across teams to investigate and respond to incidents.
  • Ability to lead or participate in IT/OT security projects by creating project plans and technical requirements.
  • Ability to track and report on incident handling and response metrics.
  • Ability to participate in annual tabletop cyber incident response exercises.
  • Ability to establish and maintain positive working relationships; teamwork attitude.
  • Ability to balance project deliverables among day-to-day operational demands.
  • Ability to perform independent research and share knowledge effectively.
  • Ability to maintain calm and focus during emergency operations.
  • Ability to work in a hybrid work environment.
  • Strong working knowledge of firewall administration in a highly available production environment.
  • Networking experience.
  • Threat intelligence.
  • Experience in critical infrastructure-including ICS/OT firewall management.
  • Project management principles and practices.
  • Cybersecurity best practices.
  • Experience managing firewall changes including: NAT, routing, VPN, access policies, troubleshooting, deployment, upgrades.
  • Experience reviewing, analyzing and responding to firewall alerts: security and operational.
  • Ability to perform and analyze network captures utilizing Wireshark.
  • Experience working within a ticketing system to track requests, changes, approvals.
  • Experience participating in Blue/Red team exercises.
  • Log and systems analysis, troubleshooting, documentation techniques and procedures.
  • Change control concepts and procedures supporting a production environment.
  • Knowledge of network based attack methods and defense: DDOS, C2, data exfiltration, brute-force attacks, OWASP, etc.
  • Familiarity with Industrial Control Systems (ICS) and Operational Technology (OT) environments.
  • Project management.
  • A bachelor’s degree; and
  • Two years of experience in information technology engineering, one year of which was at a level comparable to or higher than the EBMUD class of Information Technology (IT) Engineer II.
  • Willingness to participate in a rotating on-call schedule to support 24/7 network security operations, including incident response and critical issue resolution.
  • Overtime will be required on an as needed basis.

Nice To Haves

  • Experience with automating firewall rule analysis or change workflows using scripts or APIs is a plus.
  • Familiarity with Industrial Control Systems (ICS) and Operational Technology (OT) environments is a plus.

Responsibilities

  • Administering firewalls in enterprise-scale, high-availability production environments, including policy management, troubleshooting, and rule lifecycle maintenance.
  • Configuring, supporting and managing routing (BGP, OSPF, EIGRP, static).
  • Analyzing firewall logs and packet captures.
  • Managing virtual firewalls in AWS, Azure and/or GCP.
  • Implementing and supporting SSL-inspection in a production environment.
  • Managing VPNs (IPSEC site to site and end user remote access).
  • Working with firewall policies, implementing changes, testing changes, submitting changes through change control processes.
  • Automating firewall rule analysis or change workflows using scripts or APIs.
  • Create and maintain network diagrams and documentation for new and existing firewall deployments- depicting logical and physical environments.
  • Communicate complex topics to non-technical users.
  • Create documentation detailing implementation steps, tracking changes.
  • Work across teams to investigate and respond to incidents.
  • Lead or participate in IT/OT security projects by creating project plans and technical requirements.
  • Track and report on incident handling and response metrics.
  • Participate in annual tabletop cyber incident response exercises.
  • Establish and maintain positive working relationships; teamwork attitude.
  • Balance project deliverables among day-to-day operational demands.
  • Perform independent research and share knowledge effectively.
  • Maintain calm and focus during emergency operations.
  • Work in a hybrid work environment.
  • Managing firewall changes including: NAT, routing, VPN, access policies, troubleshooting, deployment, upgrades.
  • Reviewing, analyzing and responding to firewall alerts: security and operational.
  • Performing and analyzing network captures utilizing Wireshark.
  • Working within a ticketing system to track requests, changes, approvals.
  • Participating in Blue/Red team exercises.
  • Log and systems analysis, troubleshooting, documentation techniques and procedures.
  • Supporting change control concepts and procedures for a production environment.
  • Participate in a rotating on-call schedule to support 24/7 network security operations, including incident response and critical issue resolution.
  • Perform overtime as needed.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service