Network Security Engineer
woods oviatt gilmanRochester, NY
$100,000-$130,000 annuallyAPPLY NOW
Network Security Engineer
woods oviatt gilmanRochester, NY
yesterday
Occupations
Information Security EngineersInformation Security AnalystsNetwork and Computer Systems Administrators$100,000-$130,000 annually
APPLY NOWAbout the role
Job Title: Network Security Engineer
Department: Information Technology
Location: Rochester, NYClassification: Exempt
Reports To: Director of Information Technology
Company Overview:
Woods Oviatt Gilman, LLP is a leading and reputable full-service law firm dedicated to providing exceptional legal services to our clients. With a team of highly skilled and experienced attorneys, we strive to deliver comprehensive and effective solutions to meet the diverse needs of our clients. Our headquarters is in Rochester, NY with additional offices in Albany and Buffalo, NY.We foster a collaborative and inclusive work environment where every team member is valued and respected. We encourage open communication, teamwork, and professional growth. Our firm promotes a healthy work-life balance and supports the well-being of our employees.
Position Summary:
The Network Security Engineer is a hands-on technical role responsible for implementing and maintaining the firm’s security controls across a hybrid Microsoft environment, including FortiGate firewalls, endpoint protection, Microsoft 365 and Intune, data protection, and a co-managed monitoring service. Working under the direction of the Director of Information Technology, who sets security policy and priorities, the Engineer provides the technical assessment, recommendations, and documentation behind those decisions, and exercises the judgment and discretion required to protect privileged client information.
Duties and Responsibilities:
- Administer and tune FortiGate firewalls, and maintain segmentation, remote access, and wireless security
- Administer CrowdStrike and Microsoft Defender, and manage device compliance and encryption in Intune
- Maintain identity and access controls in Entra ID and Active Directory, including MFA, conditional access, and privileged accounts
- Maintain cloud email security, including filtering rules, phishing defenses, and SPF, DKIM, and DMARC records
- Lead the firm’s data loss prevention and data classification program in Microsoft Purview, including sensitivity labels and policy tuning
- Support retention, eDiscovery, and information barrier requirements in coordination with firm counsel
- Assess AI platforms and cloud services before adoption, and implement the firm’s AI acceptable use controls
- Serve as daily technical contact for the firm’s managed monitoring service, triaging and validating alerts
- Investigate security events, perform containment and recovery, and contribute to incident response planning and tabletop exercises
- Perform vulnerability and patch management across servers, endpoints, and network devices
- Conduct vendor and application security reviews, and implement controls supporting NIST CSF, CIS Controls, or ISO 27001 Prepare technical responses for client security questionnaires, audits, and SHIELD Act obligations
- Administer security awareness and phishing simulation program
Technical Skills:
Required FortiGate firewall administration, including policy, VPN, and intrusion prevention Endpoint detection and response, ideally CrowdStrike Falcon, and Microsoft Defender Microsoft 365 security administration, email protection, and SPF, DKIM, and DMARCMicrosoft Entra ID, Active Directory, and Intune in a hybrid configuration Microsoft Purview sensitivity labels, data classification, and data loss prevention Networking fundamentals, vulnerability management, and security monitoring PreferredLaw firm or professional services experience, including client security auditsAI governance experience, including acceptable use controls or AI risk assessmentCISSP, CISM, or an equivalent industry-recognized certification Knowledge, Skills, and Abilities: Ability to assess and prioritize risk against practical business needs Ability to work independently while escalating decisions and exceptions appropriately Skill in explaining security risks clearly to attorneys, staff, and IT colleagues Discretion and sound judgment in handling confidential and privileged information
Education and Experience:
- Bachelor’s degree in Cybersecurity, Information Technology, or a related field, or equivalent
- Five or more years of hands-on network or information security experience
- Experience implementing controls in support of a security framework, with audit exposure
Physical Requirements:
Ability to work in server rooms and network closets, including bending, reaching, and lifting up to 50 pounds, and availability for occasional after-hours maintenance and incident response. Reasonable accommodations may be made for qualified individuals with disabilities.
Other Duties:
Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties, or responsibilities that are required of the employee for this job. This is a snapshot of the core functions and responsibilities. All inquiries will be handled with the utmost confidentiality. The compensation range for this position is $100,000-$130,000 annually, representing our good faith and reasonable estimate of the potential compensation at the time of posting. Actual compensation will be determined based on various factors, including the candidate’s qualifications, experience, skill set, and office location. Woods Oviatt Gilman LLP is an Equal Opportunity Employer. We value an open mind, dedication to work, and a collaborative spirit. We hire based on these qualities, a job’s requirements, our business needs, and an applicant’s qualifications. We do not tolerate discrimination or harassment of any kind—in the hiring process or in the workplace. We comply with the ADA and consider reasonable accommodation measures that may be necessary for eligible applicants/employees to perform essential functions. We participate in E-Verify. We will provide the federal government with employees’ Form I-9 information to confirm authorization to work in the U.S. We will only use E-Verify once an employee has accepted a job offer and completed Form I-9.
Matching similar jobs
JOB OVERVIEW
Salary
$100,000-$130,000 annually
Experience level
Lead
Location
Rochester, NY
Occupation
Information Security Engineers
Industry
Computer Systems Design Services
Posted
yesterday
Tired of running searches?
Rank the roles you'd take once, and matches like these arrive on their own.
CREATE PROFILE