Position Overview
This role is responsible for leading the design, administration, and continuous improvement of enterprise network security infrastructure. The position combines technical leadership, operational oversight, and strategic alignment with global security initiatives.
Key Responsibilities
Infrastructure Oversight
-
Lead the design, implementation, and administration of enterprise network security infrastructure.
-
Manage critical components including DNS, load balancers, firewalls, VPNs, proxies, remote access, and DMZ connectivity.
-
Support environments utilizing technologies from vendors such as Fortinet, Palo Alto Networks, and Cisco.
Technology Initiatives
-
Drive technology initiatives that enhance cybersecurity posture and optimize network performance.
-
Align infrastructure improvements with organizational and regulatory requirements.
Continuous Monitoring & Incident Response
-
Monitor network performance and security posture through dashboards and monitoring platforms.
-
Investigate and respond promptly to security events and performance issues.
-
Utilize security and monitoring tools including Splunk, Centreon, and Qualys.
Documentation Management
-
Maintain accurate and comprehensive technical documentation including:
-
Network diagrams
-
Security asset inventories
-
Procedures and operational runbooks
-
Vendor contacts
-
Cross-Department Collaboration
-
Partner with infrastructure and engineering teams to resolve network and security issues.
-
Ensure consistent and reliable service delivery across departments.
Audit & Security Coordination
-
Collaborate with audit and IT security teams across regional and global operations.
-
Provide documentation and implement remediation plans to address audit findings.
Staff Mentorship & Development
-
Mentor and train junior engineers.
-
Promote technical growth and knowledge sharing within the network security team.
Vulnerability & Patch Management
-
Conduct vulnerability assessments and coordinate remediation efforts.
-
Manage patching processes and track risk mitigation activities.
Security Reporting
-
Develop and deliver regular security and operational reports to leadership.
-
Provide insight into trends, risks, incidents, and key performance metrics.
LOD1 Security Management
-
Manage Line of Defense 1 (LOD1) network security controls in coordination with IT Risk.
Strategy Alignment
-
Ensure alignment with regional and global IT security strategies and policies.
Required Technical Skills
Networking & Security
-
Advanced knowledge of network technologies: L2, L3, VXLAN, BGP, LAN, WAN, VPN
-
Deep understanding of firewall, load balancing, proxy, and authentication technologies
-
Strong knowledge of DNS, DHCP, Web Security Gateways, and proxy client scripting
-
Layer 4 and Layer 7 protocol analysis and troubleshooting
-
Zero Trust Architecture and Network Access Control design
Infrastructure & Platforms
-
Network design, configuration, and automation using Arista Networks and Cisco technologies (preferred)
-
Microsegmentation platforms such as Illumio or VMware NSX (preferred)
Automation & Scripting
-
Proficiency in Python, PowerShell, or Ansible
-
Infrastructure automation and configuration management experience preferred
Troubleshooting & Operations
-
Ability to diagnose and resolve complex network and security issues independently
-
Strong documentation and communication skills
-
Ability to explain complex technical concepts to non-technical stakeholders
Professional Competencies
-
Highly organized and results-oriented
-
Able to manage multiple priorities in a dynamic environment
-
Self-starter with minimal supervision
-
Strong ownership and accountability
-
Effective project reporting and status communication
-
Demonstrated leadership and collaboration skills
Education & Experience
-
Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field (Master’s preferred)
-
8 years of hands-on experience in network security management (financial services experience preferred)
-
Extensive experience managing enterprise firewalls and DMZ environments
Certifications (Preferred / Desired)
-
Fortinet NSE 4 or 5
-
Palo Alto Networks Certified Network Security Engineer (PCNSE)
-
Cisco CCNP Enterprise or CCNP Security
-
CISSP or CISM (highly desirable)
Additional Requirements
-
Strong project management and leadership experience
-
Excellent communication and problem-solving abilities
-
Collaborative mindset with focus on teamwork and operational excellence
Work Schedule Requirement
All employees are required to work in the office at least two (2) Mondays and two (2) Fridays per month.
Nesco Resource offers a comprehensive benefits package for our associates, which includes a MEC (Minimum Essential Coverage) plan that encompasses Medical, Vision, Dental, 401K, and EAP (Employee Assistance Program) services.
Nesco Resource provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws.