Woods Oviatt Gilman LLP

Network Security Engineer

Woods Oviatt Gilman LLP Rochester, New York, United States · $100K–$120K/yr

Legal Services · 51-200 employees

4 h ago
security Senior (5-10 yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Network Security Engineer is responsible for implementing, configuring, and maintaining security controls across the firm's hybrid environment. This includes managing firewalls, endpoint protection, identity access, and ensuring compliance with security frameworks and privacy regulations.

What they look for

FortiGate Network Security Microsoft 365 Microsoft Intune CrowdStrike Identity and Access Management Vulnerability Management Incident Response Active Directory Firewall Administration TCP/IP Compliance Risk Assessment Security Frameworks Data Protection Technical Documentation

Requirements

Candidates must have at least five years of hands-on experience in network or information security and a bachelor's degree in a related field. Strong technical proficiency in FortiGate firewalls, Microsoft 365 security, and identity management systems is required.

Full description

Job Title: Network Security Engineer Department: Information Technology Location: Rochester, NY Classification: Exempt Reports To: Director of Information Technology

Company Overview:

Woods Oviatt Gilman, LLP is a leading and reputable full-service law firm dedicated to providing exceptional legal services to our clients. With a team of highly skilled and experienced attorneys, we strive to deliver comprehensive and effective solutions to meet the diverse needs of our clients. Our headquarters is in Rochester, NY with additional offices in Albany and Buffalo, NY.

We foster a collaborative and inclusive work environment where every team member is valued and respected. We encourage open communication, teamwork, and professional growth. Our firm promotes a healthy work-life balance and supports the well-being of our employees.

Position Summary:

The Network Security Engineer is a hands-on technical role responsible for implementing, configuring, and maintaining the firm's security controls across a hybrid environment, including FortiGate firewalls, endpoint protection, cloud email and Microsoft 365, Intune-managed devices, and a co-managed monitoring and detection service. The Engineer works under the direction of the Director of Information Technology, who sets security policy and priorities for the department, and provides the technical assessment, recommendations, and documentation that support those decisions. Because the firm safeguards confidential and privileged client information, this position calls for strong technical skill, sound judgment, discretion, and clear communication with both the IT team and firm personnel.

Duties and Responsibilities:

Network and Perimeter Security

  • Administer, tune, and monitor FortiGate firewalls, including security policies, VPN configuration, intrusion prevention, web and content filtering, and logging
  • Implement and maintain network segmentation, secure remote access, and wireless security across firm locations, in line with the department's standards
  • Maintain secure connectivity for remote and hybrid users, including VPN and conditional access
  • Conduct scheduled reviews of firewall rules and network configurations, recommend changes to the Director of Information Technology, and maintain accurate network security documentation

Endpoint, Identity, and Email Security

  • Administer the firm's endpoint protection platforms, including CrowdStrike and Microsoft endpoint protection, covering policy configuration, detection review, containment actions, and agent coverage
  • Configure and maintain device compliance, configuration, and application deployment through Microsoft Intune in a hybrid environment, including full-disk encryption and recovery key handling
  • Configure and maintain identity and access controls across Microsoft Entra ID and on-premises Active Directory, including multifactor authentication, conditional access, and privileged account settings, and perform periodic access reviews
  • Configure and maintain security settings for cloud email and collaboration, including mail flow and filtering rules, phishing and malware defenses, email authentication records, and Microsoft 365 security configuration
  • Perform vulnerability and patch management across servers, endpoints, and network devices, including scanning, prioritizing findings, tracking remediation, and reporting status to the Director of Information Technology

Monitoring, Detection, and Incident Response

  • Serve as the day-to-day technical contact for the firm's managed monitoring service, triaging alerts, validating findings, and carrying issues through to resolution
  • Investigate security events and perform containment, eradication, and recovery steps in accordance with the firm's incident response procedures, escalating promptly to the Director of Information Technology
  • Contribute to the development, maintenance, and testing of the firm's incident response plan, including participation in tabletop exercises
  • Verify that backup, recovery, and business continuity controls are functioning and tested, and support the department's disaster recovery planning

Security Program Support, Privacy, and Compliance

  • Provide technical evaluation and recommendations to support the department's selection and adoption of a recognized security framework such as the NIST Cybersecurity Framework, CIS Controls, or ISO 27001
  • Implement and maintain the technical controls that support the framework, and assist in assessing and reporting the firm's posture against it
  • Assist the Director of Information Technology in drafting and maintaining information security policies, standards, and procedures, and implement the technical measures that carry them out
  • Maintain security documentation, control evidence, and a working risk log, and recommend remediation priorities to the Director of Information Technology
  • Support compliance with applicable privacy and data protection obligations, including the New York SHIELD Act and other state privacy requirements, and requirements applicable to regulated client data such as protected health information
  • Prepare technical responses and supporting documentation for client security requirements, including outside counsel guidelines, security questionnaires, and client and third-party audits, and complete remediation items assigned by the Director of Information Technology
  • Support obligations arising from clients in regulated industries, including financial services requirements such as NYDFS Part 500 as applied to the firm through client agreements
  • Perform technical security reviews of vendors, applications, and services under consideration, and provide findings and recommendations to the Director of Information Technology
  • Assist with independent assessments, including penetration testing and external audits, and complete assigned remediation work

Awareness and Collaboration

  • Administer the firm's security awareness program, including training delivery, phishing simulations, and user communication developed with the Director of Information Technology
  • Partner with the IT team on secure configuration, change management, and project work, and provide technical guidance to service desk staff on security escalations
  • Report on control status, vulnerabilities, incidents, and open remediation items to the Director of Information Technology
  • Maintain current knowledge of emerging threats, vulnerabilities, and security technologies relevant to the legal industry, and share findings with the department

Technical Skills:

Required

  • Hands-on administration of FortiGate firewalls, including policy management, VPN, intrusion prevention, and content filtering
  • Endpoint detection and response administration, ideally CrowdStrike Falcon, and familiarity with Microsoft endpoint protection
  • Microsoft 365 security administration, including cloud email protection, mail flow and filtering, phishing defense, and email authentication using SPF, DKIM, and DMARC
  • Identity and access administration across Microsoft Entra ID and on-premises Active Directory in a hybrid configuration, including multifactor authentication and conditional access
  • Microsoft Intune administration, including device compliance and configuration, application deployment, and device encryption in a hybrid environment
  • Solid networking fundamentals, including TCP/IP, routing and switching, VLANs, DNS, DHCP, segmentation, and wireless security
  • Vulnerability management and patch management practice, including scanning, prioritization, and remediation tracking
  • Security monitoring and log analysis, and experience working with a managed detection and response or co-managed SOC provider
  • Working familiarity with a recognized security framework such as the NIST Cybersecurity Framework, CIS Controls, or ISO 27001, and experience implementing controls in support of one
  • Familiarity with privacy and data protection requirements, including state breach notification obligations and handling of regulated data
  • Ability to produce clear technical documentation, control evidence, risk write-ups, and status reporting for both technical and non-technical readers

Preferred

  • Prior experience in a law firm or other professional services environment, including familiarity with outside counsel guidelines and client security audits
  • Experience preparing responses to client security questionnaires and third-party risk assessments
  • Azure or other cloud security administration
  • PowerShell or comparable scripting for automation and reporting
  • Experience with data loss prevention, email encryption, or information rights management
  • Experience with security awareness platforms and phishing simulation tools
  • Familiarity with SD-WAN, zero trust, or secure access service edge architectures
  • Relevant certifications such as Fortinet NSE, CompTIA Security+, GIAC credentials, Microsoft SC-200 or SC-300, CISSP, or CISM

Qualifications and Competencies:

  • Strong analytical and problem-solving skills, with sound technical judgment in assessing and prioritizing risk
  • Ability to manage assigned technical work independently while escalating decisions and exceptions appropriately
  • Clear verbal and written communication, including the ability to explain security risks and requirements to attorneys, staff, and IT colleagues
  • Ability to weigh security requirements against practical business needs and recommend workable options
  • Ability to influence behavior and support change constructively and without confrontation
  • Highly organized and detail-oriented, and able to manage concurrent projects alongside daily operational work
  • Discretion and sound judgment in handling confidential and privileged information
  • Commitment to continued technical development in a rapidly changing field

Education and Experience:

  • Bachelor of Science in Information Technology, Cybersecurity, Computer Science, or a related field, or equivalent practical experience
  • Five or more years of hands-on experience in network security, information security, or systems and network engineering with substantial security responsibility
  • Experience implementing security controls in support of a security framework, and exposure to policy, compliance, or audit support work

Physical Requirements:

The following are representative of the physical demands of this position. Reasonable accommodations may be made for qualified individuals with disabilities.

  • Ability to work in server rooms and network closets, including bending, reaching, and standing for extended periods
  • Ability to install and service rack-mounted network and server equipment
  • Ability to lift and move items weighing up to 50 pounds
  • Availability for occasional after-hours maintenance windows and response to security incidents outside normal business hours

Other Duties: Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties, or responsibilities that are required of the employee for this job. This is a snapshot of the core functions and responsibilities. All inquiries will be handled with the utmost confidentiality. The compensation range for this position is $100,000-$120,000 annually, representing our good faith and reasonable estimate of the potential compensation at the time of posting. Actual compensation will be determined based on various factors, including the candidate’s qualifications, experience, skill set, and office location.

Woods Oviatt Gilman LLP is an Equal Opportunity Employer. We value an open mind, dedication to work, and a collaborative spirit. We hire based on these qualities, a job’s requirements, our business needs, and an applicant’s qualifications. We do not tolerate discrimination or harassment of any kind—in the hiring process or in the workplace. We comply with the ADA and consider reasonable accommodation measures that may be necessary for eligible applicants/employees to perform essential functions. We participate in E-Verify. We will provide the federal government with employees’ Form I-9 information to confirm authorization to work in the U.S. We will only use E-Verify once an employee has accepted a job offer and completed Form I-9.

Similar roles