Overview
The Network Security Engineer within the University of California, San Francisco’s (UCSF) Information Technology (IT) department will ensure the security and integrity of UCSF’s network infrastructure. The Network Security Engineer supports the planning, design, optimization, implementation, audit, and troubleshooting of network security systems. The Engineer improves the overall security posture of UCSF and its assets. The Security Engineer will partner with other teams, including security operations, governance, and system administrators, to successfully design and deploy required solutions to harden UCSF platforms.
IT - Network Engineering
Full Time
The final salary and offer components are subject to additional approvals based on UC policy. Your placement within the salary range is dependent on a number of factors including your work experience and internal equity within this position classification at UCSF. For positions that are represented by a labor union, placement within the salary range will be guided by the rules in the collective bargaining agreement.
The salary range for this position is $136,000 - $204,000 (Annual Rate).
Responsibilities
- Configure / Install and manage various network security devices, features, and technologies, including, but not limited to Firewalls, DDI (DNS, DHCP and IP Address Management), VPN, Network Access Control solutions, Web Filtering solutions, CASB and SASE systems, Intrusion Detection / Prevention systems, Network Packet Brokers, and Network Traffic Visibility solutions
- Fulfill project requests and tasks for our clients (Firewall Policy, VPN tunnel creation, DDI, CASB Incident Response, applying web filter entries, etc.)
- Manage and mitigate vulnerabilities for the devices that are backed by the Network Security Team
- Resolve problems and break / fix incidents on the enterprise network and its network security systems
- Provide an administrative-level technical network security implementation skill set for the enterprise and Data Center environments of UCSF
- Assist in the development of network device hardening standards
- Apply professional communications concepts, industry practices, and relevant policies, procedures, and objectives to resolve highly complex issues
- Establish methods, techniques, and evaluation criteria to obtain results
- Interface with management, IT-Security, and vendors to develop and implement new solutions to meet business requirements
- Serve as an escalation point for junior staff
Qualifications
Bachelor’s Degree, or equivalent combination of experience / training in one or more of the following fields : computer science, engineering, computer information systems, etc.5-7 years of experience in network services, information technology, network security, or network operationsCisco Certified Network Professional (CCNP) and / or equivalent experience / trainingDemonstrated advanced knowledge of various network security devices, features, and technologies (firewalls, IDS / IPS, NAC, web filtering, CASB, VPN, DDI, etc.)Demonstrated advanced knowledge of VPN technologiesDemonstrated advanced knowledge of network security protocols, technologies, standards, and toolsDemonstrated advanced knowledge of various authentication protocols and servicesDemonstrated advanced understanding of modern enterprise TCP / IP networks (e.g., OSPF, STP, RSTP, 802.1Q, Multicast, QoS, tunneling)Demonstrated advanced knowledge of security architectures in private and public cloud environments. Experience designing and implementing network services within public cloud environments (e.g., AWS, Azure)Demonstrated advanced knowledge of Cisco Routing and Switching productsExperience with BGP, intrusion detection, proxies, firewalls, load balancing, packet capture, and data loss preventionAbility to learn effectively, meet deadlines, work independently and in a team, and participate in a 24 / 7 on-call rotationExcellent communication skills; ability to convey technical information to technical and non-technical personnel; ability to create presentation materials and lead stakeholder presentationsDemonstrated ability to gather, organize, and analyze data; strong problem-solving skills; experience with certificates and PKI (802.1X or SSL) and web proxy / content filtering for DLPFamiliarity with network security best practices and maintaining firewall rules, access controls, and IDS / IPSExcellent interpersonal skills across departmentsPreferred Qualifications
Demonstrated advanced knowledge of Juniper Routing and Switching productsExperience with network device management tools and products like SASE, CASE, and CASB solutionsExtensive knowledge of structured cabling systems, network facilities, electrical, UPS, etc.Experience performing packet and flow analysis with various toolsets; scripting in Python or Bash; using monitoring toolsPalo Alto Networks Certified Network Security Engineer and / or equivalentCISSPAWS Solutions Architect or AWS Cloud PractitionerLicense / Certification
CCNP or equivalent experience / trainingAbout UCSF
UCSF is a leading academic healthcare organization focused on patient care, education, research, and healthcare services. Infrastructure Services (IS) provides 24 / 7 support to the University community and strives for innovation and excellence in IT services.
Equal Employment Opportunity
The University of California is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, age, protected veteran status, or other protected status under state or federal law.
Organization
Health
Location : San Francisco, CA
#J-18808-Ljbffr