Cybersecurity Network Engineer

Seminole Hard Rock Support Services

Town of Florida (NY)

On-site

USD 120,000 - 160,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Seminole Hard Rock Support Services is seeking a Network Cybersecurity Engineer to implement and optimize network security controls across on‑premises and cloud environments, including Azure, AWS, and Google Cloud. You will deploy zero-trust segmentation, build automation, and instrument telemetry to enable rapid threat detection and response.

This hands-on role bridges network engineering, cloud operations, and cybersecurity, reporting to the Manager of Cybersecurity Engineering.

Qualifications

  • 5–7+ years of combined experience in network engineering, network security engineering, or cloud networking, with at least 4+ years focused on hands-on network security engineering in enterprise environments.
  • Deep network engineering fundamentals: TCP/IP, BGP/OSPF, DNS, DHCP, TLS/PKI, NAT, IPv6, packet analysis.

Responsibilities

  • Deploy, configure, and tune secure-access service edge controls — secure web gateway, cloud firewall, CASB, and DLP policy.
  • Operate zero-trust network access for workforce and third parties with least-privilege access.
  • Harden DNS, certificate, and TLS posture at the edge with PKI teams.
  • Design and enforce microsegmentation and network policy for sensitive zones.
  • Develop and maintain production-grade scripts and tooling that automate network controls.

Skills

Network security engineering
Zero trust
Cloud networking
SASE / SSE platforms
Automation
Python
PowerShell
Go

Tools

Python
PowerShell
Go

Job description

Our team members are the key to our company’s success, and their health and well-being, as well as that of their families, is very important to us. We offer a comprehensive benefits package that allows our team members stay healthy, plan for their future and maintain a healthy work-life balance. Benefits may vary with employment status. To see our fill list of Team Member Benefits please visit our career site: www.gotoworkhappy.com/benefits

Overview
Job Description

At Seminole Hard Rock Support Services, we are on a mission to protect our guests, team members, and enterprise assets through world-class cybersecurity practices. As the Network Cybersecurity Engineer, you will implement, operate, and continuously improve the network security controls that defend traffic in, out, and across the enterprise — from the campus and data center edge to SASE, cloud networks, and the applications they carry — turning architecture and policy into running, automated, measurable defenses.

Reporting to the Manager of Cybersecurity Engineering, this role requires a hands-on, security-minded engineer who bridges the worlds of network engineering, cloud operations, and cybersecurity. You will configure and tune the enterprise network security stack — secure access service edge, perimeter and edge defenses, network detection and response, and zero-trust segmentation — and build the integrations and automations that connect it together across on-premises environments and Microsoft Azure (primary), Amazon Web Services, and Google Cloud.

This is a builder’s role, not an architecture role. You do not define standards from the sidelines; you take reference architectures and network security requirements and make them real: deploying and tuning controls, writing production-grade automation, and instrumenting the telemetry that turns raw network events into actionable insight. Your networking depth lets you treat traffic as evidence, and your fluency with AI and large language models lets you accelerate detection, triage, and analysis of network data far beyond manual effort.

You will work across campus, data center, edge, remote access, and cloud network domains, partnering with architecture, IAM, infrastructure, application, and SOC teams to ensure network controls are deployed consistently, operate reliably, and improve continuously across all Seminole Hard Rock business units. You measure your impact in risks reduced, incidents prevented, and manual effort eliminated through automation.

Responsibilities
Secure Access & Edge
  • Deploy, configure, and tune secure-access service edge controls — secure web gateway, cloud firewall, CASB, and DLP policy — keeping coverage complete and policies current
  • Operate zero-trust network access for workforce and third parties, replacing legacy VPN patterns with identity-aware, least-privilege application access
  • Operate the enterprise browser to enforce least-privilege, isolated access to sensitive applications from managed and unmanaged endpoints via an enterprise browser platform
  • Tune SSL/TLS inspection, tenant restrictions, and egress policy to balance security, privacy, and application compatibility — including protocols sensitive to interception such as NTLM, Kerberos, and certificate-pinned traffic
  • Manage traffic steering, forwarding, and PAC configurations so users land on the right control path from any location worldwide
Perimeter, WAF & Application Edge
  • Manage edge and perimeter defenses: web application firewall rules, DDoS mitigation, bot management, CDN and DNS policy for internet-facing properties
  • Operate API security posture and runtime protection, discovering shadow APIs and closing authentication and data-exposure gaps
  • Administer next-generation firewall policy, NAT, and rule lifecycle across data center and property perimeters, driving rule hygiene and least-privilege access
  • Harden DNS, certificate, and TLS posture at the edge in partnership with the PKI and infrastructure teams
  • Coordinate perimeter changes with franchise, property, and vendor networks so remote sites integrate securely without breaking authentication or application flows
Network Detection, Response & Visibility
  • Deploy and tune network detection and response, triaging anomalous east-west and north-south activity and feeding high-fidelity findings to the SOC
  • Engineer network telemetry pipelines — flow data, DNS logs, proxy logs, firewall logs, packet metadata — that route, shape, and enrich data for cost-effective analysis
  • Develop and tune network-focused detections and SIEM content, mapping coverage to attacker techniques
  • Investigate network-layer incidents end-to-end — from packet capture and flow analysis to proxy and firewall log correlation — isolating root cause under time pressure
  • Maintain authoritative visibility of network assets and attack surface, continuously reconciling what is connected against what is inventoried
Segmentation, Zero Trust & Cloud Networking
  • Apply zero-trust segmentation and least-privilege access principles consistently across campus, data center, gaming, and hospitality network estates
  • Design and enforce microsegmentation and network policy for sensitive zones — payment, gaming, surveillance, and OT/IoT environments — in partnership with infrastructure and compliance teams
  • Implement cloud network security guardrails across Azure (primary), AWS, and Google Cloud: virtual network design, firewalling, private connectivity, and logging baselines (Azure Firewall, NSGs, Private Link)
  • Remediate cloud network misconfigurations and exposure paths surfaced by posture management, preventing drift over time
  • Integrate network security checks into infrastructure-as-code and deployment workflows so network changes are secure by default
Network Automation, AI & Detection Engineering
  • Build and maintain network security automations, integrations, and response playbooks across the stack using APIs and SOAR
  • Leverage AI/ML and large language models to analyze large volumes of network telemetry, accelerate alert triage and enrichment, surface anomalies, and automate reporting and documentation
  • Develop and maintain production-grade scripts, services, and tooling (e.g., Python, PowerShell, Go) that operationalize network controls and eliminate repetitive manual work
  • Automate firewall rule reviews, policy validation, and configuration compliance checks so drift is caught by pipelines, not people
  • Instrument metrics and dashboards that make network control coverage, detection efficacy, and remediation timeliness measurable
Collaboration & Continuous Improvement
  • Partner with Cybersecurity Architecture, IAM, infrastructure, application, and SOC/MSSP teams to deploy network controls consistently and resolve issues quickly
  • Support Cybersecurity Strategy & Governance, audit, and privacy programs by automating evidence collection and continuous control monitoring for network controls
  • Document standards, runbooks, integration designs, and operating procedures so network controls are repeatable and supportable
  • Research, prototype, and pilot emerging network security tools and AI-driven capabilities that improve detection, automation, and analyst efficiency
  • Participate in an on-call rotation and incident response for a 24/7 gaming and hospitality environment
Qualifications & Experience
  • 5–7+ years of combined experience in network engineering, network security engineering, or cloud networking, with at least 4+ years focused on hands-on network security engineering in enterprise environments
  • Deep network engineering expertise, with hands-on experience designing, operating, and troubleshooting enterprise networks: routing and switching, firewalls, proxies, VPN/ZTNA, load balancing, DNS, and TLS/PKI
  • Strong automation and software proficiency, with hands-on experience in Python, PowerShell, Go, or similar languages, and the ability to build custom network security tooling, integrations, and automation from scratch
  • Practical experience applying AI/ML or large language models to network data analysis, detection, triage, or automation
  • Strong working knowledge of SASE / SSE platforms (secure web gateway, ZTNA, CASB, DLP), WAF and DDoS mitigation, NDR, and API security
  • Hands-on experience securing cloud networks on Microsoft Azure (required), with working experience in AWS and/or Google Cloud: virtual network design, cloud firewalls, private connectivity, and network security posture management
  • Deep networking fundamentals: TCP/IP, BGP/OSPF, DNS, DHCP, TLS/PKI, NAT, IPv6, packet analysis, segmentation, and zero-trust access models
  • Experience integrating network security tools and data sources via API, with familiarity in SOAR playbook development and SIEM content engineering
  • Familiarity with regulatory and compliance frameworks relevant to gaming and hospitality (PCI-DSS, SOX, tribal gaming regulations, GLBA), preferred but not required
  • Relevant certifications preferred: Cisco CCNP Security, vendor certifications in next-generation firewall and SASE/SSE platforms, Microsoft AZ-700 or AZ-500, AWS Advanced Networking Specialty, GIAC (GCIA, GDSA, GCLD), or equivalent; CISSP a plus
Professional Skills
  • Translate network security requirements and architecture into deployed, automated controls that operate reliably and integrate cleanly into existing networks and workflows, without creating friction
  • Operate as a hands-on engineer who personally builds, configures, tests, and ships high-quality automation and integrations, measuring success in problems solved, not tickets closed
  • Troubleshoot methodically across physical, virtual, and cloud network layers — from packet captures to policy engines — isolating root cause under time pressure during incidents
  • Collaborate effectively across cross-functional teams: cybersecurity, network and infrastructure engineering, cloud, IAM, compliance, and the SOC
  • Communicate technical findings and recommendations clearly to both technical peers and non-technical stakeholders, including property and franchise contacts
  • Thrive in an Agile, fast-paced environment that values automation, rapid iteration, and measurable security outcomes over manual process
  • Demonstrate a builder’s mindset and a passion for using engineering and AI to make network security faster, more consistent, and more scalable
Cybersecurity Tool Ecosystem

This role operates across a broad network security and engineering toolstack. Candidates should demonstrate depth across multiple categories below:

Category

Capability Areas

SASE, SWG, ZTNA & CASB

Secure web gateway, cloud firewall, zero-trust network access, and CASB/DLP platforms

Edge, WAF & DDoS & DNS

Web application firewall, DDoS mitigation, bot management, CDN, and DNS security

API & Application-Layer Defense

API discovery, posture governance, and runtime protection platforms

NDR & Network Visibility

Network detection and response, flow and packet analysis, attack-surface visibility

Enterprise Browser & Remote Access

Enterprise browser, ZTNA, and secure remote-access platforms

Firewalls, Segmentation & Zero Trust

Next-generation firewalls, microsegmentation, zero-trust network access

Cloud Network Security

Azure Firewall, NSGs, Private Link, cloud network security posture management

PKI, Certificates & Secrets

PKI and certificate lifecycle management, secrets management, cloud key management

SIEM, SOAR, Telemetry & Automation

Enterprise SIEM, SOAR, telemetry pipeline, and vulnerability management platforms

Cybersecurity Strategy & Governance

GRC automation, privacy management, and compliance evidence platforms

Cloud Platforms

Microsoft Azure (primary), AWS, Google Cloud (IaaS, PaaS, serverless)

Languages & Scripting

Python, PowerShell, Go, Bash — custom tooling and automation

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Automation Engineer III
Cybersecurity Automation Engineer III

Seminole Hard Rock Support Services • Town of Florida (NY)

On-site
USD 120,000 - 150,000
Benefits package
Network Security Engineer
Network Security Engineer

Jobtailor • New Jersey

On-site
USD 110,000 - 140,000
Network Security Engineer
Network Security Engineer

Liquid-Env-Solutions-of-Texa • Irving (TX)

On-site
USD 95,000 - 150,000
DevSecOps Architect
DevSecOps Architect

Seminole Hard Rock Support Services • Town of Florida (NY)

On-site
USD 140,000 - 200,000
Benefits package
Career site benefits
Network Security Engineer
Network Security Engineer

Jobtailor • Sunnyvale (CA)

On-site
USD 155,000 - 190,000
Senior Manager – IT Security
Senior Manager – IT Security

Jobtailor • United States

On-site
USD 160,000 - 200,000
Network and Cybersecurity Systems Engineer
Network and Cybersecurity Systems Engineer

Jobtailor • Waltham (MA)

On-site
USD 130,000 - 190,000
Senior Network Security Engineer
Senior Network Security Engineer

Jobtailor • Menomonee Falls (WI)

On-site
USD 120,000 - 170,000
Security Engineer
Security Engineer

Jobtailor • Arizona

On-site
USD 85,000 - 130,000
Network & Security Engineer
Network & Security Engineer

Ren • Indianapolis (IN)

On-site
USD 90,000 - 130,000