Network Security Operations Engineer

Koitecc Solutions

Boston, Northern (MA, KY)

Hybrid

USD 90,000 - 120,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

UMass Boston is seeking a Network Security Operations Engineer to lead network security incidents in the NSOC, manage firewall policies, and maintain secure segmentation, VPN, and NAC. The role includes after-hours on-call support, documentation, and cross-team collaboration with Infrastructure, Network Services, and ISO.

A BS in cybersecurity/IT plus 5 years' experience is required, with proficiency in SIEM, DNS security, and scripting.

Qualifications

  • Bachelor's degree in Cybersecurity/IT with 5+ years in network and security operations.
  • Experience administering enterprise firewall platforms in production.
  • Experience with network segmentation, VPN and NAC.
  • Experience using enterprise SIEM for monitoring and incident response.
  • Experience in enterprise incident response.
  • Ability to diagnose and resolve complex network security issues.
  • Experience centrally managing DNS, DHCP, and IPAM (DDI).
  • Experience implementing DNS security against DDoS, hijacking, and other DNS threats.
  • Hands-on with security and network technologies; knowledge of best practices.
  • Automation development using PowerShell or Python.

Responsibilities

  • Lead technical coordination of network security incidents at NSOC and coordinate response per incident plans.
  • Maintain secure firewall policies and configurations to protect resources.
  • Maintain security configuration of network segmentation, VPN, and NAC.
  • Analyze and coordinate response to security events from monitoring platforms.
  • Maintain operational docs for continuity, DR, audits, and knowledge transfer.
  • Ensure visibility across on-prem, cloud, and hybrid environments for security controls.
  • Utilize SIEM and other tools to monitor, analyze, and respond to threats.
  • Assess network security maturity; document risks and remediation priorities.
  • Lead incident response activities with ISSO.
  • Conduct post-incident reviews to close gaps and track actions.
  • Translate technical issues to leadership communications.
  • Develop and maintain network status dashboards and service bulletins.
  • Contribute to security risk assessments, audits and pen tests.
  • Coordinate vulnerability remediation with IT teams.
  • Support mail security operations and anti-phishing controls.
  • Evaluate emerging threats and translate into controls improvements.
  • Participate in on-call rotation for after-hours incidents and upgrades.
  • Train and mentor student staff.
  • Build partnerships across university to deliver secure services.
  • Identify opportunities to automate and reduce technical debt.

Skills

Five years experience
SIEM monitoring
Firewall administration
DNS security
Automation scripting

Education

Bachelor's degree in Cybersecurity/IT

Tools

Firewall platforms
VPN
NAC
SIEM platforms
DDI infrastructure

Job description

General Summary:

Reporting to the Chief Information Security Officer (CISO), the Network Security Operations Engineer (NSOE) is responsible for the operational management, security, reliability, and continuous improvement of the University's network security infrastructure. The position is responsible for the day-to-day operation of enterprise network security technologies, ensuring the confidentiality, integrity, availability, and resilience of university systems while partnering with Infrastructure, Network Services, and other IT teams. Primary responsibilities include ownership of enterprise firewall services, network security segmentation, VPN and Network Access Control (NAC) security services, security event monitoring within the Network and Security Operations Center (NSOC), and technical leadership for network security incident response in coordination with the Information Security Office and Network Services. The role requires after-hours support for critical security events.

Success in this role is measured by maintaining secure, resilient, and reliable network security services while continuously improving operational maturity, reducing organizational risk, and delivering exceptional service to the university community.

Examples of Duties:
  • Lead technical coordination of network security incidents at the Network and Security Operations Center (NSOC), overseeing security event monitoring, investigation, and response in accordance with enterprise incident response protocols.
  • Maintain secure, resilient firewall policies and configurations that protect university resources while enabling business operations.
  • Maintain the security configuration and operational effectiveness of network segmentation, VPN, and Network Access Control (NAC) technologies in partnership with Network Services.
  • Analyze, investigate, and coordinate response to network security events and alerts generated through enterprise monitoring platforms.
  • Maintain accurate operational documentation supporting service continuity, disaster recovery, audits, and knowledge transfer.
  • Maintain operational visibility across on-premises, cloud, and hybrid environments to ensure consistent enforcement of network security controls.
  • Leverage automation, security monitoring platforms, and enterprise security tools, including SIEM, to proactively monitor, analyze, and respond to threats while enabling rapid containment of security incidents and vulnerabilities.
  • Maintain an ongoing assessment of network security maturity, documenting risks, technical debt, and recommending remediation priorities through annual gap assessments and the University's Plan of Action and Milestones (POAM).
  • Lead technical incident response activities in coordination with the Information Security Office.
  • Conduct post-incident reviews to identify gaps, refine security controls, minimize future risk, and track corrective actions through completion.
  • Partner with Network Services and ISO to translate complex technical issues into clear operational communications for leadership and campus stakeholders.
  • Develop and maintain network status dashboards, outage notifications, and service bulletins to keep the community informed of operational changes.
  • Participate in and contribute technical expertise to security risk assessments, audits, and penetration testing activities.
  • Lead the operational coordination of network security vulnerability remediation by identifying, prioritizing, tracking, and validating remediation activities in partnership with Desktop Services, Systems Administration, and Infrastructure teams.
  • Support mail security operations, including monitoring and tuning of email threat protection, anti-phishing, and anti-spoofing controls (SPF, DKIM, DMARC).
  • Evaluate emerging threats and translate threat intelligence into improvements to security controls and operational practices.
  • Participate in an on-call rotation and provide after-hours support for critical security incidents, network upgrades, and emergency response.
  • Train, mentor, and supervise student employees to support their professional development.
  • Build trusted partnerships across the university by delivering responsive, collaborative, and solutionsoriented security services.
  • Continuously improve network security operations by identifying opportunities to automate manual processes, reduce technical debt, enhance operational efficiency, and strengthen the University's overall security posture.
  • Perform other duties as assigned.
Qualifications:
Required Qualifications
  • Bachelor's degree (BS) in Cybersecurity, Information Technology, Networking, or a related field, plus five (5) years of cumulative hands-on experience in network and security operations
  • Operational experience administering enterprise firewall platforms and network security controls in a production environment.
  • Demonstrated competency in network segmentation, VPN, and Network Access Control (NAC) concepts and operations.
  • Demonstrated experience using enterprise SIEM platforms for monitoring, investigation, and incident response.
  • Demonstrated experience participating in technical incident response within enterprise environments.
  • Proven ability to diagnose and resolve complex network security issues in enterprise environments.
  • Proven experience centrally managing DNS, DHCP, and IPAM (DDI) infrastructure.
  • Demonstrated experience implementing DNS security solutions that protect against DDoS, hijacking, cache poisoning, and other DNS-based threats. Proven ability to maintain continuous protection during active attacks, deploy adaptive defense mechanisms, and utilize global visibility tools to monitor and analyze attack patterns across distributed networks.
  • Hands-on experience configuring, monitoring, and troubleshooting security and network technologies in production environments, and a working knowledge of industry-standard network and security platforms and their best practices for implementation.
  • Experience developing automation using scripting languages such as PowerShell or Python.
Preferred Qualifications
  • CISSP (Certified Information Systems Security Professional) or CISM (Certified Information Security Manager) certification.
  • Experience working with multiple stakeholders in a matrixed environment consisting of Systems, Network Operations, Information Security, internal business units, and external incident response teams.
  • Experience supporting organizations aligned with NIST Cybersecurity Framework, CIS Controls, PCI-DSS, FERPA, GLBA, or other regulatory or compliance frameworks.
  • Knowledge of security risks, copyright violations, and other inappropriate or unlawful computing practices.
  • Strong interpersonal skills that facilitate positive working relationships with both co-workers and end-users.
  • Strong oral and written communication skills for personal interaction with end-users, written reports, documentation, and call ticket tracking.
  • Desire and willingness to work with end-users and provide high-quality customer service to people at all levels in a university setting.
  • Higher education experience preferred.
  • Strong commitment to customer service.
For Professional Unit Positions:

Is this job required to be on call? Yes.

Supervision Received:

The Network Security Operations Engineer reports directly to the CISO.

Supervision Exercised:

Provides technical leadership for cross-functional projects and supervises approximately five student employees. Collaborates closely with Infrastructure, Network Services, and Information Security teams to successfully deliver operational and security initiatives.

Salary Ranges for the appropriate Pay Grade can be found at the following link:

Grade: 33

Salary Ranges

This is an exempt union position.

All official salary offers must be approved by Human Resources.

UMass Boston is committed to the full inclusion of all qualified individuals. As part of this commitment, we will ensure that persons with disabilities are provided reasonable accommodations for the hiring process. If reasonable accommodation is needed, please contact HR@umb.edu or 617-287-5150.

Applications close: 07 Sep 2026 Eastern Daylight Time

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Network Security Operations Engineer
Network Security Operations Engineer

UMass Boston • Boston (MA)

On-site
USD 110,000 - 150,000
Network Security Operations Engineer
Network Security Operations Engineer

University of Massachusetts Boston • Boston (MA)

On-site
USD 90,000 - 120,000
Cyber Network Security Operations Lead
Cyber Network Security Operations Lead

University of Massachusetts Boston • Boston (MA)

On-site
USD 90,000 - 120,000
Network Security Operations Lead
Network Security Operations Lead

Koitecc Solutions • Boston (MA), Northern (KY)

Hybrid
USD 90,000 - 120,000
Network Security Operations Engineer: Incident Response & SIEM
Network Security Operations Engineer: Incident Response & SIEM

UMass Boston • Boston (MA)

On-site
USD 110,000 - 150,000
Cybersecurity Operations Engineer
Cybersecurity Operations Engineer

Socket.dev • New Hampshire

On-site
USD 60,000 - 108,000
Network Engineer V
Network Engineer V

University of Maryland Medical System • Columbia (MD)

On-site
Senior Network Engineer
Senior Network Engineer

Princeton University • Princeton (NJ)

On-site
USD 115,000 - 130,000
Senior Systems Engineer
Senior Systems Engineer

UMass Boston • Massachusetts

On-site
USD 110,000 - 150,000
Senior Network Security Engineer
Senior Network Security Engineer

NMC2 • Dallas (TX)

On-site
USD 120,000 - 150,000