Network Security Operations Engineer

Apply now Job no: 530186
Work type: Staff Full Time
Campus: UMass Boston
Department: IT Comm & Infrastructure Serv
Pay Grade: 33
Categories: Information Technology, Professional Staff Union (PSU)

 

General Summary: 

Reporting to the Chief Information Security Officer (CISO), the Network Security Operations Engineer (NSOE) is responsible for the operational management, security, reliability, and continuous improvement of the University's network security infrastructure. The position is responsible for the day-to-day operation of enterprise network security technologies, ensuring the confidentiality, integrity, availability, and resilience of university systems while partnering with Infrastructure, Network Services, and other IT teams. Primary responsibilities include ownership of enterprise firewall services, network security segmentation, VPN and Network Access Control (NAC) security services, security event monitoring within the Network and Security Operations Center (NSOC), and technical leadership for network security incident response in coordination with the Information Security Office and Network Services. The role requires after-hours support for critical security events.

Success in this role is measured by maintaining secure, resilient, and reliable network security services while continuously improving operational maturity, reducing organizational risk, and delivering exceptional service to the university community.

 

 

Examples of Duties: 

• Lead technical coordination of network security incidents at the Network and Security Operations Center (NSOC), overseeing security event monitoring, investigation, and response in accordance with enterprise incident response protocols.

• Maintain secure, resilient firewall policies and configurations that protect university resources while enabling business operations.

• Maintain the security configuration and operational effectiveness of network segmentation, VPN, and Network Access Control (NAC) technologies in partnership with Network Services.

• Analyze, investigate, and coordinate response to network security events and alerts generated through enterprise monitoring platforms.

• Maintain accurate operational documentation supporting service continuity, disaster recovery, audits, and knowledge transfer.

• Maintain operational visibility across on-premises, cloud, and hybrid environments to ensure consistent enforcement of network security controls.

• Leverage automation, security monitoring platforms, and enterprise security tools, including SIEM, to proactively monitor, analyze, and respond to threats while enabling rapid containment of security incidents and vulnerabilities.

• Maintain an ongoing assessment of network security maturity, documenting risks, technical debt, and recommending remediation priorities through annual gap assessments and the University’s Plan of Action and Milestones (POAM).

• Lead technical incident response activities in coordination with the Information Security Office.

• Conduct post-incident reviews to identify gaps, refine security controls, minimize future risk, and track corrective actions through completion.

• Partner with Network Services and ISO to translate complex technical issues into clear operational communications for leadership and campus stakeholders.

• Develop and maintain network status dashboards, outage notifications, and service bulletins to keep the community informed of operational changes.

• Participate in and contribute technical expertise to security risk assessments, audits, and penetration testing activities.

• Lead the operational coordination of network security vulnerability remediation by identifying, prioritizing, tracking, and validating remediation activities in partnership with Desktop Services, Systems Administration, and Infrastructure teams.

• Support mail security operations, including monitoring and tuning of email threat protection, anti-phishing, and anti-spoofing controls (SPF, DKIM, DMARC).

• Evaluate emerging threats and translate threat intelligence into improvements to security controls and operational practices.

• Participate in an on-call rotation and provide after-hours support for critical security incidents, network upgrades, and emergency response.

• Train, mentor, and supervise student employees to support their professional development.

• Build trusted partnerships across the university by delivering responsive, collaborative, and solutionsoriented security services.

• Continuously improve network security operations by identifying opportunities to automate manual processes, reduce technical debt, enhance operational efficiency, and strengthen the University's overall security posture.

• Perform other duties as assigned.

 

 

Qualifications: 

Required Qualifications

• Bachelor's degree (BS) in Cybersecurity, Information Technology, Networking, or a related field, plus five (5) years of cumulative hands-on experience in network and security operations

• Operational experience administering enterprise firewall platforms and network security controls in a production environment.

• Demonstrated competency in network segmentation, VPN, and Network Access Control (NAC) concepts and operations.

• Demonstrated experience using enterprise SIEM platforms for monitoring, investigation, and incident response.

• Demonstrated experience participating in technical incident response within enterprise environments.

• Proven ability to diagnose and resolve complex network security issues in enterprise environments.

• Proven experience centrally managing DNS, DHCP, and IPAM (DDI) infrastructure.

• Demonstrated experience implementing DNS security solutions that protect against DDoS, hijacking, cache poisoning, and other DNS-based threats. Proven ability to maintain continuous protection during active attacks, deploy adaptive defense mechanisms, and utilize global visibility tools to monitor and analyze attack patterns across distributed networks.

• Hands-on experience configuring, monitoring, and troubleshooting security and network technologies in production environments, and a working knowledge of industry-standard network and security platforms and their best practices for implementation.

• Experience developing automation using scripting languages such as PowerShell or Python.

 

 

Preferred Qualifications

• CISSP (Certified Information Systems Security Professional) or CISM (Certified Information Security Manager) certification.

• Experience working with multiple stakeholders in a matrixed environment consisting of Systems, Network Operations, Information Security, internal business units, and external incident response teams.

• Experience supporting organizations aligned with NIST Cybersecurity Framework, CIS Controls, PCI-DSS, FERPA, GLBA, or other regulatory or compliance frameworks.

• Knowledge of security risks, copyright violations, and other inappropriate or unlawful computing practices.

• Strong interpersonal skills that facilitate positive working relationships with both co-workers and end-users.

• Strong oral and written communication skills for personal interaction with end-users, written reports, documentation, and call ticket tracking.

• Desire and willingness to work with end-users and provide high-quality customer service to people at all levels in a university setting.

• Higher education experience preferred.

• Strong commitment to customer service.

 

 

For Professional Unit Positions:

Is this job required to be on call? Yes.

 

 

Supervision Received:

The Network Security Operations Engineer reports directly to the CISO.

 

 

Supervision Exercised:

Provides technical leadership for cross-functional projects and supervises approximately five student employees. Collaborates closely with Infrastructure, Network Services, and Information Security teams to successfully deliver operational and security initiatives.

 

Application Instructions: 

Please apply online with your resume, cover letter and list of three professional references.

Review of candidates will begin following the application closing date. 

Only Internal candidates in the Professional Staff Bargaining Unit will be considered during the first 10 business days of the posting.  All other candidates will be considered after that period. 

Salary Ranges for the appropriate Pay Grade can be found at the following link: 

Grade: 33             

Salary Ranges

This is an exempt union position.

 

 

All official salary offers must be approved by Human Resources.

UMass Boston is committed to the full inclusion of all qualified individuals. As part of this commitment, we will ensure that persons with disabilities are provided reasonable accommodations for the hiring process. If reasonable accommodation is needed, please contact HR@umb.edu or 617-287-5150.

Advertised: Eastern Daylight Time
Applications close: Eastern Daylight Time

Back to search results Apply now Refer a friend

The University of Massachusetts President’s Office welcomes all qualified applicants and complies with all state and federal anti-discrimination laws.