Network Security Engineer

7 days ago


San Francisco, California, United States University of California - San Francisco Full time

The Network Security Engineer within the University of California, San Francisco's (UCSF) Information Technology (IT) department will ensure the security and integrity of UCSF's network infrastructure. The Network Security Engineer supports the planning, design, optimization, implementation, audit, and troubleshooting of network security systems. The Engineer improves the overall security posture of UCSF and its assets. The Security Engineer will partner with other teams, including security operations, governance, and system administrators, to successfully design and deploy required solutions to harden UCSF platforms.

The Network Security Engineer will

  • Configure/Install and manage various network security devices, features, and technologies including, but not limited to Firewalls, DDI (DNS, DHCP and IP Address Management), VPN, Network Access Control solutions, Web Filtering solutions, CASB and SASE systems, Intrusion Detection/Prevention systems, Network Packet Brokers, and Network Traffic Visibility solutions
  • Fulfill project requests and tasks for our clients (Firewall Policy, VPN tunnel creation, DDI, CASB Incident Response, applying web filter entries, etc.)
  • Manage and mitigate vulnerabilities for the devices that are backed by the Network Security Team
  • Resolve problems and break/fix incidents on the enterprise network and its network security systems.
  • Provide administrative-level technical network security implementation skill set for enterprise and Data Center environments of UCSF
  • Assist in the development of network device hardening standards
  • Apply professional communications concepts, industry practices, and relevant policies, procedures, and objectives to resolve highly complex issues.
  • Establish methods, techniques and evaluation criteria to obtain results.
  • Interface with management, IT-Security and vendors to develop and implement new solutions to meet business requirements
  • Serve as an escalation point for junior staff

The final salary and offer components are subject to additional approvals based on UC policy.

Your placement within the salary range is dependent on a number of factors including your work experience and internal equity within this position classification at UCSF. For positions that are represented by a labor union, placement within the salary range will be guided by the rules in the collective bargaining agreement.

The salary range for this position is $113,800 - $242,800 (Annual Rate).

To learn more about the benefits of working at UCSF, including total compensation, please visit:

Department Description

This position works in the Information Technology Department of UCSF. Supporting UCSF's complex business and mission needs requires a broad set of skills and services that UCSF IT provides for the campus community.

Required Qualifications

  • Bachelor's Degree, or equivalent combination of experience/training in one or more of the following fields: computer science, engineering, computer information systems, etc.
  • 5-7 years of experience working in one or more of the following fields: network services, information technology, network security, or network operations.
  • Cisco Certified Network Professional (CCNP) and/or equivalent experience/training
  • Demonstrated advanced knowledge of various network security devices, features, and technologies like firewalls, intrusion detection and prevention systems, network access control solutions, web filtering solutions, network packet brokers, load balancing, DDI (DNS, DHCP, and IP Address management), VPN, and network traffic visibility solutions.
  • Demonstrated advanced knowledge of various VPN technologies.
  • Demonstrated advanced knowledge of network security protocols, technologies, standards, and tools.
  • Demonstrated advanced knowledge of various authentication protocols and services.
  • Demonstrated advanced understanding of modern enterprise TCP/IP data networks using standards and technologies including but not limited to: OSPF, STP, RSTP, 802.1Q, Multicast, Quality of Service and tunneling protocols.
  • Demonstrated advanced knowledge of security architectures in private and public cloud environments. Experience designing and implementing network services within public cloud environments (e.g., AWS, Azure).
  • Demonstrated advanced knowledge, skills, and experience with Cisco Routing and Switching products.
  • Experience with Border Gateway Protocol (BGP), intrusion detection, proxies, firewalls, load balancing, packet capture, and/or data loss prevention.
  • Understands implications of work on other areas of IT and business.
  • Proven ability to learn effectively and meet deadlines. Self-motivated and works independently and as part of a team with minimal supervision. Participates in network on-call rotation supporting a 24/7 environment.
  • Excellent communication skills with the ability to convey technical information to both technical and non-technical personnel. Ability to support the creation of presentation materials, generate reports, and lead presentations to stakeholders.
  • Demonstrated advanced ability to gather, organize, and analyze data in the completion of a variety of functional assignments.
  • Demonstrated advanced problem-solving skills. Ability to diagnose and resolve network connectivity issues, in a timely manner. Experience troubleshooting and deploying solutions involving certificates and public key infrastructures (802.1X or SSL decryption and offloading), and designing and deploying web proxy and content filtering solutions for data loss prevention.
  • Familiarity with network security best practices and the ability to implement and maintain firewall rules, access controls, and intrusion detection/prevention systems.
  • Excellent interpersonal skills, with the ability to work effectively with colleagues and stakeholders across departments.

Preferred Qualifications

  • Demonstrated advanced knowledge, skills, and experience with Juniper Routing and Switching products.
  • Demonstrated advanced knowledge and experience with network device management tools, technologies, and products like SASE, CASE, and CASB solutions.
  • Extensive knowledge of structured cabling systems, network facilities, electrical, UPS, etc.
  • Experience performing packet and flow analysis with various toolsets, including in-line taps, firewall/IPS appliances, network routers, and hosts. Experience working with network access control platforms, writing shell scripts using Python or Bash, and using infrastructure monitoring tools.
  • Palo Alto Networks Certified Network Security Engineer and/or equivalent experience/training
  • Certified Information Systems Security Professional (CISSP)
  • AWS Solutions Architect or AWS Cloud Practitioner Certification

License/Certification

  • Cisco Certified Network Professional (CCNP) and/or equivalent experience/training

About UCSF

The University of California, San Francisco (UCSF) is a leading university dedicated to promoting health worldwide through advanced biomedical research, graduate-level education in the life sciences and health professions, and excellence in patient care. It is the only campus in the 10-campus UC system dedicated exclusively to the health sciences. We bring together the world's leading experts in nearly every area of health. We are home to five Nobel laureates who have advanced the understanding of cancer, neurodegenerative diseases, aging and stem cells.

Pride Values

UCSF is a diverse community made of people with many skills and talents. We seek candidates whose work experience or community service has prepared them to contribute to our commitment to professionalism, respect, integrity, diversity and excellence – also known as our PRIDE values.

In addition to our PRIDE values, UCSF is committed to equity – both in how we deliver care as well as our workforce. We are committed to building a broadly diverse community, nurturing a culture that is welcoming and supportive, and engaging diverse ideas for the provision of culturally competent education, discovery, and patient care. Additional information about UCSF is available at

Join us to find a rewarding career contributing to improving healthcare worldwide.

Equal Employment Opportunity

The University of California is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, age, protected veteran status, or other protected status under state or federal law.

Organization

Campus

Job Code and Payroll Title

004909 COMM AND NETWORK TCHL ANL 4 TX

Job Category

Clinical Systems / IT Professionals

Bargaining Unit

University Professional Technical Employees - Technical Unit (UPTE-TX)

Employee Class

Career

Percentage

100%

Location

San Francisco, CA

Campus

Mission Center Building (SF)

Work Style

Flexible

Shift

Days

Shift Length

8 Hours

Additional Shift Details

Mon-Fri, 9-5, as required after hours support



  • San Diego, California, United States Apple Full time

    The Applied Networking team builds core infrastructure for device-to-device communication on Apple devices, including both messaging and realtime communications. The team's frameworks are behind sharing, collaboration, messaging, and secure connectivity, providing API surfaces that power Apple products such as iMessage, FaceTime, HomeKit, SharePlay, Apple...

  • Network Engineer

    2 weeks ago


    San Jose, California, United States Altera Full time

    Job DetailsJob Description:We are seeking a skilled Network Engineer to design, build, deploy, and support our enterprise network infrastructure, including LAN, WAN, wireless, firewalls, and VPN systems This role supports branch operations, production data centers, cloud connectivity, and business-critical applications including telephony and video systems....


  • San Diego, California, United States Booz Allen Hamilton Full time

    Job Number: R0226898Network Engineer, LeadThe Opportunity:A well-designed network is critical to move data and enable global organizations and users to achieve their mission, but how can an organization make sure their network will fit their current and evolving needs? Crafting the right network with the right equipment and software requires a combination of...


  • San Francisco, California, United States Harmonic Security Full time

    About  Harmonic SecurityThe TechOps team builds the internal systems that keep Harmonic running smoothly as we scale. We create a self-service, automation-first environment where employees get what they need quickly - without relying on traditional ticket-based IT models. Our work blends operational support with engineering, enabling teams through reliable...


  • San Francisco, California, United States Brex Full time $240,000 - $300,000

    Why join usBrex is the AI-powered spend platform. We help companies spend with confidence with integrated corporate cards, banking, and global payments, plus intuitive software for travel and expenses. Tens of thousands of companies from startups to enterprises — including DoorDash, Flexport, and Compass — use Brex to proactively control spend, reduce...


  • San Francisco, California, United States Aircall Full time $215,000 - $265,000

    Aircall is a unicorn AI-powered customer communications platform used by 22,000+ companies worldwide to drive revenue, faster resolutions, and scale. We're redefining what a customer communications platform can be—by combining voice, SMS, WhatsApp, and AI into one seamless workspace.Our momentum comes from a simple but powerful idea: help every...


  • San Diego, California, United States GuidePoint Security Full time

    GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation's top organizations, such as Fortune 500 companies and U.S. government agencies,...


  • San Francisco, California, United States Sierra Full time

    About usAt Sierra, we're creating a platform to help businesses build better, more human customer experiences with AI. We are primarily an in-person company based in San Francisco, with growing offices in Atlanta, New York, London, and Singapore.We are guided by a set of values that are at the core of our actions and define our culture: Trust, Customer...


  • San Jose, California, United States Foxconn Industrial Internet - FII Full time $100,000 - $140,000

    JOB DESCRIPTIONDEPARTMENT: ITPOSITION: Network AdministratorLOCATION: San Jose, CACATEGORY: Exempt, Full Time, 100% On-site.Requires flexibility to work day and swing shifts based on operational needs.JOB FUNCTION: The Senior Network Engineer is a critical member of the IT team, responsible for the planning, design, optimization, and daily operational...


  • San Mateo, California, United States Roblox Full time

    Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators.At Roblox, we're building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to...