Network Perimeter Security & Compliance Engineer

Plano, United States

Bank of America

What would you like the power to do? At Bank of America, our purpose is to help make financial lives better through the power of every connection.

View all jobs at Bank of America

Apply now Apply later

Job Description:

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.

Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being a diverse and inclusive workplace, attracting and developing exceptional talent, supporting our teammates’ physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve.

At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!

Job Description:
This job is responsible for tool and service designs within a technical domain that enable business strategies in accordance with architectural governance, standards and policies. Key responsibilities include creating infrastructure tools and their integration as a service, facilitating deployment of technical solutions by developing templates, playbooks and automation used during implementation. Job expectations include looking for opportunities to improve efficiency when implementing and maintaining tools/services and embracing a culture of innovation and continuous improvement.

Responsibilities:

  • Provides subject matter expertise and consulting services on a range of technologies and assists Technical Analysts and Infrastructure Engineers to ensure that technology solutions comply with enterprise system design and engineering standards
  • Assists with translating business requirements into technical definitions, reference models, blueprints, and playbooks for deployment in compliance with architecture standards and policies
  • Assists in the evaluation of reference models, blueprints and playbooks to ensure they are fit for purpose
  • Develops software solutions to address manual and repeatable work or inefficient processes
  • Conducts on-site evaluations of third-party products being considered for firm adoption
  • Promotes an inclusive and healthy working environment and helps to resolve organizational impediments/blockers
  • Contributes to the creation/selection of functional and non-functional product evaluation requirements within and across domains

Position Overview:

The Network Services organization is seeking a talented Network Perimeter Security & Compliance Engineer to join the Cyber Security Product Governance and Compliance team. This role will support the Rule Review and Remediation program to ensure Firewall and Proxy rules and policies are in compliance with network security standards and design principles to mitigate information security risk and protect the firm. 

The Network Perimeter Security & Compliance Engineer will provide subject matter expertise to support the review and remediation of firewall and web proxy policies, rules, and configurations to ensure compliance with network and information security baselines and standards.  The Individual will analyze and understand a variety of existing and evolving business requirements, interface with technology engagement teams and provide best in class Firewall/IDS/Proxy solutions that align to meet business and technology requirements. 

Additional Responsibilities include:

  • Manage the rule review and remediation process to analyze and identify non-compliant firewall and proxy rules and policies within the Bank’s global perimeter and threat prevention infrastructure. 
  • Work with different application owners and LOBs (lines of business) to remediate rules and ensure adequate entitlements exist for compliance with information security standards and design principles.
  • Review complex firewall, IDS and proxy rules, policies and configuration and collaborate with multiple teams including Global Information Security, Perimeter Architecture and Engineering security, operations and change implementation to identify solutions to non-compliant rules and policies.
  • Track compliance status, report weekly and monthly metrics and interface with audit and risk teams in support of the program.

Required Qualifications:

  • At least 5+ years of experience directly managing or supporting networking or network security or cybersecurity solutions including Firewalls, Intrusion Detection/Prevention Systems, Web Content filtering or Web proxies.
  • Experience with firewall policy management and reporting solutions including FortiManager, FortiAnalyzer, Check Point Provider, Tufin, Splunk/SIEM, or similar tools.
  • Good understanding of networking and network security protocols including TCP/IP, UDP, HTTP, HTTPS, SSH, FTP, Socks, PAC files, DNS, NTP, ANYCAST services, and others.
  • Proven experience managing and researching complex firewall and/or proxy policies and rules, including access lists, NATs, object groups, policy layers, authentication.
  • Ability to manage and manipulate large data sets, databases, and reports with high attention to details and data accuracy.
  • Knowledge of authentication protocols such as LDAP, IWA, IWA-direct, SSO, Active Directory.
  • Strong analytical, troubleshooting, and problem-solving skills and ability to collaborate with other technical areas to define complex configuration designs.
  • Must be able to communicate at different organizational levels including senior management, lines of business and application teams in delivering Cybersecurity services and drive remediation of non-compliant policies.
  • Ability to lead small teams in the development and implementation of improved process and reporting capabilities.

Desired Qualifications:

  • B.S. degree in Computer Science, Engineering, or related field.
  • Experience with automation and scripting skills on Python or similar is a plus.
  • Knowledge of network connectivity, web connectivity and proxying technologies, WCCP, explicit or transparent proxy, reverse proxy, are a plus.
  • Experience with Jira for Non-Software Projects Team, issue tracking and project management application.
  • At least one professional level certification in Web Content filtering technologies, Network Security or Networks such as CCNA Security, CCNP, BCCPA, BCCPP, CISSP, CCSP, CEH, is desirable.

Skills:

  • Analytical Thinking
  • Application Development
  • Automation
  • Production Support
  • Risk Management
  • Adaptability
  • Business Acumen
  • DevOps Practices
  • Solution Delivery Process
  • Solution Design
  • Architecture
  • Collaboration
  • Innovative Thinking
  • Stakeholder Management
  • Technical Strategy Development

Shift:

1st shift (United States of America)

Hours Per Week: 

40
Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  1  0  0

Tags: Active Directory Automation CCNP CCSP CEH CISSP Compliance Computer Science DevOps DNS Firewalls Governance IDS Intrusion detection Jira LDAP Network security Python Risk management Scripting SIEM Splunk SSH SSO Strategy TCP/IP

Perks/benefits: Career development

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.