Company Description
NORCOM provides 911 services and dispatch for the northeast part of King County in Bellevue, WA, serving over 700,000 community members, including 14 fire departments and 6 police departments. NORCOM's dispatchers handle a wide range of calls, from emergencies to non-emergencies, and play a crucial role in providing assistance and referring callers to resources.
NORCOM offers a positive, inclusive culture and the opportunity to support a team of dedicated professional who help save lives every day. If you're looking to make a difference and be part of a close-knit team, NORCOM may be the right fit for you.
Role Description
This is a full-time hybrid role for a Network Security Engineer at NORCOM 911 in Bellevue, WA. The Network Security Engineer will be responsible for network administration, network security, network engineering, cybersecurity, and information security tasks on a day-to-day basis.
Qualifications
Network Management:
· Monitor and maintain the Cisco switching environment, VLANs and Authentication, Authorization and Accounting (AAA) resources
· Manage multi-homed Internet connections with BGP routing
· Monitor, maintain and troubleshoot LAN-to-LAN IPSec tunnels to connected agencies
· Monitor, configure, and troubleshoot Cisco next-generation firewalls utilizing both command-line interfaces and Firepower Management Center
· Create and maintain up to date technical documentation to include network diagrams, inventories, and relevant information on connected agencies
· Create change management processes for any changes to network equipment and coordinate changes with staff and external agencies
· Manage support contracts on network hardware and plan for equipment replacement
· Manage network resources and connectivity of physical and virtual servers and workstations
· Manage connectivity to external providers such as ISPs, private fiber providers, and city infrastructure
· Ensure compliance with Criminal Justice Information Systems (CJIS) policy
· Manage internal VoIP systems
· Monitor and maintain network connectivity to the Disaster Recovery Center and external resources
· Routinely back up device configurations and document all changes
· Implement new networks as designed by the Network Architect
Cybersecurity:
· Stay abreast of cybersecurity alerts and evaluate the network for any security issues
· Ensure the integrity and availability of system logs from all network hardware (routers, switches, firewalls)
· Respond to cybersecurity incidents and assist in digital forensics analysis
· Maintain current knowledge of standards and guidelines for resilient and secure networks, including NIST 800-53, FBI CJIS, and tools published by the Cybersecurity and Infrastructure Security Agency (CISA)
· Participate in meetings and events available through Multi-State Information Sharing and Analysis Center (MS-ISAC)
· Participate in the application of Security Awareness training to the organization
· Understand and apply published methodologies for network and security monitoring, such as the CIA Triad (Confidentiality, Integrity, and Availability) and the NIST Five-layer model
· Deploy critical patches while maintaining high availability
· Triage reported security incidents, escalating the incident when warranted
· Manage and update the agency’s Incident Response Plan
Cloud Computing:
· Maintain and Operate PaaS and SaaS cloud-based systems including Azure, Amazon AWS, and Google Cloud
· Manage and monitor private connections to cloud systems
REQUIRED EDUCATION AND EXPERIENCE:
· 7+ years overall experience in computer networking
· BS degree from an accredited college or university in Computer Engineering, Computer Science, or Information Technology
· Cisco Certified Network Professional (CCNP) or greater
· CompTIA Security Analyst (CySA+) or equivalent
· EC-Council Certified Ethical Hacker or greater desirable
· Experience implementing and maintaining high-availability systems in an organization classified as Critical Infrastructure
· Intimate knowledge of IPv4, Ipv6 and VLSM
· Experience implementing LAN-to-LAN and Remote Access VPNs
· Experience with Desktop and Server technologies, including Active Directory, Group Policy, Windows Server 2016-2022, Windows 10/11, Linux/Unix
· Experience with virtualization using VMWare, ESXi and vCenter
· First-hand experience investigating and recovering from a cybersecurity incident