Personal Injury Law Firm
IT Security Systems Administrator
Location
United States
Posted
2 days ago
Salary
$115K - $135K / year
Seniority
Lead
Job Description
IT Security Systems Administrator
TopDog Law
• Administer Google Workspace and Microsoft 365 environments, while facilitating the setup and full migration to Microsoft 365. • Manage a mix of Windows and Mac endpoints using MDM tools for device enrollment, configuration, compliance, and patch management policies. • Administer SSO, MFA, and directory integrations; maintain identity provider configuration and authentication policy. • Administer and manage security toolsets (DLP, EDR, email security, and SIEM logs) to ensure effective threat detection and policy enforcement. • Provide tier 2/3 support for firm-wide SaaS applications as necessary. • Monitor, triage, and respond to security alerts across endpoint, email, identity, and cloud environments. • Support compliance activities and internal audits; maintain evidence and documentation for security controls. • Contribute to incident response: detection, containment, remediation, and post-incident review. • Assist with vulnerability management, including patch cadence tracking and endpoint hygiene reporting. • Identify gaps in security coverage or operational process and drive remediation. • Stay current on emerging threats, vulnerabilities, and best practices relevant to a remote-first professional services environment. • Develop dashboards & reports for security metrics, compliance status, and operational health. • Manage relationships with key vendors and service providers, ensuring service level agreements (SLAs) are met. • Oversee security operations and ensure compliance with relevant industry standards and internal policies. • Strategy and planning: Translate business needs into operational capability, capacity planning, DR/BCP design, cloud migration strategy, and lifecycle roadmaps.
Job Requirements
- Minimum of 7 years experience in IT systems administration, security, operations, or a combined role.
- Proven expertise in managing modern, complex IT environments.
- Enterprise level collaboration suite administration experience (Microsoft 365 and/or Google Workspace).
- Security fundamentals: Identity/access controls, patching, vulnerability management, and secure configuration practices.
- Disaster recovery & backups: Design and testable DR plans, RTO/RPO understanding, and backup validation.
- Working knowledge of EDR, email security (SPF/DKIM/DMARC, anti-phishing), DLP, or SIEM tooling in an operational capacity.
- Hands-on MDM/UEM experience across Mac and Windows (Jamf, Microsoft Intune, or equivalent); comfortable managing device compliance at scale.
- Demonstrated experience administering SSO, MFA, and an identity provider (Okta, Google Identity, Azure AD / Entra ID, or equivalent).
- Solid understanding of security fundamentals: identity lifecycle management, endpoint hygiene, phishing defense, zero-trust principles.
- Experience supporting a fully remote or distributed workforce.
- Excellent communication, leadership, and interpersonal skills.
- (Preferred) Experience in a law firm, legal technology, or professional services environment.
- (Preferred) Exposure to compliance frameworks (SOC 2, HIPAA, NIST CSF, or similar).
- (Preferred) Minimum of 1-3 years of experience in a leadership or management role, overseeing a team of IT professionals.
- (Preferred) Understanding of monitoring and logging tools (i.e. Nagios, Splunk, ELK stack).
- (Preferred) Scripting or automation experience (n8n, Python, Bash, Google Apps Script).
Benefits
- Medical, dental, and vision insurance
- 401(k) with company match
- HSA
- Life insurance
- Disability coverage
- Paid time off
- Parental leave
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Senior Product Security Engineer
NexthinkUnparalleled Visibility Into Issue Detection, Diagnosis, and Remediation
Base Salary Range: USD 140000 - USD 180000 - YEARLY Company Description Nexthink is the leader in digital employee experience management software. The company provides IT leaders with unprecedented insight allowing them to see, diagnose and fix issues at scale impacting employees anywhere, with any application or network, before employees notice the issue. As the first solution to allow IT to progress from reactive problem solving to proactive optimization, Nexthink enables its more than 1,200 customers to provide better digital experiences to more than 15 million employees. Dual headquartered in Lausanne, Switzerland and Boston, Massachusetts, Nexthink has 9 offices worldwide. Job Description As a scale-up experiencing rapid growth, we are looking for a highly experienced and driven Senior Product Security Engineer to join our Security team. This role is critical to the security, resilience, and operational excellence of our FedRAMP cloud environment and broader SaaS platform. We are seeking a senior security engineer who can take ownership of complex cloud security challenges, drive technical decisions, and help shape the future of our cloud security program. You will play a key role in designing, operating, hardening, and continuously improving a secure AWS-based environment, with a strong focus on FedRAMP requirements, automation, incident response, and scalable security architecture. This is an opportunity for someone who thrives in high-impact environments, enjoys tackling difficult technical problems, and wants to help build secure, resilient systems at scale. What you'll do - Serve as a core member of the Cloud Security team with significant influence on the direction, priorities, and execution of the cloud security program. - Own, operate, maintain, and improve our FedRAMP cloud environment, ensuring it meets high standards for security, availability, compliance, and operational excellence. - Design, implement, and maintain a secure, scalable, and resilient AWS cloud infrastructure, covering both the cloud platform and the applications running on it. - Build and improve security controls across cloud resources, including networking, compute, storage, logging, monitoring, and IAM. - Lead the hardening of AWS environments and Kubernetes-based platforms, applying security best practices and secure-by-default patterns. - Drive the automation of security controls, operational processes, and compliance requirements to reduce manual effort and human error. - Partner closely with SRE, platform, and engineering teams to ensure services are deployed and operated securely in highly regulated environments. - Develop, maintain, and continuously improve incident response capabilities for cloud environments, including detection, containment, investigation, recovery, and post-incident analysis. - Respond to security incidents, perform deep technical investigations, and drive remediation and long-term corrective actions. - Proactively identify and mitigate security risks through threat-informed assessments, vulnerability management, and continuous cloud security reviews, including the use of tools such as CNAPP. - Manage and improve security tooling and services such as SIEM, EDR, cloud-native security tooling, and monitoring platforms, while developing meaningful security and risk metrics. - Contribute to the development and execution of our cloud security strategy, balancing business needs, engineering velocity, and regulatory obligations. - Collaborate with engineering teams to understand system designs, guide secure architecture decisions, and help solve complex technical security problems. - Contribute to cloud security education and training for engineering teams, helping raise the overall security maturity of the organization. - Stay current on emerging cloud threats, AWS security capabilities, attacker techniques, and industry best practices, and translate that knowledge into practical improvements. Qualifications What you'll need - 7+ years of hands-on experience designing, building, securing, and operating cloud infrastructure on AWS, including deep practical knowledge of AWS security services, architecture patterns, and operational best practices. - Proven experience working in high-security and regulated cloud environments, with strong familiarity with FedRAMP and SOC 2 requirements. - Strong hands-on expertise with Kubernetes, container security, and modern infrastructure platforms. - Strong experience with infrastructure as code and automation tooling such as Terraform/OpenTofu, Terragrunt, Ansible, Crossplane, Jenkins, and GitHub Actions. - Demonstrated ability to design and implement scalable security automation and DevSecOps practices. - Strong experience in incident response, security monitoring, investigation, and remediation in cloud-native environments. - Deep understanding of IAM, least privilege, identity architecture, and access control best practices in AWS. - Strong knowledge of network security, including segmentation, firewalls, VPNs, intrusion detection, and secure connectivity patterns in cloud environments. - Experience managing and tuning security tools and platforms, including SIEM, EDR, vulnerability management, and cloud security posture tools. - Excellent troubleshooting, analytical, and problem-solving skills, with the ability to work through complex technical and operational challenges. - Ability to operate with a high degree of ownership, make sound technical decisions, and drive initiatives from design through implementation and continuous improvement. - Strong communication and collaboration skills, with the ability to clearly explain technical security concepts to both technical and non-technical stakeholders. - A proactive, hands-on mindset and a strong commitment to building secure, resilient, and maintainable systems. - Fluent in English, written and spoken. What will make you stand out - Experience securing and operating FedRAMP-authorized or similarly regulated SaaS environments. - Experience with additional cloud platforms such as Azure. - Proficiency in Python or Golang; JavaScript/TypeScript is a plus. - Knowledge of security standards and frameworks such as CIS Benchmarks, NIST, and ISO 27001. - Experience influencing security architecture across multiple engineering teams and driving adoption of security best practices at scale. Who you are - You are a senior-level engineer who enjoys taking on difficult technical problems and solving them pragmatically. - You are comfortable owning critical security infrastructure and making decisions in complex, fast-moving environments. - You combine strong technical depth with sound judgment and a practical approach to risk reduction. - You advocate for high security standards while enabling engineering teams to move effectively. - You are curious, adaptable, and motivated by continuous improvement. Additional Information We are the pioneers and trailblazers of a global IT Market Category (DEX) that is shaping the future of how the world works, giving our customers' IT Teams total digital visibility across their enterprise. Our innovative solutions integrate real-time analytics, automation, and employee feedback across all endpoints. This enables our IT teams to solve complex technical challenges, create ever more productive workplaces, and deliver happy, satisfied employees in the digital workplace. Total Rewards @ Nexthink At Nexthink, we offer one of the most comprehensive and generous benefits plans. Your total rewards compensation package includes base salary and may also include a commission or performance bonus plan. We provide our US employees with 100% covered company benefits that consist of health, dental, vision as well as access to life insurance, long-term disability, and accidental death/personal loss coverage. In addition, we offer: - Flexible Hours and unlimited vacation (employees have unlimited paid time off on top of the 15 days of holidays we offer), 11 company-paid holidays, and 3 extra days for volunteering. - Hybrid work model that balances office and remote work, with structured onboarding to foster connections and team integration. - Free access to professional training platforms to explore your interests and enhance your skills. - Up to 16 weeks of paid leave for birthing parents/primary caregivers, 6 weeks for secondary caregivers. - Plan for the future with a 401(k) plan featuring up to 4% company matching contributions, vesting immediately, to grow your retirement savings. - Bonuses for referring successful hires after three months of continuous employment. Base salary ranges are determined by country, role, level, experience, and skills. The range displayed on each job posting reflects Nexthink's good faith determination of the minimum and maximum targets for new hire salaries across all US locations. Individual pay is determined by related factors, including job skills, experience, and relevant education or training, which may impact a final offer. Your Talent Acquisition Partner can share more about the specific salary range during the hiring process.
Senior Associate - Senior GCP Security Engineer
New York LifeNew York Life is headquartered in New York, New York, and offers a portfolio of products for life insurance, long-term care insurance, retirement, investment an
Location Designation: Hybrid - 3 days per quarter Role Overview We are looking for a Senior GCP Security Engineer who lives on GCP and can own the security architecture end-to-end, not just advise on it. You will design guardrails, write Terraform, integrate with Harness CI/CD pipelines, and partner with engineering teams to ensure every resource deployed is secure by default. This role is GCP-first. Familiarity with AWS and Azure is a plus, but your day-to-day will be deep in Google Cloud: securing GKE workloads, governing AI pipelines on Vertex AI, managing identities via ICAM, and using native GCP security services to detect and respond to threats. What You'll Bring: - 5+ years of experience in cloud security, with the majority focused on GCP environments. - Deep hands-on experience with GCP security services including IAM, VPC Service Controls, Cloud Armor, KMS, Secret Manager, DLP, and SCC. - Strong Elastic SIEM experience including log ingestion, detection engineering, alert management, and threat correlation. - Production-level Terraform experience including module development, infrastructure automation, and state management. - Experience integrating security controls into CI/CD pipelines using Harness or equivalent platforms. - Strong knowledge of Kubernetes and GKE security including pod security admission, network policies, Workload Identity, and Binary Authorization. - Hands-on experience with ICAM or enterprise identity platforms governing non-human identities and workload access. - Practical knowledge of AI/ML security including Vertex AI workload protection, LLM API governance, and training data security. Preferred Qualifications - Google Professional Cloud Security Engineer or Professional Cloud Architect certification. - Experience with policy-as-code tooling such as OPA/Rego, Sentinel, or Checkov. - Familiarity with AWS security services including IAM, GuardDuty, SCPs, and multi-cloud security architectures. - Experience with Cribl Stream or similar log routing technologies integrated with Elasticsearch. - Understanding of compliance-driven security requirements including NY DFS 23 NYCRR 500, NAIC, NIST CSF, CIS Benchmarks, and ISO 27001. - Working knowledge of enterprise identity platforms including SailPoint, CyberArk, Ping Identity, Active Directory, and LDAP. - Experience securing AI agent frameworks such as LangChain or Vertex AI Agent Builder. Primary Technology Stack: - GCP: Vertex AI, GKE, Cloud Armor, KMS, SCC, DLP, Secret Manager, Certificate Manager, BigQuery, Cloud Run - Infrastructure as Code: Terraform (required), Harness CI/CD, ICAM - Identity: GCP Workload Identity Federation, service account governance, ICAM, SailPoint, CyberArk, Ping Identity, Active Directory, LDAP - AI/ML: Vertex AI Agent Builder, Gemini APIs, BigQuery ML, RAG pipelines - Secondary: AWS (IAM, GuardDuty, Bedrock), Azure (familiarity acceptable) - Observability: Elastic SIEM (primary), SCC, Cribl Stream, Elasticsearch Pay Transparency Salary Range: $124,000-$177,000 Overtime eligible: Exempt Discretionary bonus eligible: Yes Sales bonus eligible: No Actual base salary will be determined based on several factors but not limited to individual's experience, skills, qualifications, and job location. Additionally, employees are eligible for an annual discretionary bonus. In addition to base salary, employees may also be eligible to participate in an incentive program. Company Overview At New York Life, our 180-year legacy of purpose and integrity fuels our future. As we evolve into a more technology-, data-, and AI-enabled organization, we remain grounded in the values that drive lasting impact. Our diverse business portfolio creates opportunities to make a difference across industries and communities-inviting bold thinking, collaborative problem-solving, and purpose-driven innovation. Here, you'll find the rare balance of long-standing stability and forward momentum, supported by an inclusive team that honors tradition while embracing progress. As a Fortune 100 mutual company, we offer a place to grow your skills, contribute to meaningful work, and deliver solutions that matter. Your ideas drive what's next, and your growth powers it. Our Benefits We provide a full package of benefits for employees - and have unique offerings for a modern workforce, including leave programs, adoption assistance, and student loan repayment programs. Based on feedback from our employees, we continue to refine and add benefits to our offering, so that you can flourish both inside and outside of work.Click hereto discover more about our comprehensive benefit options or visit our NYL Benefits Site. Our Commitment to Inclusion At New York Life, fostering an inclusive workplace is fundamental to who we are and how we serve our communities. We have a longstanding commitment to creating an environment where individuals can contribute their best and succeed together. This foundation is rooted in our core values of humanity and integrity, ensuring that every employee feels valued and supported. By embracing a broad range of perspectives and experiences, we achieve greater success and fulfill our promise of providing financial security and peace of mind to families across all communities. Click here to learn more about New York Life's leadership in this space. Recognized as one of Fortune's World's Most Admired Companies, New York Life is committed to improving local communities through a culture of employee giving and volunteerism, supported by the Foundation. We're proud that due to our mutuality, we operate in the best interests of our policy owners. To learn more about career opportunities at New York Life, please visit the Careers page of www.NewYorkLife.com. Visit our LinkedIn to see how our employees and agents are leading the industry and impacting communities. Visit our Newsroom to learn more about how our company is constantly evolving to meet our clients' and employees' needs. Job Requisition ID: 94053 #BI-Hybrid
Network Security Engineer
CloudflareCloudflare, Inc. protects online applications without installing software, adding hardware, or changing lines of code. The company’s internet properties help
About Us At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world's largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine's Top Company Cultures list and ranked among the World's Most Innovative Companies by Fast Company. At Cloudflare, we're not looking for people who wait for a polished roadmap; we're looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a "normalized" problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you're the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you'll fit right in. Available Location: Singapore About the Team The Cloudflare Customer Support Team solves complicated problems and answers technical questions via phone, email, chat and social media. Whether it is a Wordpress blogger using our services for free or a global Enterprise business with petabytes of web traffic, we are always eager to assist. We are the eyes and ears of Cloudflare, acting as the real-time voice of the customer to help communicate their needs and real-world use cases back to the rest of the company - for better service and future product development. What You'll Do Do you love solving complex technical issues and interacting with people? Are you passionate about providing premium-level support to customers and are a standout colleague? Cloudflare is seeking an experienced Network Security Engineer to join our team and support our largest and most technically sophisticated customers in resolving technical problems, threats or attacks on their infrastructure at OSI Layers 3, 4, and 7. This will span the range of Cloudflare products from Magic Transit Infrastructure Protection, Argo Smart Routing, DDoS mitigation and Network Firewall, to using the Web Application firewall (WAF), Spectrum and Rate Limiting to help customers. - Serve as a trusted technical advisor for our enterprise customers, responding to and resolving inquiries and incidents related to network security and performance, while delivering timely, high-quality and personalized assistance. - Work directly with customers to diagnose, troubleshoot and resolve complex technical issues involving DDoS mitigation, firewall rules, SSL/TLS, network confirmation, and other security configurations. - Create and maintain knowledge base articles, technical guides, and troubleshooting documentation for internal and customer use. - Compare traffic signatures and attributes including IP addresses, cookie variations, HTTP headers, and JavaScript footprints to determine what is good traffic and what is malicious - DDoS mitigation for OSI layers 3,4, & 7: advise customers on how to filter malicious traffic using Cloudflare tools like Magic Transit, Network Firewall, WAF, IP reputation lists, packet inspection, blocklisting, allowlisting, and rate limiting - Work with Engineering and Product teams to improve products and tools - Utilize generative AI and automation tools to streamline log analysis, accelerate root-cause analysis during security incidents, and optimize customer response times. What We're Looking For - You have a minimum of 4 years experience working as a Network Security Engineer / Technical Support Engineer / Sr. Support Engineer supporting networking or web security products. - Exceptional troubleshooting and problem-solving skills, with the ability to simplify complex concepts for customers. - Strong customer service orientation and communication skills - Ability to work independently and collaboratively in a fast-paced, dynamic environment. - Strong understanding of network protocols, including TCP/IP, DNS, HTTP/S, and BGP, with a particular focus on anycast routing concepts and implementation, as well as tools such as iptables and looking glass. - Proven experience troubleshooting network connectivity issues, BGP routing, and GRE tunnels, and performing packet capture analysis - Confident with command line and tools, including curl, dig, traceroute, openssl, git - Experience in a web development and / or hosting environment such as installing and configuring web servers like Apache, Nginx, Caddy and IIS. - You are competent at writing scripts in Bash, Python, JavaScript or other scripting languages. - You have worked with PostgreSQL, MySQL, MS SQL, and other database servers. - Bachelor's degree in Computer Science, Cybersecurity, or a related field (or equivalent experience). - Relevant certifications such as CISSP, GCIA GCIH, GCFA, GCFE or equivalent. What Makes Cloudflare Special? We're not just a highly ambitious, large-scale technology company. We're a highly ambitious, large-scale technology company with a soul. Fundamental to our mission to help build a better Internet is protecting the free and open Internet. Project Galileo: Since 2014, we've equipped more than 2,400 journalism and civil society organizations in 111 countries with powerful tools to defend themselves against attacks that would otherwise censor their work, technology already used by Cloudflare's enterprise customers--at no cost. Athenian Project: In 2017, we created the Athenian Project to ensure that state and local governments have the highest level of protection and reliability for free, so that their constituents have access to election information and voter registration. Since the project, we've provided services to more than 425 local government election websites in 33 states. 1.1.1.1: We released 1.1.1.1 to help fix the foundation of the Internet by building a faster, more secure and privacy-centric public DNS resolver. This is available publicly for everyone to use - it is the first consumer-focused service Cloudflare has ever released. Here's the deal - we don't store client IP addresses never, ever. We will continue to abide by our privacy commitment and ensure that no user data is sold to advertisers or used to target consumers. Sound like something you'd like to be a part of? We'd love to hear from you! Please note that applicants who progress to the offer stage of the interview process may be asked to attend an in-person interview within one of the Cloudflare Offices or Cloudflare Hubs. More details about this will be available at that stage of the interview process. This position may require access to information protected under U.S. export control laws, including the U.S. Export Administration Regulations. Please note that any offer of employment may be conditioned on your authorization to receive software or technology controlled under these U.S. export laws without sponsorship for an export license. Cloudflare is proud to be an equal opportunity employer. We are committed to providing equal employment opportunity for all people and place great value in both diversity and inclusiveness. All qualified applicants will be considered for employment without regard to their, or any other person's, perceived or actual race, color, religion, sex, gender, gender identity, gender expression, sexual orientation, national origin, ancestry, citizenship, age, physical or mental disability, medical condition, family care status, or any other basis protected by law. We are an AA/Veterans/Disabled Employer. Cloudflare provides reasonable accommodations to qualified individuals with disabilities. Please tell us if you require a reasonable accommodation to apply for a job. Examples of reasonable accommodations include, but are not limited to, changing the application process, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment. If you require a reasonable accommodation to apply for a job, please contact us via e-mail at hr@cloudflare.com or via mail at 101 Townsend St. San Francisco, CA 94107.
Associate Information Security Engineer
Highmark HealthCreating remarkable health experiences, freeing people to be their best.
• Assists teams in clearly defining requirements, deliverables and timeframes • Escalate issues and make recommendations to resolve them • Assists in conducting root cause analysis to identify and resolve complex problems • Assists in developing and/or delivering technical training in less complex areas • Assists in completing project tasks to enable on time, within budget delivery of ISRM Infrastructure projects • Assists to implement, monitor, configure, and maintain security systems.




