Cybersecurity Network Security Engineer
Remote (preferred Denver, CO Area)
$132,000-$135,000 The Cybersecurity Network Security Engineer is a hands-on security engineering role responsible for the design, hardening, oversight, and continuous improvement of GMR's enterprise network security architecture. This position partners closely with Cybersecurity Architecture & Engineering, Network Engineering, Infrastructure, Cloud, the Security Operations Center, and other technology teams to ensure network services are secure, resilient, supportable, and aligned with organizational risk standards.The engineer assesses current-state controls, translates security requirements into practical design and remediation recommendations, supports approved implementation and operational response, and helps establish repeatable security patterns across data center, campus, WAN, cloud edge, wireless, and remote-access environments. Success requires strong technical depth, disciplined change control, clear documentation, and effective cross-functional collaboration.
Essential Functions and Duties
- Review network security configurations and recommend improvements aligned with GMR standards, NIST guidance, and industry best practices.
- Harden routers, switches, firewalls, wireless infrastructure, and network appliances to reduce attack surface and enforce secure configuration baselines.
- Administer and optimize Palo Alto Networks Next-Generation Firewalls and Panorama, including policy review, rule management, security profiles, logging, and configuration governance.
- Partner with Network Engineering to advance enterprise segmentation, including microsegmentation, zone design, access control, and path isolation.
- Provide security guidance for BGP and OSPF routing designs and help address routing-related threats, exposure, and resilience concerns.
- Assess network configurations for misconfiguration, policy drift, visibility gaps, compliance concerns, and opportunities to strengthen preventive and detective controls.
- Develop actionable remediation recommendations and support implementation through approved change management processes, including risk articulation, validation criteria, rollback considerations, and documentation.
- Provide subject matter expertise during incidents and investigations involving firewalls, network traffic, routing, remote access, or network security technologies.
- Collaborate with Networking, Infrastructure, Cloud, SOC, GRC, Applications, and Architecture teams on secure deployment of new technologies and services.
- Contribute to architecture and technology evaluations involving SD-WAN, Palo Alto ION, Prisma Access, Zero Trust Network Access, and SASE-aligned capabilities.
- Support audit and assessment readiness activities, including remediation related to PCI DSS, NIST CSF, NIST 800-53, and NIST 800-171.
- Maintain clear technical documentation, secure design patterns, standards, procedures, and decision records for network security controls.
- Develop and report meaningful measures for configuration conformance, policy review, remediation progress, and network security maturity.
- Maintain current knowledge of network threats, vendor capabilities, vulnerabilities, and security practices across Cisco, Palo Alto Networks, Meraki, and related ecosystems.
Qualifications
Education, Licensing, and Certification
- Bachelor's degree in Computer Science, Information Security, Network Engineering, or a related field, or equivalent combination of education and relevant experience.
- Preferred certifications include CISSP, PCNSE, CCNP Security, CCNP Enterprise, Cisco CyberOps, or comparable network and security credentials.
Experience
- Ten or more years of hands-on enterprise networking experience, including routing, switching, firewalls, and network security controls.
- Demonstrated experience operating in structured, change-controlled enterprise environments.
- Experience supporting security architecture, technical assessments, hardening, remediation, and incident response in a regulated or mission-critical environment.
Required Technical Knowledge
- Cisco routers and switches, including IOS and NX-OS.
- Cisco Identity Services Engine (ISE) and Cisco Application Centric Infrastructure (ACI).
- Palo Alto Networks Next-Generation Firewalls and Panorama.
- Meraki access points and MX firewalls.
- BGP and OSPF routing protocols.
- Network appliance hardening, access control, segmentation, logging, and security control implementation.
- Network security monitoring and troubleshooting using enterprise network and security telemetry.
Preferred Knowledge and Experience
- Palo Alto ION, Prisma Access, SD-WAN, Zero Trust Network Access, or SASE architectures.
- SolarWinds or comparable network monitoring and management platforms.
- NIST CSF, NIST 800-53, NIST 800-171, PCI DSS, HIPAA, and related security or compliance frameworks.
- Security assessments, penetration testing remediation, architecture review, or regulated healthcare and emergency services environments..
Measurable alignment of network security controls with GMR standards and applicable security frameworks
Why Choose GMR? Global Medical Response(GMR) and its family of solutions are dedicated to delivering compassionate, quality medical care, primarily in the areas of emergency and patient relocation services. Hereyou'llembark on meaningful work that will make an impact on you and the customers we serve.View the stories on how our employees provide care to the world atwww.AtaMomentsNotice.com.
GMR's Core Behaviors-keep care at the center, raise your hand,seekto understand, find a way together and be accountable-uniteour teamsand set us apart in emergency medical services.
EEO Statement
Global Medical Response and its family of companies are an Equal Opportunity Employer, which includes supporting veterans and providing reasonable accommodations for individuals with a disability. Check out our careers site benefits page to learn more about our benefit options. R0055722
|