Security Engineer II – Network & Firewall Security
Cyber Security
Cybersecurity Tools
Data Platform
Data Security
Endpoint Security
Engineer
Facilities Management
Firewall Security
Identity and Access Management
Incident Management
Incident Response
Information Security
Information Technology (IT)
InfoSec
Log Management
Management
Network Security
Project Management
Risk Management
Rmf
Security
Security Architecture
Security Compliance
Security Engineering
Security Information And Event Management
Security Monitoring
Security Operations
Security Standards
Solution Architecture
Splunk
Splunk Siem
Vpn/ipsec
Zero Trust
Zero Trust Architecture
Job Description
URM Stores Inc is hiring a Security Engineer II focused on Network & Firewall Security to help safeguard systems, networks, users, and data in a Spokane, WA onsite environment. In this role, you will implement, operate, and continuously improve network and firewall security controls, while supporting security operations through technical investigations and escalation.
What you’ll do
- Engineer, administer, and maintain enterprise cybersecurity technologies and controls.
- Provide technical expertise in firewall security, network segmentation, VPN, secure remote access, and network security architecture.
- Review firewall policies and network security configurations to support appropriate access, segmentation, and risk reduction.
- Partner with Network Engineering on firewall upgrades, rule changes, VPN/IPsec connectivity, segmentation, and secure network design.
- Support URM security operations platform activities and act as internal Tier 2/3 escalation for security investigations.
- Investigate security alerts and incidents, coordinating remediation with infrastructure, application, and business teams.
- Support vulnerability and exposure management, including vulnerability analysis, risk prioritization, remediation coordination, validation, and reporting.
- Engineer and maintain endpoint security and application-control technologies.
- Support identity and access security initiatives, including MFA, privileged access, Zero Trust, and secure remote-access efforts.
- Participate in incident-response activities, tabletop exercises, and development of response playbooks.
- Support cybersecurity logging, telemetry, detection engineering, and integration of security data sources.
- Assist with implementation and tuning of technologies including Stellar Cyber, ThreatLocker, BeyondTrust, endpoint security, vulnerability-management platforms, and related controls.
- Support NIST CSF and PCI DSS security assessments, audits, penetration testing, and remediation from a technical perspective.
- Participate in security architecture reviews and technology or vendor assessments.
- Develop security documentation, procedures, standards, and technical diagrams.
- Participate in after-hours incident response and on-call support as required.
- Mentor junior technical staff and share cybersecurity knowledge across Infrastructure and IT.
What you bring
- 4+ years of cybersecurity, network security, network engineering, systems security, or a related technical field.
- Strong hands-on knowledge of enterprise firewalls, firewall policy, VPN/IPsec, network segmentation, routing, and TCP/IP.
- Experience administering or supporting enterprise cybersecurity technologies.
- Experience investigating security events and analyzing technical security issues.
- Working knowledge of vulnerability management and remediation processes.
- Understanding of endpoint security, identity and access management, MFA, logging/SIEM, and incident response.
- Understanding of NIST CSF or comparable cybersecurity frameworks.
- Ability to independently troubleshoot complex security and network problems.
- Strong documentation and communication skills.
Technologies you may work with
- Firewalls, VPN/IPsec, TCP/IP
- Stellar Cyber, ThreatLocker, BeyondTrust
- Endpoint security, application-control technologies
- Vulnerability-management platforms, MFA
- SIEM
- NIST CSF, PCI DSS
- Fortinet/FortiGate (including Fortinet certification)
- Qualys, Microsoft Entra, Microsoft Defender, Carbon Black
- SASE, ZTNA, Zero Trust
Compensation & benefits
- Salary: $102,000 - $125,000 per year (DOE)
- Insurance benefits: URM pays 100% of Medical/Dental/Vision/RX premiums for the employee and over 93% for dependents
- 401k retirement plan with company match up to 9% of annual salary
- Subsidized life insurance for employees and great rates for family
- Company-paid long-term disability insurance
- Short-term disability and cancer insurance available
- Life Flight insurance at special rate
- Great vacation plan, including six paid holidays and four paid personal holidays
- Paid sick days
- Paid volunteer service day
- Company-sponsored activities (including events such as URM March Madness Brackets, Family Hockey Night with the Chiefs, Holiday Mingle & Jingle, Summer Evening Wine & Music Event, and Winter Break Movie Night)
- Corporate discounts (gym memberships, cell phone plans, computer discounts)
- A company-owned grocery store employee discount program
Preferred experience
- Hands-on Fortinet/FortiGate experience
- Experience with Stellar Cyber or comparable SIEM/XDR platforms
- Experience with ThreatLocker, BeyondTrust, Qualys, Microsoft Entra, Microsoft Defender, Carbon Black, or comparable technologies
- Experience with PCI DSS environments
- Experience with SASE, ZTNA, Zero Trust, and cloud networking/security
- Security+ and/or CySA+, Fortinet certification, CCNA/CCNP, CISSP, or comparable certification
- Experience in multi-site retail, warehouse, distribution, or other operationally critical environments