Network and Security Engineer
Company: RevOne Companies
Department: Information Security and Compliance
Reports To: Director of Information Security and Compliance
Employment Type: Full-Time, Exempt
Work Arrangement: 100% On-Site – Greenwood, Indiana
Experience Level: Senior – Typically 6–10 Years
Role Allocation: Approximately 70% Infrastructure and 30% Security and Compliance
Position Summary
RevOne Companies is seeking an experienced Network and Security Engineer to oversee and support the organization’s network, server, and systems infrastructure while serving as a primary technical responder for security events.
This senior, hands-on position combines network and systems engineering with security operations, identity and access management, and regulatory compliance support. Approximately 70% of the position is focused on network and systems infrastructure, with the remaining 30% dedicated to security monitoring, incident response, Microsoft Entra ID administration, audit logging, and compliance evidence.
The Network and Security Engineer serves as the senior technical authority for the organization’s network and server environment. The successful candidate must be able to independently evaluate technical issues, make design and remediation recommendations, document decisions, and explain system configurations and security controls to leadership and auditors.
Essential Duties of the PositionNetwork and Systems Infrastructure
- Manage, monitor, maintain, and troubleshoot enterprise switches, routers, firewalls, VPNs, wireless infrastructure, and VLAN segmentation.
- Administer Windows Server environments, including system updates, patch management, backups, restoration, and routine maintenance.
- Maintain and support Active Directory and related infrastructure services, including DNS, DHCP, and Group Policy.
- Conduct vulnerability scans across network devices and servers and remediate findings within established timeframes.
- Maintain approved system and network configuration baselines and investigate configuration drift.
- Process infrastructure and security changes through established change-management procedures.
- Perform and document periodic backup restoration testing to confirm system recoverability.
- Maintain accurate network diagrams, server inventories, configuration records, operating procedures, and technical documentation.
- Respond to network outages, server failures, system performance issues, and other time-sensitive infrastructure incidents.
- Manage infrastructure capacity planning, equipment lifecycle planning, upgrades, and replacement roadmaps.
- Serve as the senior escalation point for network and server issues.
- Provide technical guidance and mentorship to junior network, systems, and service desk personnel.
- Lead infrastructure projects from planning and design through implementation, vendor coordination, testing, documentation, and handoff.
Security Monitoring and Incident Response
- Review and triage security, system, and email alerts.
- Validate security findings, document false-positive dispositions, and escalate confirmed incidents according to established procedures.
- Investigate suspicious activity, phishing reports, anomalous sign-ins, malware events, and suspected account or system compromises.
- Perform initial containment and remediation actions during security incidents.
- Tune security detections and alerting rules to reduce unnecessary alerts while maintaining appropriate detection coverage.
- Serve in a lead technical capacity under the organization’s incident-response plan.
- Participate in and help facilitate incident-response tabletop exercises.
- Recommend security architecture improvements involving segmentation, firewall policies, secure configurations, system hardening, and infrastructure protection.
Identity and Access Management
- Administer Microsoft Entra ID user accounts, security groups, roles, and access permissions.
- Administer Conditional Access policies and multifactor authentication requirements.
- Monitor sign-in activity and audit logs for anomalous or unauthorized behavior.
- Complete joiner, mover, and leaver access changes within established timeframes.
- Conduct and document periodic access reviews.
- Apply least-privilege and role-based access principles when assigning or modifying system access.
Audit Logging and Compliance Support
- Maintain audit logging capabilities across systems included within the organization’s compliance scope.
- Verify that required audit events are generated and successfully forwarded to centralized, access-controlled storage.
- Conduct and document periodic audit-log reviews, including the scope reviewed, findings identified, and corrective actions taken.
- Maintain audit-record retention according to organizational, contractual, and regulatory requirements.
- Support the implementation and enforcement of approved information security policies and technical controls.
- Compile system records, screenshots, configurations, logs, and other evidence for internal and external audits.
- Identify control or documentation gaps and drive corrective actions through completion.
- Assist with maintaining security standards, system procedures, control narratives, and technical operating documentation.
- Support compliance obligations associated with HIPAA, SOC 2, NIST SP 800-53, FISMA, and IRS Publication 1075, as applicable.
Required Skills and Qualifications
- Six to ten years of progressively responsible experience in network engineering, systems engineering, security operations, or a comparable blended technical role.
- Demonstrated experience independently managing or supporting a business-critical network and server environment.
- Advanced knowledge of TCP/IP, DNS, DHCP, VLANs, routing, firewalls, VPNs, and wireless networking.
- Ability to design, configure, secure, and troubleshoot network infrastructure—not solely monitor or operate existing systems.
- Strong Windows Server and Active Directory administration experience.
- Experience with patch management, backup administration, restoration testing, vulnerability remediation, and system hardening.
- Direct experience administering Microsoft Entra ID and Microsoft 365 security capabilities.
- Experience with Conditional Access, multifactor authentication, access reviews, sign-in logs, and privileged-role administration.
- Working experience with a SIEM, EDR, or comparable security-monitoring platform.
- Experience investigating security alerts, documenting findings, and completing or coordinating response actions.
- Understanding of change management, configuration baselines, least privilege, segregation of duties, and audit-log retention.
- Strong technical documentation, organization, and recordkeeping skills.
- Ability to prioritize and manage concurrent infrastructure, security, and compliance responsibilities.
- Effective written and verbal communication skills, including the ability to explain technical risks to nontechnical stakeholders.
- Ability to exercise sound independent judgment while appropriately escalating significant risks and incidents.
Healthcare, Privacy, and Security Responsibilities
- Protect confidential organizational information, personally identifiable information, protected health information, and other regulated data.
- Follow all RevOne Companies privacy, information security, acceptable-use, and confidentiality requirements.
- Implement and maintain technical safeguards supporting applicable HIPAA, SOC 2, NIST, FISMA, and IRS Publication 1075 requirements.
- Ensure that access is granted according to job responsibilities and least-privilege principles.
- Immediately report suspected security incidents, unauthorized access, privacy events, or policy violations.
- Complete required security awareness and role-based training upon hire and annually thereafter.
- Maintain appropriate documentation and evidence demonstrating the operation of assigned security controls.
Separation of Duties
Because this position holds administrative access to systems for which it may also review audit logs, the following compensating controls apply:
- Audit logs must be forwarded to centralized storage where the Network and Security Engineer does not have modification or deletion authority.
- Privileged activity performed by the Network and Security Engineer will be subject to review by the Director of Information Security and Compliance.
- Material security and infrastructure configuration changes require secondary review through the established change-management process.
- Exceptions or conflicts involving privileged access must be reported to the Director of Information Security and Compliance.
Preferred Qualifications
- CompTIA Security+, Network+, or CySA+ certification.
- Microsoft AZ-500 or SC-200 certification.
- Cisco CCNA or CCNP certification.
- Experience with enterprise vulnerability scanning and remediation platforms.
- PowerShell scripting and task-automation experience.
- Experience supporting regulated healthcare, financial, government, or consumer-data environments.
- Familiarity with NIST SP 800-53, FISMA, HIPAA, SOC 2, or IRS Publication 1075.
- Previous responsibility for producing technical evidence during an external audit or assessment.
- Experience coordinating with managed service providers, technology vendors, auditors, or security consultants.
Work Schedule and Conditions of Employment
- Standard business hours are Monday through Friday, with work performed on-site at the Greenwood, Indiana office.
- This position does not currently include a formal on-call rotation.
- After-hours availability is required as needed for critical network or server outages, cybersecurity incidents, and scheduled maintenance.
- Planned maintenance windows will be scheduled and communicated in advance whenever practicable.
- Remote and hybrid work arrangements are not available for this position.
- All work must be performed within the United States. Access to organizational systems from outside the United States is prohibited.
- Employment is contingent upon successful completion of required background screening before production-system access is granted.
- Periodic background screenings may be required based on contractual, security, or regulatory obligations.
Work Environment and Physical Requirements
- Work is primarily performed in an office, server room, and data-closet environment.
- The position requires occasional installation, movement, or replacement of network and server equipment.
- Must be able to work around equipment racks, cabling, power supplies, and related infrastructure.
- Must be able to occasionally lift and carry equipment weighing up to approximately 40 pounds, with or without reasonable accommodation.
- Must be able to perform scheduled after-hours work when required for maintenance or incident response.
What Success Looks Like
Success in this position includes:
- Network and server systems remain stable, secure, appropriately maintained, and properly documented.
- Infrastructure incidents are addressed promptly, with root causes and corrective actions documented.
- Vulnerabilities, patches, configuration issues, and access changes are completed within established timeframes.
- Security alerts and audit logs are reviewed consistently and documented according to the required cadence.
- Backup restoration testing confirms that critical systems and data can be recovered.
- Technical documentation, diagrams, inventories, and configuration records remain current.
- Audit evidence is accurate, complete, organized, and available by required deadlines.
- Security and infrastructure improvements are evaluated based on organizational risk, operational impact, and regulatory requirements.
- Junior technical personnel receive effective guidance and escalation support.
- Infrastructure needs do not routinely displace required security and compliance activities.
Role Allocation and Oversight
RevOne Companies will actively manage the blended nature of this position:
- Security-alert triage, audit-log reviews, and other recurring security responsibilities will be assigned a defined cadence and dedicated time.
- Security and compliance tasks delayed by a critical infrastructure incident must be rescheduled rather than eliminated.
- The Director of Information Security and Compliance will review the role allocation at least quarterly.
- Scope, priorities, resources, or staffing may be adjusted if the intended 70% infrastructure and 30% security allocation cannot be reasonably maintained.
Pay: $75,000.00 - $95,000.00 per year
Benefits:
- 401(k)
- 401(k) matching
- Dental insurance
- Flexible schedule
- Health insurance
- Health savings account
- Life insurance
- Paid time off
- Retirement plan
- Vision insurance
Work Location: In person