Job Specifications
US Job Description
Firm Information
Reed Smith is a dynamic international law firm dedicated to helping clients move their businesses forward. With an inclusive culture and innovative mindset, we deliver smarter, more creative legal services that drive better outcomes for our clients. Our deep industry knowledge, long-standing relationships and collaborative structure make us the go-to partner for complex disputes, transactions and regulatory matters.
Our team of 3,000 people (including more than 1,600 lawyers) across more than 30 offices in the United States, Europe, the Middle East and Asia, operate as one global partnership to drive progress for our clients, for ourselves and for our communities.
Position Summary
Under the supervision of the Security Manager, the Security Engineer – Infrastructure is responsible for supporting the security and compliance of the firm’s infrastructure, including networks, servers, workstations, and telecommunications systems. This role works closely with Information Technology teams to ensure all infrastructure components meet firm, industry, and ISO 27001 security standards. The Security Engineer reviews and secures infrastructure, develops risk mitigation strategies, and contributes to enterprise-wide security projects and initiatives. Responsibilities include serving as a key resource for consulting on security matters, maintaining access controls, and addressing escalations related to security audits, incident response, and internal security concerns. The Security Engineer also participates in the design, implementation, and support of LAN/WAN, remote access, IDS/IPS, PKI, and firewall/unified threat management systems, as well as Identity & Access Management, Endpoint Security Management, Domain Management, and DNS Management. The Security Engineer is also a contributing member of the Cybersecurity Incident Response Team (CIRT).
Job Duties And Responsibilities
Manage and maintain the organization’s Public Key Infrastructure (PKI) systems, ensuring secure encryption, certificate management, and cryptographic key lifecycle processes are in place and operating effectively.
Implement and oversee encryption solutions to protect data at rest, in transit, and in use across both on-premises and cloud environments, ensuring compliance with firm and industry security standards.
Secure cloud environments (including AWS, Azure, and GCP) by ensuring adherence to internal security policies and industry best practices, and assist in the implementation and management of identity management, access control, and data protection within cloud services.
Collaborate with third-party vendors to securely integrate external systems into the firm’s infrastructure, ensuring secure communication, interoperability, and compliance with security requirements.
Deploy, manage, and maintain firewalls, including Firewall-as-a-Service (FWaaS), Unified Threat Management (UTM) solutions, and Secure Web Gateways (SWG), to secure network traffic and enforce firm security policies.
Implement and manage advanced security technologies such as Cloud Access Security Brokers (CASB), Zero Trust Network Access (ZTNA), and other solutions to strengthen the firm’s security posture.
Serve as a primary escalation point for security incidents and audits, leading or assisting in the development of mitigation strategies, post-incident reviews, and compliance reviews to ensure ongoing ISO 27001 adherence.
Act as an internal consultant to IT teams and departments, providing subject matter expertise on infrastructure security, cloud environments, and endpoint protection.
Lead reviews of infrastructure security components, recommend improvements, and develop risk mitigation strategies aligned with the firm’s security posture and industry requirements.
Continuously monitor internal control systems to ensure appropriate access levels and security configurations are maintained across all infrastructure components.
Analyze daily security events and alerts in the context of firm policies, prioritizing and escalating issues as appropriate to support timely and effective incident response.
Evaluate security policies and procedures to identify improvement opportunities and ensure alignment with firm standards, industry requirements, and regulatory expectations.
Provide technical support and administration for LAN/WAN, remote access, IDS/IPS, and unified threat management systems, including troubleshooting, analysis, and the testing and deployment of new hardware and security applications.
Deploy and manage policies for antivirus and endpoint detection and response agents in collaboration with system owners to ensure effective endpoint security management.
Manage the availability and security of the firm’s public domains and DNS records, coordinating with relevant stakeholders as required.
Perform all other duties as assigned.
Job duties and responsibilities included are not exhaustive and may be supplemented as necessary. Ree
About the Company
At Reed Smith, everything we do is to apply our global experience in law to drive progress for our clients, for ourselves and for our communities. We are focused on outcomes, are highly collaborative and have deep industry insight. When combined with our local market knowledge and innovative mindset, this allows us to anticipate and address the needs of our clients and help them achieve their goals. Our team of 3,000 people (including more than 1,600 lawyers) operate across more than 30 offices in the United States, Europe, ...
Know more