Security Engineer
About this role
Joining McNees Wallace & Nurick LLC means becoming part of a team that values your voice, your growth, and your impact on clients, colleagues, and the communities we serve. Since 1935, McNees has been a trusted, client-focused law firm delivering practical, results-driven legal solutions with integrity and a client-first philosophy. We are a full-service firm with more than 170 attorneys and 350 professionals, committed to excellence across a wide range of practice areas and industries.
At McNees, we are guided by our core values of authentic relationships, excellence, growth, and balance to foster collaboration and innovation. We support your success through mentorship, leadership development, and continuous learning opportunities. Our commitment to community runs deep, with a strong tradition of stewardship through pro bono work, charitable initiatives, and civic engagement. We also prioritize flexibility and well-being with a family-focused culture, reasonable revenue hour expectations, and technology that drives efficiency.
If you’re looking for an opportunity to do meaningful work with people who value integrity and collaboration, you’ll feel at home at McNees.
McNees, Wallace & Nurick is actively seeking a Security Engineer to join our Information Technology department. At McNees, we believe our people are our greatest asset. We foster a culture of integrity, innovation, and collaboration - where your ideas matter, and your contributions make a real impact.
Responsibilities
- Design, implement, and maintain enterprise security infrastructure, including firewalls, intrusion detection and prevention systems (IDS/IPS), endpoint protection platforms, SIEM solutions, and application control technologies.
- Lead the execution of the firm's cybersecurity strategy and roadmap, aligning security initiatives with business objectives and risk management priorities.
- Monitor security systems, investigate alerts, and coordinate responses to security incidents, including high-severity events and forensic investigations.
- Conduct vulnerability assessments and penetration testing activities while partnering with system owners to remediate identified risks.
- Develop, maintain, and enforce security policies, standards, and procedures aligned with industry frameworks such as NIST CSF, CIS Controls, and ISO 27001.
- Manage identity and access management solutions, including multi-factor authentication, single sign-on, privileged access management, and periodic access reviews.
- Support security and privacy compliance initiatives, audits, risk assessments, and third-party vendor security reviews.
- Administer and optimize security tools, including email security gateways, web filtering solutions, and cloud security technologies.
- Lead incident response, business continuity, disaster recovery, and major security-focused projects such as platform migrations and zero-trust initiatives.
- Collaborate with infrastructure, cloud, and business teams to integrate security requirements into new and existing technologies and processes.
- Advise firm leadership on cybersecurity risks, security architecture, and strategic technology investments.
- Track emerging threats and security trends, and prepare metrics, dashboards, and reports demonstrating the firm's security posture and program maturity.
- Mentor colleagues, share technical expertise, and help foster a culture of security awareness across the organization.
Requirements
- Bachelor's degree in Information Security, Information Technology, Information Systems, or a related field, or an equivalent combination of education and experience.
- Five or more years of progressive experience in cybersecurity or information security, including responsibility for complex security programs and initiatives.
- Strong knowledge of network security, operating system hardening, Azure security, and modern security architectures, including zero-trust principles.
- Hands-on experience with SIEM platforms, vulnerability management tools, endpoint detection and response (EDR), firewalls, and IDS/IPS technologies.
- Working knowledge of security frameworks and standards such as NIST CSF, CIS Controls, ISO 27001, and SOC 2.
- Understanding of identity and access management technologies and protocols, including SAML, OAuth, LDAP, and directory services.
- Experience with scripting and automation tools such as PowerShell and Python.
- Exceptional analytical, troubleshooting, and problem-solving abilities.
- Strong written and verbal communication skills with the ability to present technical concepts to both technical and non-technical audiences.
- Ability to manage multiple priorities, work independently, and maintain confidentiality in a professional services environment.
- Industry certifications such as CISSP, CISM, CEH, GIAC, or CompTIA Security+ are strongly preferred.
- Master's degree in Cybersecurity, Information Security, or a related discipline is preferred.
#LI-REMOTE
#LI-DNP
About McNees
Headquartered in Harrisburg, Pa., McNees operates offices across Pennsylvania, Maryland, Ohio, and Washington, D.C., giving our team a broad regional footprint and diverse opportunities for collaboration. We are ranked among the NLJ 500, Best Law Firms, and Best Lawyers, and nationally recognized for excellence in areas such as construction litigation and energy law.
Our attorneys deliver tailored strategies to businesses, individuals, and organizations across industries, including real estate, energy, healthcare, banking and finance, insurance, construction, and technology. We also have a strong presence in public sector law, advocating for clients in regulatory and legislative matters at all levels of government.
Our services span corporate law, real estate and construction, labor and employment, litigation, tax, intellectual property, energy and environmental, estate planning, and public sector law, complemented by affiliated businesses like Apollo Communications (strategic marketing and PR), Keystone Municipal Solutions (municipal consulting), and Pine Street Land Company (title and settlement services).
McNees offers an engaging work environment, robust opportunities for professional development, challenging and rewarding career paths, and competitive compensation. McNees is an Equal Opportunity Employer. Employment decisions are made without regard to any trait protected by law.
