94-1687665 Bank of America, National Association · Denver

Salary
$98,400–$160,000from the description
Posted
Jul 7, 2026
Location
Denver
Last confirmed open
Jul 20, 2026

What this job asks for AI summary

A network security engineering role focused on designing, deploying, and maintaining enterprise-grade security infrastructure. Day-to-day work centers on BGP routing, DDoS mitigation using NetScout Arbor hardware, and web application firewall configuration, with additional exposure to cloud network security platforms. The position also involves leading cross-functional technical projects, defining security requirements, and mentoring teammates. Suits an experienced network security engineer with strong hands-on routing and DDoS mitigation backgrounds.

Senior level · 5+ years · Denver, CO · Full-time

Must have (3)
BGP · 5+ yrsNetScout ArborDDoS mitigation
Nice to have (2)
Akamai or CloudflareWAF

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What won't set you apart
BGP40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $139,675 (middle half $110,017–$174,679). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (8)

The posting lists three work locations (Denver CO, Washington DC, Chicago IL); Denver is used as the primary CBSA here since it is listed first. The same pay range ($98,400–$160,000/year) applies to all three sites.

BGP design/configuration/troubleshooting with 5+ years is the only hard-gated experience requirement; it sits in the Required Qualifications section with explicit years.

NetScout Arbor hardware and DDoS mitigation experience also appear in the Required Qualifications section and are treated as hard gates, even though the phrasing is descriptive rather than using 'must' language.

ISP/BGP community-based routing policy experience is explicitly flagged 'highly desirable' within the Required Qualifications block — treated as preferred despite its placement.

Cloud network security (Akamai, Cloudflare) and WAF configuration are both explicitly called out as 'a plus' — treated as preferred.

The role title is 'Network Security Engineer' with no seniority modifier; advertised seniority is Unspecified. The 5+ years requirement and scope (SME, mentoring, leading cross-functional efforts) support a Senior classification.

SOC code 15-1212 (Information Security Analysts) is chosen over 15-1244 (Network/Systems Admins) because the primary day-to-day work is security engineering — DDoS mitigation, WAF, BGP security policy — rather than general network operations.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): ISP routing / BGP community policies.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗