IT@JH EMMS is seeking an Enterprise Cybersecurity Engineer will be responsible for log management, host security, cloud security, asset discovery, vulnerability management, incident response, threat intelligence, Security Incident and Event Management (SIEM) Security Orchestration and Automated Response (SOAR), Network Access Control, and network security for the Enterprise Management, Monitoring and Security (EMMS) team within Central IT. The Enterprise Cyber Security Engineer will be responsible for one or more of these technologies, often working with one or more team members to support these functions.
Job Scope/Complexity
- Cyber security efforts at Johns Hopkins are complex due to our Academic and Healthcare missions and the complexity to support security projects for Johns Hopkins University and Medicine. Incidents and projects are complex and varied in nature and also requires the ability to balance the demands of multiple projects.
- The scale is “big-E” Enterprise. All Hopkins Medicine affiliates, including international locales.
Users: 100,000+
Systems: 100,000+
Complexity is at the highest.
Specific Duties & Responsibilities
- The responsibilities below illustrate work performed by this position. Not all duties assigned to this position are included, nor is it expected that everyone in this position will be assigned every job responsibility.
Security Monitoring
- Respond to all user, system and network security incidents.
- Troubleshoot problems associated with security tools.
- Stay abreast of emerging security threats, vulnerabilities and controls.
- Filter and analyze large datasets from security logging and telemetry sources, and build tools to integrate data into operational controls.
- Automate security controls, data and processes to provide improved metrics and operational support.
- Filter and analyze large datasets from security logging and telemetry sources, and build tools to integrate data into operational controls – SIEM, Log Aggregation Tools.
- Apply adept understanding and experience with systems automation platforms and technologies.
- Knowledge of the latest trends and awareness of current hacking techniques and cyber-crime.
Host and Cloud Security
- Design, implement and administer automated security update technologies for client and server systems.
- Design, implement and administer advanced endpoint protection technologies.
- Test and identify network and system vulnerabilities and working to address them with the appropriate owners.
- Help shape the organization’s security policies and standards for use in on-premises and cloud environments.
- Create technical documents on use of security technologies.
- Apply system security engineering principles to deliver real world solutions to enhance our organization security posture.
Data Security and Compliance
- Direct and influence multi-disciplinary teams in implementing and operating information security controls.
- Collaborate with application developers and database administrators to deliver creative solutions to difficult technology challenges and business requirements.
- Provide subject matter expertise on information security architecture and systems engineering to other IT and business teams.
- Interpret security and technical requirements into business requirements and communicate security risks to relevant stakeholders.
- Perform other related duties as requested.
Minimum Qualifications
- Bachelor’s Degree.
- Six years of related work experience with computer systems, applications and cybersecurity technologies.
- Additional education may substitute for required experience and additional related experience may substitute for required education beyond HS Diploma/Graduation Equivalent, to the extent permitted by the JHU equivalency formula.
Preferred Qualifications
- Knowledge in the assigned technical areas this position is responsible for.
- A CISSP certification is desirable.
Classified Title: Enterprise Cybersecurity Engineer
Role/Level/Range: ATP/04/PF
Starting Salary Range: $85,500 - $149,800 Annually (Commensurate w/exp.)
Employee group: Full Time
Schedule: Mon-Fri 8:30am-5:00pm
FLSA Status: Exempt
Location: Remote
Department name: IT@JH EMMS
Personnel area: University Administration