IT Security Engineer; Johns Hopkins Public Safety
Listed on 2025-12-08
-
IT/Tech
Cybersecurity, Network Security
Johns Hopkins Public Safety is seeking an IT Security Engineer who will be responsible for log management, host security, cloud security, asset discovery, vulnerability management, incident response, threat intelligence, Security Orchestration and Automated Response (SOAR), Network Access Control, network security and oversight of either a Managed Security Service Provider (MSSP) or Security Incident and Event Management (SIEM) tool.
Candidates must have a good understanding of firewall technologies, including next-generation firewall capabilities and be able to implement in an evolving network. Experience with multiple Firewall vendors is helpful. This position will work with the network team to assist managing firewall security and implementation.
The Engineer will be responsible for running penetration and vulnerability scans externally, internally, and producing reports and providing support in resolving those issues to the technical team responsible for the health of those systems.
Experience with SaaS based SIEM technologies and the ability to coordinate with the enterprise IT team on security concerns leading and resolve any issue is required.
Position will also write and deliver department security documentation and processes, review with peers, and be responsible for coordinating internal reviews, reviews with enterprise security team and participate in audits.
Job Scope/ComplexitySecurity efforts at Johns Hopkins Public Safety are complex due to our Academic and Healthcare missions and the complexity of supporting security projects. Incidents and projects are complex and varied in nature and also require the ability to balance the demands of multiple projects.
Specific Duties & Responsibilities- The responsibilities below illustrate work performed by this position
- . Not all duties assigned to this position are included, nor is it expected that everyone in this position will be assigned every job responsibility.
- Respond to all user, system, and network security incidents.
- Troubleshoot problems associated with security tools.
- Stay abreast of emerging security threats, vulnerabilities, and controls.
- Filter and analyze large datasets from security logging and telemetry sources and build tools to integrate data into operational controls.
- Automate security controls, data, and processes to provide improved metrics and operational support.
- Filter and analyze large datasets from security logging and telemetry sources and build tools to integrate data into operational controls - SIEM, Log Aggregation Tools.
- Apply adept understanding and experience with systems automation platforms and technologies.
- Knowledge of the latest trends and awareness of current hacking techniques and cybercrime.
- Working knowledge of either Cisco or Palo Alto firewall technologies. Familiarity with firewall rules and advanced threat protection capabilities in next-generation firewall technologies is a plus.
- Design, implement and administer automated security update technologies for client and server systems.
- Design, implement and administer advanced endpoint protection technologies.
- Test and identify network and system vulnerabilities and work to address them with the appropriate owners.
- Help shape the organization’s security policies and standards for use in on-premises and cloud environments.
- Create technical documents on the use of security technologies.
- Apply system security engineering principles to deliver real world solutions to enhance our organization security posture.
- Familiarity with network scanners such as Nessus, Tenable or Qualys and ability to interpret reporting and communicate remediation steps to others in the department.
- Direct and influence multi-disciplinary teams in implementing and operating information security controls.
- Provide subject matter expertise on information security architecture and systems engineering to other IT and business teams.
- Interpret security and technical requirements into business requirements and communicate security risks to relevant stakeholders.
- Familiarity with NIST, CJIS or CIS frameworks and understanding of how to…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).