Security Engineer

Updated: 2 months ago
Location: Ashburn, VIRGINIA
Job Type: FullTime
Deadline: ;

Posting Details
I. JOB OVERVIEW


Job Description Summary:
GW Information Technology (GW IT) provides empowering tools and caring support for all members of The George Washington University (GW) community. We are focused on driving digital transformation and innovation to enable the academic and operational excellence of our students, faculty, staff, and researchers. At GW IT, we are committed to cultivating a team culture that values diversity, inclusion, respect, and collaboration, and invests in each of our team members to grow in their technology and career skills.
The Security Engineer works within GW IT as a member of the IT security operations and incident response (SOC/IR) team, working closely with key stakeholders across GW to ensure the effective use of tools and techniques necessary to protect the pursuit of research and academic excellence. The SOC/IR team aligns with NIST CSF leveraging both NIST 800-171 and the MITRE ATT&CK framework to deliver core capabilities with additional regulatory requirements attached to specific clinical, research and academic efforts.
As a SOC/IR team member, the incumbent is responsible for helping to ensure that the university’s digital assets are protected from unauthorized access and malicious activity through consistent monitoring, investigation, response, and continuous improvement efforts.
These duties include:
  • Monitors network traffic and responds promptly to threats by determining the criticality of alerts and enriching them with relevant data to guide corrective actions; proactively mitigates risks before breaches occur.
  • Builds partnerships and relationships across the university community and performs ticketing, remediation, and follow-up on all assigned security events, alerts, and vulnerabilities.
  • Participates in incident response activities and analyzes security incidents to identify root causes and makes recommendations for process improvements and adjustments to security controls.
  • Contributes to the development and implementation of security solutions to mitigate risks; Creates, executes, and monitors security protocols to protect information, network infrastructure, and computer systems.
  • Provides support in the administration of IDS/IPS, DLP, firewalls, SEIM/SOAR, and other related security tools and services.
  • Supports cybersecurity awareness campaigns and community engagement by participating in educating staff on information system security best practices to enhance overall security awareness within the organization.
  • Participates in on call rotation schedules ensuring 24×7 coverage for escalated issues outside of normal operating hours.
  • May provide support with eDiscovery and data forensics activities.

Performs other related duties as assigned. The omission of specific duties does not preclude the supervisor from assigning duties that are logically related to the position.
Minimum Qualifications:
Qualified candidates will hold a Bachelor’s degree in an appropriate area of specialization, OR a High School diploma plus a relevant IT Security certification. Degree must be conferred by the start date of the position. Degree requirements may be substituted with an equivalent combination of education, training and experience.
Additional Required Licenses/Certifications/Posting Specific Minimum Qualifications:
Preferred Qualifications:
The SOC/IR team is a highly collaborative and agile team that works collectively requiring each team member to adapt to daily threats and incidents as well as enhance longer term capabilities to remain effective in supporting GW’s mission.
Desired Skills:
  • Passionate cybersecurity professional that is self-motivated, detail-oriented, and able to maintain composure in challenging situations.
  • Experience in security operations center (SOC) environment leveraging an enterprise SEIM and other related tools to aid in the monitoring for irregularities, identifying security risks and investigating events to determine necessary corrective action.
  • Applied knowledge of NIST 800-171 and MITRE ATT&CK framework and their application in security operations and incident response.
  • Strong foundations in network infrastructure and ability to demonstrate knowledge of system security requirements.
  • Focused ability to define, document, recommend, review and improve processes and procedures.
  • Experience with hybrid infrastructure environments (mix of on premise, cloud, PaaS and SaaS). IPv6 experience preferred.
  • Experience administering and leveraging security appliances and systems supporting intrusion detection and response, data loss prevention, incident response, and endpoint protection.
  • Experience working across key IT functional areas including systems, engineering, networking, and application/web services.
  • Knowledge of system administration principles, including system monitoring, hardening, and performance optimization and familiarity with containers and container management.
  • Effective problem-solving, communication, and collaboration skills, and ability to effectively balance multiple concurrent tasks.
  • Ability to lead and take ownership of projects and deliverables.
  • Experience in working in a higher education, research and/or academic medical center.
  • Excellent verbal and written communication skills; ability to prepare and present comprehensive presentations to IT and business executives.
  • Passion for building systems, a willingness to learn, and the ability to program, along with strong, applied systems engineering skills.
Typical Hiring Range $29.92 - $46.29 How is pay for new employees determined at GW?

II. JOB DETAILS


Campus Location: Ashburn, Virginia
College/School/Department: GW IT
Family Information Technology
Sub-Family Systems Security
Stream Individual Contributor
Level Level 1
Full-Time/Part-Time: Full time -> FTE 1.00
Hours Per Week: 40
Work Schedule: Monday - Friday, 8:30AM - 5:30PM
Will this job require the employee to work on site? Yes
Employee Onsite Status Hybrid
Telework: Yes
Required Background Check: Criminal History Screening, Education/Degree/Certifications Verification, Social Security Number Trace, and Sex Offender Registry Search
Special Instructions to Applicants:
Employer will not sponsor for employment Visa status
Internal Applicants Only? No
Posting Number: S012831
Job Open Date: 02/20/2024
Job Close Date:
If temporary, grant funded or limited term appointment, position funded until:
Background Screening Successful Completion of a Background Screening will be required as a condition of hire.
EEO Statement:

The university is an Equal Employment Opportunity/Affirmative Action employer that does not unlawfully discriminate in any of its programs or activities on the basis of race, color, religion, sex, national origin, age, disability, veteran status, sexual orientation, gender identity or expression, or on any other basis prohibited by applicable law.



Similar Positions