IT Security Engineering Manager
James Madison University · Harrisonburg, VA · Today
$114k–$130k/yrFull-time
About the role
The Security Engineering Manager will lead a collaborative team of four security professionals that support the University's IT security needs for all JMU students, faculty, and staff. This position is eligible for a hybrid work schedule.
Responsibilities
- Captures the IT organization's technical activities to implement and manage security infrastructure.
- Provides status updates to management and completes work assigned to the security team as a technical resource.
- Translates the IT risk requirements and constraints of the business into technical control requirements and specifications.
- Provides leadership skills to manage a highly technical staff and leads projects and work assigned to the security team.
- Interacts with JMU employees, building strong relationships at all levels and across all business units and organizations.
Qualifications
- Understanding of information security concepts, protocols, industry best practices, and strategies.
- Ability to recommend, design, and implement new technologies that improve security.
- Working knowledge of Security Information Event Management (SIEM) systems.
- Experience monitoring and analyzing the security of IT systems.
- Knowledge of and experience working with enterprise firewalls and VPN appliances.
- Proficient with Linux, macOS, and Windows operating systems.
- Strong analytical skills to analyze security requirements and relate them to appropriate security controls.
- Experience providing leadership, guidance, and encouragement to the security team.
- Ability to coordinate and/or assist with incident response and event handling needs as well as respond to occasional requests for IT Security assistance after standard work hours.
Additional Qualifications
- Experience with common information security management frameworks, such as ISO 2700x, NIST SP800 series.
- Familiarity with applicable legal and regulatory requirements, including, but not limited to: FERPA, HIPAA, GLBA, PCI-DSS.
- A strong understanding of the business impact of security tools, technologies and policies.
- Experience securing cloud applications and Microsoft 365.
- Knowledge of and experience in developing and documenting security architecture and plans, including strategic, tactical and project plans.
- Proficiency in performing risk, business impact, control and vulnerability assessments, and in defining treatment strategies.
- Project management skills and experience in creating and managing project plans, including budgeting and resource allocation.
- Experience developing and maintaining policies, standards, and procedures as well as experience working with legal, audit and compliance staff.