Senior Microsoft Security Engineer
University of Maryland Global Campus · Adelphi, MD · 4 days ago
Hybrid$116k–$131k/yrFull-time
About the role
The Senior Microsoft Security Engineer will be responsible for identifying potential threats to the IT infrastructure, recommending enhancements accordingly and implementing those technologies. The Senior Microsoft Security Engineer provides support to ensure applicable information protection policies, procedures, guidelines, best practices are followed. Performs Security Risk Assessments (SRAs) and performs compliance reviews to ensure applications and servers are operating in accordance with established policies and procedures.
Responsibilities
- Leads the educational institutions Microsoft security "cloud first" strategy leading to fully leverage SDN (Software Defined Networking) Zero Trust, and Least Privilege strategies
- Designs, implements, and maintains Microsoft security solutions for the educational institution's infrastructure
- Ensures that Microsoft operating systems are configured securely and that security patches are regularly applied
- Manages the configuration and effective use of Microsoft security products, including Microsoft Defender ATP, Azure Security Center, and Microsoft Information Protection
- Implements Microsoft security best practices to maintain the security posture of the educational institution's infrastructure
- Collaborates with Infrastructure/ITSM/Technical teams to implement security requirements in new and existing technology solutions
- Stays up-to-date with the latest security threats and industry trends, and apply this knowledge to improve security protocols within the educational institution
- Serves as a security expert in network efforts, helping project teams comply with enterprise and IT security policies, industry regulations, and best practices
- Led and executes projects on our security roadmap
- Adheres to existing risk management frameworks, such as COBIT, ITIL, and ISO 27002
- Manages incident response for network security events
- Develops and maintains IT security policies
- Researches, designs, and advocates new technologies, architectures, and security products that will support security requirements for the enterprise and its customers, business partners, and vendors
- Supports vulnerability assessments on various types of networks and topologies
- Executes risk and vulnerability assessments and remediation activities
- Analyzes output from network vulnerability assessments, recommend mitigation strategies and resolve any security incidents through work with pertinent business departments
- Reviews and provides feedback on security plans and procedures regarding all aspects of LAN, WAN or MANs, as applicable
- Reviews and provides input into network designs to ensure compliance with security and enterprise architecture
- Provides input and visibility into emerging security technologies, deployment strategies and other security protocols to ensure awareness within the IT security branch
- Builds/enhances security architecture and configures network to enhance the security posture of the enterprise
- Reviews in-house and 3rd-party applications/code for security vulnerabilities and best practices
- Participates in Software Development Lifecycle: code review, QA security testing, launches, etc.
- Develops and/or implements automated security testing tools where possible
- Participates in the development of security-related tools and applications, such as multi-platform cookie-based authentication and internal security libraries/frameworks
- Trains engineers on common security problems and best practices for writing secure code
- Provides security input on overall software architecture
- Performs hands-on testing of applications, as well as build and enforce information risk management requirements and structure, including providing practical secure architecture skills and developing and implementing Information Security best practices.
Requirements
- Experience: 10 years or more of professional experience with 7 or more years in IT security including security policy development, security architecture models, and information security regulatory compliance
- Knowledge of IT security technologies such as firewalls, intrusion detections systems, antivirus, patch management, etc., and the interest and experience to work on security policy and architecture
- Hands-on experience with the following technologies: enterprise system administration across multiple operating systems, IPS management (i.e., Cisco ASA, Palo Alto), vulnerability scanning applications, Splunk
- Experience in engineering and enterprise system administration roles
- Experience developing a standard set of metrics that measure our security posture on a monthly/weekly basis
- Proven experience developing security policies, procedures, risk registers and incident response plans
- Intermediate to advanced knowledge of information security concepts
- Experience with one or more applications development languages such as Ruby on Rails, Java, C/C++, .NET
- Solid knowledge of and experience with secure web architectures, tools and processes
- Knowledge of network architecture and design, network Security, wireless Security and client/server security. Very strong computer networking skills and understanding of networking protocols
- Security of virtual machine environments is highly desirable
- Knowledge of vulnerability assessment/network discovery and associated tools
- Understands infrastructure monitoring
- Knowledge of securing Linux and Windows systems
- Experience with various types of firewalls and technologies
- Demonstrated process improvement experience
- Previous application development experience is very helpful for secure code reviews
- Hands-on experience using multiple Amazon Web Services technologies to support an enterprise environment
- Prior experience as a team lead or role mentoring junior team members
- Experience with threat detection and incident management for web applications that deal with PI
Qualifications
- Possessing at least one professional security certification such as CISSP, CISM, CISA or similar