James Madison University (JMU) IT Security Team is looking to fill the position of Security Engineering Manager to lead a team of four security professionals supporting the University's IT security needs for all JMU students, faculty, and staff.
Requirements
- Understanding of information security concepts, protocols, industry best practices, and strategies.
- Ability to recommend, design, and implement new technologies that improve security.
- Working knowledge of Security Information Event Management (SIEM) systems.
- Experience monitoring and analyzing the security of IT systems.
- Knowledge of and experience working with enterprise firewalls and VPN appliances.
- Proficient with Linux, macOS, and Windows operating systems.
- Strong analytical skills to analyze security requirements and relate them to appropriate security controls.
Responsibilities
- Coordinates the IT organization's technical activities to implement and manage security infrastructure, provides status updates to management, and completes work assigned to the security team as a technical resource.
- Translates the IT risk requirements and constraints of the business into technical control requirements and specifications.
- Provides leadership skills to manage a highly technical staff and leads projects and work assigned to the security team.
- Ability to recommend, design, and implement new technologies that improve security.
- Experience monitoring and analyzing the security of IT systems.
- Ability to coordinate and/or assist with incident response and event handling needs as well as respond to occasional requests for IT Security assistance after standard work hours.
- Experience securing cloud applications and Microsoft 0365.
Other
- Interacts with JMU employees, building strong relationships at all levels and across all business units and organizations.
- Experience providing leadership, guidance, and encouragement to the security team.
- Experience with common information security management frameworks, such as ISO 2700x, NIST SP800 series.
- Familiarity with applicable legal and regulatory requirements, including, but not limited to: FERPA,HIPAA, GLBA, PCI-DSS.
- A strong understanding of the business impact of security tools, technologies and policies.