Sr. Cyber Security Engineer
Senior
Cloud Platforms
Cloud Security
Cybersecurity Tools
Edr And Xdr
Endpoint Security
Engineer
Identity and Access Management
Incident Response
Information Security
InfoSec
Microsoft Azure Security
Microsoft Defender
Microsoft Sentinel
Project Management
Security
Security Automation
Security Operations
Security Standards
Solution Architecture
Job Description
Johns Manville is seeking a senior-level security engineer to design and operate enterprise cybersecurity capabilities across a global, hybrid environment.
Responsibilities
- Lead the design, implementation, administration, and support of enterprise cybersecurity solutions and security architecture initiatives.
- Perform security research, evaluate emerging technologies, and recommend improvements to organizational security posture.
- Design and implement security controls across enterprise infrastructure, cloud platforms, endpoints, identity systems, and manufacturing environments.
- Develop and maintain secure configurations, security standards, and technical documentation.
- Drive and support multi-team cybersecurity projects across business units, technical teams, vendors, and stakeholders.
- Coordinate project timelines, testing, validation, and operational transition activities for security enhancement initiatives.
- Support security integration efforts across cloud services, endpoint technologies, vulnerability management platforms, SIEM/SOAR solutions, and identity security initiatives.
- Participate in planning and execution of security modernization and operational improvement projects.
- Serve as a senior technical expert for enterprise cybersecurity operations and security technologies.
- Administer, maintain, and optimize security platforms, including:
- Cloud security technologies
- Endpoint Detection and Response (EDR/XDR)
- Email security
- Identity and access management
- Data protection technologies
- SIEM and SOAR platforms
- Vulnerability management platforms
- Threat intelligence integrations
- Develop, tune, and maintain advanced threat detections, correlation rules, analytics, dashboards, and automation workflows.
- Use Kusto Query Language (KQL) to build threat-hunting queries, detections, reporting, and investigations in Microsoft Sentinel, Microsoft Defender, and related platforms.
- Build and maintain SOAR playbooks and automation workflows to improve incident response efficiency and reduce manual work.
- Conduct advanced threat hunting and log analysis across cloud, endpoint, network, and identity environments.
- Support secure cloud operations and security monitoring across Microsoft Azure, Microsoft 365, AWS, and related enterprise technologies.
- Lead vulnerability management initiatives across enterprise infrastructure, cloud services, servers, endpoints, applications, and operational technology environments.
- Maintain operational knowledge of vulnerability management and scanning platforms such as Tenable, Qualys, Rapid7, Defender Vulnerability Management, or equivalent technologies.
- Coordinate vulnerability remediation with infrastructure, server, networking, cloud, and application teams.
- Analyze vulnerability data, prioritize remediation by risk, and provide reporting to technical leadership and management.
- Coordinate security validation and penetration testing remediation tracking.
- Collaborate with infrastructure, engineering, cloud, networking, DevOps, and business teams to implement secure solutions and resolve security issues.
- Provide technical mentorship, training, and guidance to cybersecurity engineers, analysts, and IT personnel.
- Assist with secure deployment practices, incident troubleshooting, and operational security best practices.
- Support development of operational procedures, standards, and security documentation.
- Lead and support cybersecurity incident handling, including investigation, containment, eradication, and recovery.
- Perform advanced forensic analysis and security investigations involving endpoints, cloud services, email systems, identity systems, and enterprise infrastructure.
- Develop and maintain threat detections and response processes across SIEM, EDR/XDR, and cloud security platforms.
- Analyze escalated alerts and suspicious activity to identify malicious behavior and reduce false positives.
- Create and maintain custom detection logic and security analytics to improve threat visibility and response capabilities.
- Develop remediation plans and coordinate incident response activities with technical teams and leadership.
- Prepare investigation findings, root cause analysis, and executive-level incident reporting documentation.
- Use PowerShell scripting to support investigations, security administration, reporting, and operational efficiency initiatives.
Requirements
- Bachelor’s degree preferred with 7 years of IT experience and minimum 4 years of cyber security experience.
- At least one certification such as CISSP, ENCE, SANS GIAC, Cisco CCSP, CISM, or completion of a masters level degree program.
- Expert-level experience supporting enterprise cybersecurity technologies and operations.
- Advanced experience with SIEM and SOAR, including security automation, orchestration, and incident response workflow development.
- Strong KQL experience for threat hunting, analytics, detections, dashboards, and investigations.
- Strong PowerShell scripting experience for automation, reporting, incident response, and systems administration tasks.
- Deep understanding of incident response methodologies, threat detection engineering, and forensic analysis best practices.
- In-depth experience with vulnerability management programs, vulnerability scanning platforms, remediation coordination, and risk prioritization processes.
- Experience implementing and managing enterprise security technologies in cloud, hybrid, and on-premises environments.
- Experience with Microsoft Sentinel, Microsoft Defender, CrowdStrike, Tenable, Qualys, Rapid7, or similar enterprise security platforms preferred.
- Experience supporting cloud security operations and securing Microsoft 365, Azure, AWS, or hybrid enterprise environments.
- Understanding of secure software development practices, DevOps/DevSecOps concepts, and application security principles preferred.
- Experience with security monitoring, endpoint protection, identity security, email security, and data protection technologies.
- Strong analytical, troubleshooting, communication, and project management skills.
- Ability to handle sensitive and confidential information.
- Ability to work independently and lead complex technical initiatives.
- Participation in after-hours support and on-call rotation as required.
- Remote/hybrid candidates must maintain a secure working environment and effectively collaborate with distributed teams.
Technologies
- SIEM, SOAR, EDR/XDR
- Kusto Query Language (KQL)
- Microsoft Sentinel, Microsoft Defender
- PowerShell
- Microsoft Azure, Microsoft 365, AWS
- Tenable, Qualys, Rapid7
- Defender Vulnerability Management
- CrowdStrike
- Email security
- Identity and access management
- Data protection technologies
- Threat intelligence integrations
- Penetration testing
Benefits
- Choice of comprehensive medical plans
- Dental plan
- Vision plan
- Wellness program
- Critical illness insurance
- 401(k) plan with a company match
- Paid vacation
- Paid sick and parental leave for eligible employees
- Basic life Insurance
- Short-term and long-term disability coverage
- Employee assistance program
- Business travel accident coverage
- Supplemental life insurance
- Accidental death and dismemberment insurance
- Health spending account
- Traditional flexible spending account
- Dependent care spending account
- Tuition reimbursement program for undergraduate and certain graduate programs
- Educational opportunities
- Company-wide mentoring program
- Soft and hard skills training
Pay Range
- Base salary pay range: $0.00-$0.00 annual
- Incentive bonus eligibility
Location & Work Style
- Denver, CO (hybrid)
- Remote/hybrid role with occasional travel
- Candidates must reside within the United States and be willing to travel occasionally to corporate headquarters in Denver, CO and other JM facilities as required
- Moderate travel required: 11–29 days annually, including occasional travel to manufacturing facilities and corporate locations