Infrastructure Security Engineer

JBG Smith

Bethesda (MD)

On-site

USD 130,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Annual bonus
Competitive benefits

Job summary

JBG SMITH seeks an Infrastructure Security Engineer to design, build, and secure cloud, network, and identity infrastructure for a mixed‑use portfolio. You will own end‑to‑end solutions from architecture to operations, advancing security posture across the stack.

The role requires hands‑on experience with cloud platforms (Azure, AWS), on‑prem environments, and strong incident response and security engineering skills. A Bachelor’s degree or equivalent experience is required.

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, or related field or equivalent experience.
  • Experience with Microsoft 365 Suite is essential.
  • Proven ability to manage enterprise‑level infrastructure across multi‑hybrid cloud environments (Azure, AWS, on‑prem).
  • Experience with Windows security for workstations and servers; strong security engineering background.

Responsibilities

  • Design, deploy, and promote cloud security solutions for Azure and AWS platforms.
  • Manage identity and access controls across on‑premises and cloud environments.
  • Lead incident response and vulnerability mitigation efforts across multiple layers.
  • Collaborate with IT and security teams to deliver secure infrastructure that supports business growth.
  • Promote security awareness and best practices, including phishing simulations.
  • Oversee enterprise‑level email security tools and communications with providers.

Skills

Cloud security
Azure
AWS
Identity management
SIEM
Zero‑trust
NIST framework
Python scripting
Networking
Windows security

Education

Bachelor's degree in Computer Science, Information Technology, or related field

Tools

Azure
AWS
Active Directory
Intune
NDES
MFA
PIM
PKI
Kerberos
Splunk
CrowdStrike
Palo Alto
Meraki
Cisco
Citrix
WVD
Zscaler

Job description

Infrastructure Security Engineer
Who We Are

JBG SMITH owns, operates, invests in and develops a dynamic portfolio of high‑growth mixed‑use properties in and around Washington, DC. Our creativity and scale enable us to be more than owners—we are place makers who shape inspiring and engaging places, which we believe create value and have a positive impact in every community we touch.

JBG SMITH has been named multiple times as one of the Washington Post's Top Workplaces in the region and we pride ourselves in both our outstanding work environments and opportunities for career growth and advancement.

Position Summary

Our Technology team is seeking an Infrastructure Security Engineer to design, build, and secure the cloud, network, and identity infrastructure that runs a mixed‑use real estate portfolio. Reporting to the Vice President of Infrastructure, this is a hands‑on engineering role—you will own solutions end‑to‑end, from architecture and deployment through day‑to‑day operations, while advancing and maturing our security posture across every layer of the stack.

A builder's role—not a monitoring role. The strongest candidates have designed and operated cloud, network, and identity infrastructure with their own hands, and bring real security depth to that engineering foundation. If your experience is limited to reviewing alerts in a SOC, this role will not be the right fit.

What You'll Do

And How You Will Be Challenged

This role suits an engineer who takes a holistic, full‑stack approach—comfortable across every layer of the environment, from physical network and cabling design through cloud architecture and application enablement—and who wants to materially influence the security posture of a multi‑faceted real estate company. You will thrive here if you enjoy real ownership and complex, fast‑paced work.

Responsibilities will include:

  • Design, deploy, and promote cloud security solutions for Azure and AWS platforms.
  • Manage identity and access controls for both on‑premises and Azure environments using technologies such as Azure Entra, Active Directory, internal PKI, Intune, NDES, MFA, PIM, security group management, group policy, and Kerberos.
  • Possess strong knowledge of modern cloud and data center architectures, platforms, and their impact on business goals, and lead teams to quickly resolve incidents and outages.
  • Support all products within the functional area, from creation and deployment to ongoing performance, aligning with business, global infrastructure, and security requirements.
  • Oversee enterprise‑level email security tools.
  • Manage, coordinate, and communicate with security and IT service providers to ensure services are being delivered and utilized appropriately.
  • Monitor and analyze security events and alerts from multiple sources, and respond to threats and vulnerabilities.
  • Script and automate processes using tools such as Python, PowerShell, and Bash.
  • Promote security awareness (e.g., phishing simulations) and best practices throughout the organization.
  • Investigate intrusion attempts, conduct thorough exploit analyses, and test defensive controls and response measures.
  • Collaborate with internal IT and other departments to deliver infrastructure and network solutions that support business growth and enhance tenant experiences.
  • Develop processes and comply with strict regulatory requirements for network operations.
  • Continuously evaluate and improve infrastructure to meet business needs, identify cost‑saving opportunities, and further cloud adoption.
What You'll Need to Succeed (Requirements)
  • A Bachelor's degree in Computer Science, Information Technology, or a related field—or equivalent experience— is required.
  • Familiarity with the Microsoft 365 Suite is essential.
  • Candidates must be self‑motivated, able to handle multiple tasks, prioritize efficiently, and thrive in fast‑paced, dynamic settings.
  • Proven expertise managing enterprise‑level infrastructure across multi‑hybrid cloud environments, including Azure, AWS, and on‑premise or colocation data centers; previous migration and transitional environment support are advantageous.
  • Experience with MS Windows implementation, operations, and security for both workstations and servers.
  • In‑depth knowledge of cloud service operations & controls, network monitoring/management tools, network access control (Cisco ISE), NIST framework, zero‑trust solution (Zscaler), sophisticated networks and dynamic routing protocols (BGP, EIGRP), SD‑WAN, VoIP/CLOUD voice solutions, SaaS, PaaS, IaaS, SCCM and device/system patching, building automation systems, SIEM (Splunk, CrowdStrike), network and endpoint security tools, firewalls (Palo Alto, Meraki, Cisco, Ruckus), Citrix, as well as WVD/workspaces.
  • Competence in email security tools and flow (DKIM, DMARC).
  • Demonstrated history of providing compute and networking infrastructure to underpin business initiatives.
  • Ability to perform initial triage on security incidents.
  • Capable of supporting transient network challenges and making real‑time decisions to maintain continual business operations, while promptly communicating issues.
  • Competence in tracking and reporting key performance indicators for network and cloud system availability.
  • Outstanding verbal and written communication skills, able to effectively convey information to non‑technical audiences; strong persuasive abilities to gain trust across all organizational levels.
  • Effective at prioritizing, organizing, and communicating multiple projects of varying complexity, often under tight deadlines.
  • Able to excel both independently and as part of a team.
  • Willingness to adapt to change, quickly learn new software, and embrace emerging technologies.

OR any equivalent combination of education, training, and/or experience that fulfills the requirements of the position will be considered.

The compensation range for this position is $130,000 to $160,000 annually. This position is also eligible for an annual performance bonus. Please note that the compensation range information provided is a general guideline. It is uncommon for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on a variety of factors. JBG SMITH considers factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience, candidate's work location, education/training, key skills, internal peer equity, external market data, as well as market and business considerations when making compensation decisions.

JBG SMITH is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, status as a protected veteran, disability, sexual orientation, genetic information or any other protected class, in accordance with applicable law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cloud & Infrastructure Security Engineer (Hands-On, Ownership)
Cloud & Infrastructure Security Engineer (Hands-On, Ownership)

JBG Smith • Bethesda (MD)

On-site
USD 130,000 - 160,000
Annual bonus
Competitive benefits
Infrastructure Security Engineer
Infrastructure Security Engineer

Blue Signal Search • Lewes (DE)

On-site
USD 110,000 - 150,000
Influence standards
Collaborative environment
Cloud tech exposure
+1
Infrastructure Security Engineer
Infrastructure Security Engineer

Blue Signal Search • Rehoboth Beach (DE)

On-site
USD 90,000 - 140,000
Senior Security Engineer, Infrastructure & Network Security
Senior Security Engineer, Infrastructure & Network Security

Metropolis • Los Angeles (CA)

On-site
USD 160,000 - 215,000
Healthcare benefits
401(k) plan
Stock option plan
+1
Senior Security Engineer, Infrastructure & Network Security
Senior Security Engineer, Infrastructure & Network Security

Metropolis Technologies • New York (NY)

On-site
USD 165,000 - 215,000
Healthcare benefits
401(k) plan
Short-term and long-term disability coverage
+3
Enterprise Security Engineer
Enterprise Security Engineer

Jenzabar • United States

On-site
USD 83,000 - 95,000
Medical Insurance
Life Insurance
Dental Insurance
+8
Senior Security Engineer, Infrastructure & Network Security
Senior Security Engineer, Infrastructure & Network Security

Metropolis Technologies • Los Angeles (CA)

On-site
USD 160,000 - 215,000
Healthcare benefits
401(k) plan
Stock option plans
+1
Senior Security Manager
Senior Security Manager

JE Dunn • Kansas City (MO)

On-site
USD 140,000 - 170,000
Multi-Cloud Engineer SME (Azure/Identity) - Ft Belvoir, VA
Multi-Cloud Engineer SME (Azure/Identity) - Ft Belvoir, VA

JCS Solutions LLC • Fort Belvoir (VA)

On-site
USD 96,000 - 105,000
Health, dental, and vision insurance
Life insurance
Disability insurance
+3
Operating Engineer
Operating Engineer

JBG SMITH • Arlington (VA)

On-site
USD 110,000 - 130,000