POSITION SUMMARY
Our Technology team is seeking an Infrastructure Security Engineer to design, build, and secure the cloud, network, and identity infrastructure that runs a mixed-use real estate portfolio. Reporting to the Vice President of Infrastructure, this is a hands-on engineering role — you will own solutions end-to-end, from architecture and deployment through day-to-day operations, while advancing and maturing our security posture across every layer of the stack.
A builder’s role — not a monitoring role. The strongest candidates have designed and operated cloud, network, and identity infrastructure with their own hands — and bring real security depth to that engineering foundation. If your experience is limited to reviewing alerts in a SOC, this role will not be the right fit.
WHAT YOU'LL DO
And How You Will Be Challenged
This role suits an engineer who takes a holistic, full-stack approach — comfortable across every layer of the environment, from physical network and cabling design through cloud architecture and application enablement — and who wants to materially influence the security posture of a multi-faceted real estate company. You will thrive here if you enjoy real ownership and complex, fast-paced work.
Responsibilities will include:
- Design, deploy, and promote cloud security solutions for Azure and AWS platforms.
- Manage identity and access controls for both on-premises and Azure environments using technologies like Azure Entra, Active Directory, internal PKI, Intune, NDES, MFA, PIM, Security Group Management, Group Policy, and Kerberos.
- Possess strong knowledge of modern cloud and data center architectures, platforms, and their impact on business goals, and lead teams to quickly resolve incidents and outages.
- Support all products within the functional area, from creation and deployment to ongoing performance, aligning with business, global infrastructure, and security requirements.
- Oversee enterprise-level email security tools.
- Manage, coordinate, and communicate with Security and IT Service providers to ensure services are being delivered and utilized appropriately.
- Monitor and analyze security events and alerts from multiple sources, and respond to threats and vulnerabilities.
- Script and automate processes using tools such as Python, PowerShell, and Bash.
- Promote security awareness (e.g., phishing simulations) and best practices throughout the organization.
- Investigate intrusion attempts, conduct thorough exploit analyses, and test defensive controls and response measures.
- Collaborate with internal IT and other departments to deliver infrastructure and network solutions that support business growth and enhance tenant experiences.
- Develop processes and comply with strict regulatory requirements for network operations.
- Continuously evaluate and improve infrastructure to meet business needs, identify cost-saving opportunities, and further cloud adoption.
WHAT YOU'LL NEED TO SUCCEED (REQUIREMENTS)
- A Bachelor’s degree in Computer Science, Information Technology, or a related field—or equivalent experience—is required.
- Familiarity with the Microsoft 365 Suite is essential.
- Candidates must be self-motivated, able to handle multiple tasks, prioritize efficiently, and thrive in fast-paced, dynamic settings.
- Proven expertise managing enterprise-level infrastructure across multi/hybrid cloud environments, including Azure, AWS, and on-premise or colocation data centers; previous migration and transitional environment support are advantageous.
- Experience with MS Windows implementation, operations, and security for both workstations and servers.
- In-depth knowledge of Cloud Service Operations & Controls, network monitoring/management tools, network access control (Cisco ISE), NIST Framework, Zero trust solution (Zscaler), sophisticated networks and dynamic routing protocols (BGP, EIGRP), SD-WAN, VoIP/Cloud Voice Solutions, SaaS, PaaS, IaaS, SCCM and device/system patching, Building Automation Systems, SIEM (Splunk, CrowdStrike), network and endpoint security tools, firewalls (Palo Alto, Meraki, Cisco, Ruckus), Citrix, as well as WVD/Workspaces.
- Competence in email security tools and flow (DKIM, DMARC)
- Demonstrated history of providing compute and networking infrastructure to underpin business initiatives.
- Ability to perform initial triage on security incidents.
- Capable of supporting transient network challenges and making real-time decisions to maintain continual business operations, while promptly communicating issues.
- Competence in tracking and reporting key performance indicators for network and cloud system availability.
- Outstanding verbal and written communication skills, with the capacity to effectively convey information to non-technical audiences; strong persuasive abilities to gain trust across all organizational levels.
- Effective at prioritizing, organizing, and communicating multiple projects of varying complexity, often under tight deadlines.
- Able to excel both independently and as part of a team.
- Willingness to adapt to change, quickly learn new software, and embrace emerging technologies.
OR any equivalent combination of education, training, and/or experience that fulfills the requirements of the position will be considered.
The compensation range for this position is $130,000 to $160,000 annually. This position is also eligible for an annual performance bonus. Please note that the compensation range information provided is a general guideline. It is uncommon for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on a variety of factors. JBG SMITH considers factors such as (but not limited to) scope and responsibilities of the position, candidate’s work experience, candidate’s work location, education/training, key skills, internal peer equity, external market data, as well as market and business considerations when making compensation decisions.