> Markdown version of [/jobs/ext/155983-cyber-security-engineer-ii](https://www.wearedevelopers.com/jobs/ext/155983-cyber-security-engineer-ii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Engineer II - **Company:** Johns Manville - **Location:** Denver, CO, United States - **Experience:** Expert - **Salary:** $101,900.0 - $152,900.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Data Analysis, Software System Penetration Testing, Systems Engineering, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, DevOps, Identity and Access Management, Intrusion Detection and Prevention, Network Security, Log Analysis, Microsoft Security Essentials, Windows PowerShell, Cloud Services, Kusto Query Language, Security Information and Event Management, Software Vulnerability Management, Enterprise Software Applications, Cloud Platform System, Software Security, Cyber Threat Analysis, Information Technology, Cybercrime, Microsoft Sentinel, Network Server, Devsecops, Qualys, Security Orchestration, Automation & Response, Vulnerability Analysis - **Published:** May 30, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=f61f0c50485bbc8b ## About the Role Do you have experience in Vuls?, Do you have a Master's degree?, * Bachelor's degree with a minimum of 7 years of IT experience, OR * 7-10 years of overall IT experience with at least 7 years focused in cybersecurity/network security. Additionally, candidates should possess two or more of the following certifications: * CISSP * GIAC Certification * Microsoft Security Certifications * Azure Security Certifications * Or equivalent cybersecurity-related certifications A Master's degree in Cybersecurity, Information Security, Computer Science, or related field may be considered in lieu of some experience requirements. Required Technical Skills and Experience * Expert-level experience supporting enterprise cybersecurity technologies and operations. * Advanced experience with SIEM and SOAR technologies, including security automation, orchestration, and incident response workflow development. * Strong experience utilizing KQL (Kusto Query Language) for threat hunting, analytics, detections, dashboards, and investigations. * Strong PowerShell scripting experience for automation, reporting, incident response, and systems administration tasks. * Deep understanding of incident response methodologies, threat detection engineering, and forensic analysis best practices. * In-depth experience with vulnerability management programs, vulnerability scanning platforms, remediation coordination, and risk prioritization processes. * Experience implementing and managing enterprise security technologies in cloud, hybrid, and on-premises environments. * Experience with Microsoft Sentinel, Microsoft Defender, CrowdStrike, Tenable, Qualys, Rapid7, or similar enterprise security platforms preferred. * Experience supporting cloud security operations and securing Microsoft 365, Azure, AWS, or hybrid enterprise environments. * Understanding of secure software development practices, DevOps/DevSecOps concepts, and application security principles preferred. * Experience with security monitoring, endpoint protection, identity security, email security, and data protection technologies. * Strong analytical, troubleshooting, communication, and project management skills. Additional Requirements * Ability to handle sensitive and confidential information. * Ability to work independently and lead complex technical initiatives. * Participation in after-hours support and on-call rotation as required. * Moderate travel required (11-29 days annually), including occasional travel to manufacturing facilities and corporate locations. * Remote and hybrid work candidates must maintain a secure working environment and effectively collaborate with distributed teams., Incumbent must be physically able to perform essential job functions. Reasonable accommodations may be made to enable individuals with disabilities to perform essential job functions. ## Description The Senior Cyber Security Engineer will lead the design, implementation, administration, and support of complex enterprise security initiatives across Johns Manville's global environment. This role is responsible for securing enterprise infrastructure, cloud environments, engineering systems, manufacturing plant floor operations, and critical business technologies through advanced security engineering, operational security management, incident response, and security architecture activities. The ideal candidate will possess deep technical expertise in cloud security, SIEM/SOAR technologies, vulnerability management, incident response, detection engineering, and security automation, along with strong project leadership and collaboration skills. This position plays a critical role in advancing the organization's cybersecurity maturity, improving threat visibility, reducing operational risk, and supporting business continuity. This is a remote/hybrid position. Candidates must reside within the United States and be willing to travel occasionally to the corporate headquarters in Denver, CO and other JM facilities as required. Responsibilities Security Architecture and Engineering (10%) * Lead the design, implementation, and support of enterprise cybersecurity solutions and security architecture initiatives. * Conduct security research, evaluate emerging technologies, and recommend solutions to improve the organization's security posture. * Design and implement security controls across enterprise infrastructure, cloud platforms, endpoints, identity systems, and manufacturing environments. * Develop and maintain secure configurations, security standards, and technical documentation. Security Project Management and Implementation (10%) * Lead and support cybersecurity projects involving multiple business units, technical teams, vendors, and stakeholders. * Manage implementation of enterprise security technologies and security enhancement initiatives. * Coordinate project timelines, technical deliverables, testing, validation, and operational transition activities. * Support security integration efforts for cloud services, endpoint technologies, vulnerability management platforms, SIEM/SOAR solutions, and identity security initiatives. * Participate in planning and execution of security modernization and operational improvement projects. Operational Security Management (30%) * Serve as a senior technical expert for enterprise cybersecurity operations and security technologies. * Administer, maintain, and optimize security platforms including: + Cloud security technologies + Endpoint Detection and Response (EDR/XDR) + Email security + Identity and access management + Data protection technologies + SIEM and SOAR platforms + Vulnerability management platforms + Threat intelligence integrations * Develop, tune, and maintain advanced threat detections, correlation rules, analytics, dashboards, and automation workflows. * Utilize Kusto Query Language (KQL) to develop advanced threat hunting queries, detections, reporting, and security investigations within Microsoft Sentinel, Microsoft Defender, and related security platforms. * Develop and maintain SOAR playbooks and automation workflows to improve incident response efficiency and reduce manual operational tasks. * Perform advanced threat hunting and log analysis across cloud, endpoint, network, and identity environments. * Support secure cloud operations and security monitoring across platforms such as Microsoft Azure, Microsoft 365, AWS, and related enterprise technologies. Vulnerability Management and Risk Reduction (15%) * Lead vulnerability management initiatives across enterprise infrastructure, cloud services, servers, endpoints, applications, and operational technology environments. * Maintain in-depth knowledge and operational experience with vulnerability management and scanning platforms such as Tenable, Qualys, Rapid7, Defender Vulnerability Management, or equivalent technologies. * Coordinate vulnerability remediation efforts with infrastructure, server, networking, cloud, and application teams. * Analyze vulnerability data, prioritize remediation activities based on risk, and provide reporting to technical leadership and management. * Conduct security validation and support penetration testing coordination and remediation tracking activities. Technical Collaboration and Mentoring (5%) * Collaborate with infrastructure, engineering, cloud, networking, DevOps, and business teams to implement secure solutions and resolve security issues. * Provide technical mentorship, training, and guidance to cybersecurity engineers, analysts, and IT personnel. * Assist teams with secure deployment practices, incident troubleshooting, and operational security best practices. * Support development of operational procedures, standards, and security documentation. Incident Response, Detection Engineering, and Forensics (30%) * Lead and support cybersecurity incident handling, investigation, containment, eradication, and recovery efforts. * Perform advanced forensic analysis and security investigations involving endpoints, cloud services, email systems, identity systems, and enterprise infrastructure. * Develop and maintain threat detections and response processes across SIEM, EDR/XDR, and cloud security platforms. * Analyze escalated security alerts and suspicious activity to identify malicious behavior and reduce false positives. * Create and maintain custom detection logic and security analytics to improve threat visibility and response capabilities. * Develop remediation plans and coordinate incident response activities with technical teams and leadership. * Prepare investigation findings, root cause analysis, and executive-level incident reporting documentation. * Utilize PowerShell scripting and automation to support investigations, security administration, reporting, and operational efficiency initiatives. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Hosting a modern justice system](https://www.wearedevelopers.com/videos/332-hosting-a-modern-justice-system) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)