Infrastructure Security Engineer

JBG SMITHBethesda, MD
$130,000 - $160,000

About The Position

JBG SMITH owns, operates, invests in, and develops a dynamic portfolio of high-growth mixed-use properties in and around Washington, DC. Our creativity and scale enable us to be more than owners—we are place makers who shape inspiring and engaging places, which we believe create value and have a positive impact in every community we touch. JBG SMITH has been named multiple times as one of the Washington Post’s Top Workplaces in the region and we pride ourselves in both our outstanding work environments and opportunities for career growth and advancement. Our Technology team is seeking an Infrastructure Security Engineer to design, build, and secure the cloud, network, and identity infrastructure that runs a mixed-use real estate portfolio. Reporting to the Vice President of Infrastructure, this is a hands-on engineering role — you will own solutions end-to-end, from architecture and deployment through day-to-day operations, while advancing and maturing our security posture across every layer of the stack. A builder’s role — not a monitoring role. The strongest candidates have designed and operated cloud, network, and identity infrastructure with their own hands — and bring real security depth to that engineering foundation. If your experience is limited to reviewing alerts in a SOC, this role will not be the right fit.

Requirements

  • A Bachelor’s degree in Computer Science, Information Technology, or a related field—or equivalent experience—is required.
  • Familiarity with the Microsoft 365 Suite is essential.
  • Candidates must be self-motivated, able to handle multiple tasks, prioritize efficiently, and thrive in fast-paced, dynamic settings.
  • Proven expertise managing enterprise-level infrastructure across multi/hybrid cloud environments, including Azure, AWS, and on-premise or colocation data centers; previous migration and transitional environment support are advantageous.
  • Experience with MS Windows implementation, operations, and security for both workstations and servers.
  • In-depth knowledge of Cloud Service Operations & Controls, network monitoring/management tools, network access control (Cisco ISE), NIST Framework, Zero trust solution (Zscaler), sophisticated networks and dynamic routing protocols (BGP, EIGRP), SD-WAN, VoIP/Cloud Voice Solutions, SaaS, PaaS, IaaS, SCCM and device/system patching, Building Automation Systems, SIEM (Splunk, CrowdStrike), network and endpoint security tools, firewalls (Palo Alto, Meraki, Cisco, Ruckus), Citrix, as well as WVD/Workspaces.
  • Competence in email security tools and flow (DKIM, DMARC)
  • Demonstrated history of providing compute and networking infrastructure to underpin business initiatives.
  • Ability to perform initial triage on security incidents.
  • Capable of supporting transient network challenges and making real-time decisions to maintain continual business operations, while promptly communicating issues.
  • Competence in tracking and reporting key performance indicators for network and cloud system availability.
  • Outstanding verbal and written communication skills, with the capacity to effectively convey information to non-technical audiences; strong persuasive abilities to gain trust across all organizational levels.
  • Effective at prioritizing, organizing, and communicating multiple projects of varying complexity, often under tight deadlines.
  • Able to excel both independently and as part of a team.
  • Willingness to adapt to change, quickly learn new software, and embrace emerging technologies.
  • OR any equivalent combination of education, training, and/or experience that fulfills the requirements of the position will be considered.

Nice To Haves

  • previous migration and transitional environment support are advantageous

Responsibilities

  • Design, deploy, and promote cloud security solutions for Azure and AWS platforms.
  • Manage identity and access controls for both on-premises and Azure environments using technologies like Azure Entra, Active Directory, internal PKI, Intune, NDES, MFA, PIM, Security Group Management, Group Policy, and Kerberos.
  • Possess strong knowledge of modern cloud and data center architectures, platforms, and their impact on business goals, and lead teams to quickly resolve incidents and outages.
  • Support all products within the functional area, from creation and deployment to ongoing performance, aligning with business, global infrastructure, and security requirements.
  • Oversee enterprise-level email security tools.
  • Manage, coordinate, and communicate with Security and IT Service providers to ensure services are being delivered and utilized appropriately.
  • Monitor and analyze security events and alerts from multiple sources, and respond to threats and vulnerabilities.
  • Script and automate processes using tools such as Python, PowerShell, and Bash.
  • Promote security awareness (e.g., phishing simulations) and best practices throughout the organization.
  • Investigate intrusion attempts, conduct thorough exploit analyses, and test defensive controls and response measures.
  • Collaborate with internal IT and other departments to deliver infrastructure and network solutions that support business growth and enhance tenant experiences.
  • Develop processes and comply with strict regulatory requirements for network operations.
  • Continuously evaluate and improve infrastructure to meet business needs, identify cost-saving opportunities, and further cloud adoption.

Benefits

  • annual performance bonus
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service