Employer Active
Job Alert
You will be updated with latest job alerts via emailJob Alert
You will be updated with latest job alerts via email$ 115000 - 157000
1 Vacancy
Systems Security Engineer I
Information Technology IT Operations
Denver Metro Area (Hybrid)
Exempt
The Systems Security Engineer is responsible for designing implementing and administering technology solutions that protect CHFAs diverse technology ecosystem including networks servers applications cloud platforms data and endpoints.
Reporting to the Manager of IT Operations this position requires advanced technical expertise in IT infrastructure and security practices. They will work closely with teammates on routine to complex assignments and act as an escalation point for advanced configuration or troubleshooting. The Systems Security Engineer collaborates daily with other teams including Information Security and Application Development to identify technology and security needs develop new solutions optimize or update existing systems and respond to incidents and requests to ensure the reliability performance and security of CHFAs IT environment.
Take a lead role in the design deployment configuration and administration of complex technology systems and procedures in support of CHFAs operational and security goals including firewalls EDR SASE PAM Enterprise DLP and IT Disaster Recovery.
Participate in the ongoing prevention and mitigation of emerging threats by evaluating and enhancing system configurations remediating vulnerabilities and improving alignment with cybersecurity best practices.
Collaborate with crossfunctional teams to assess needs evaluate solutions and implement secure technology systems and strategies. This includes a focus on supporting the Information Security team with designing deploying and optimizing securityfocused technologies and assisting them in event or incident responses.
Act as an escalation point for Help Desk Technicians Systems Administrators and Security Analysts for technical incidents and requests while sharing knowledge of contributing factors or response actions to continue to improve team performance and abilities.
Perform ongoing system management including evaluating firewall rule design and performance updating security policies in response to new products or features and participating in lifecycle management of servers and appliances.
Ensure new and existing systems conform to security benchmarks and best practices by evaluating configurations recommending improvements and implementing changes to improve or remediate configuration issues.
Participate in system administration tasks including updating patching and preventive maintenance of servers appliances or applications.
Maintain documentation of IT infrastructure and supported systems consisting of system diagrams equipment configurations and audit reports.
Stay current with emerging technologies trends and industry recommendations and promote corresponding solutions and updates across CHFAs technology ecosystem.
Coordinate with vendors and managed service providers for advanced technical expertise or assistance with technical tasks and projects as necessary.
Perform duties and participate in projects as directed by supervisors while contributing to all activities and projects that directly support CHFA in fulfilling its mission.
Proven experience as an Engineer or Administrator with expertise in firewalls encryption endpoint protection data protection intrusion detection systems antivirus software authentication systems log management content filtering and network admission control.
Strong knowledge of security best practices and frameworks (e.g. NIST SANS Azure WAF etc.
Indepth knowledge of the latest versions of operating systems (e.g. Windows 11/2025 virtualization and HCI technologies (e.g. Nutanix AHV Prism HyperV Azure Local) and cloud platforms (e.g. AWS Azure Cloudflare).
Possesses indepth knowledge of the full spectrum of security technologies with the ability to design and administer all components of complex systems such as firewalls (including rule engine SSL decryption advanced threat analysis features etc..
Familiarity with data protection and DR technologies and methodologies (e.g. snapshot BURA availability zones)
Knowledge of networking concepts including protocols subnetting zoning access control and monitoring.
Exemplary critical thinking and problemsolving skills applied at both design and troubleshooting stages.
Ability to conduct independent research and testing to support incident response system design infrastructure improvements and personal development.
Demonstrated ability to support and enhance the knowledge of coworkers through effective documentation crosstraining and communication.
Ability to manage time effectively ensure availability (including occasional nonstandard hours) prioritize work and adapt to evolving business system and security requirements.
Ability to establish rapport and communicate both orally and in writing in a positive diplomatic and friendly manner to users coworkers and the general staff who may be of a diverse ethnic racial or cultural background.
Palo Alto NGFW Wildfire Global Protect
SentinelOne Singularity
Cloudflare (DNS WAF SASE)
Intune Endpoint Privilege Management
Rapid7 and MS Sentinel SIEM
DLP (Purview Cloudflare Proofpoint)
Azure IaaS Sentinel IAM Defender
Entra ID PIM Conditional Access
Devolutions RDM PAM Gateway
Microsoft Windows IIS SQL Server
Active Directory GPOs Intune policies
Nutanix Cloud Infrastructure
Commvault Data Protection
Proofpoint Email Security
Microsoft Purview
Microsoft PKI
CIS benchmarks
5 years of experience in Administration or Engineer roles performing direct design implementation and administration of enterpriselevel systems infrastructure including direct handson experience with some or all of the described technologies or systems.
Degree in Information Systems Computer Science or related field or equivalent experience.
Relevant certifications including AZ500 AZ800 SC100 SC900 CISSP or the ability to obtain them preferred
personal computer mobile device and other rolespecific technologies
The incumbent in this position will perform the positions essential functions in a hybrid environment that requires sitting for extended periods at a desk. Must have sight and the ability to use a computer lift a computer (up to 30 lbs. and reach and bend for computer connections and disconnects with or without assisting devices. This position requires high levels of interaction and collaboration with others.
Internal candidates: Please apply internally via the job and career development page
External candidates: Please apply online at www.chfainfo Careers Tab.
This job description is a general description of essential job functions. It is not intended as an employment contract nor to describe all the duties someone in this position may perform.
Comprehensive medical dental and vision insurance plans with competitive rates
Generous Paid Time Off including paid volunteer time and leave programs.
Please visit our benefits page for additional information
$115000 $157000
Applications for this position are encouraged through April 19 2025 and will be accepted util the position is filled.
With respect to its programs services activities and employment practices Colorado Housing and Finance Authority prohibits unlawful discrimination against applicants or employees on the basis of age 40 years and over race sex sexual orientation gender identity gender expression color religion national origin disability military status genetic information marital status or any other status protected by applicable federal state or local law. Requests for reasonable accommodation the provision of auxiliary aids or any complaints alleging violation of this nondiscrimination policy should be directed to the nondiscrimination coordinator 1.800.877.2432 TDD/TTY 303.297.7305 CHFA 1981 Blake Street Denver COavailable weekdays 8:00 a.m. to 5:00 p.m.
#LIDNI
Full-Time