
Cybersecurity Engineer
American Museum of Natural History
- New York City, NY
- $70,000-77,000 per year
- Permanent
- Full-time
- Maintain and operate the Museum's information security infrastructure, including, but not limited to: network and host-based security platforms, vulnerability scanning systems and tools, intrusion detection/prevention systems (IDS/IPS), file integrity verification and monitoring software, security information and event management (SIEM) platform, application (Layer 7) firewall, network access control (NAC), data loss prevention (DLP), log indexing and correlation platform, anti-virus and anti-spyware console, firewall and network access controls lists and web and email proxy and filtering systems.
- Review and correlate data from various system reports, alerts and logs, as well as industry and partner alerts to identify potential risks and direct threats to the Museum's infrastructure, services and users. Initiate responses to such alerts consistent with establish operational standards and Museum policy and procedures.
- Identify and complete effective response mitigations in response to detected threats.
- Assist with vulnerabilities and risk analyses of existing and planned systems for a diverse clientele including scientific researchers, educational professionals, exhibit designers, administrative support staff and collaborators. Assist with digital forensics examinations, including malware analysis, using a variety of tools. Support incident response (IR) functions in keeping with existing policies, protocols and procedures.
- Continuously maintain an in-depth knowledge of the rapidly changing cybersecurity landscape by synthesizing information about cybersecurity from various sources including Homeland Security, CERT, media vendors and research organizations. Use that knowledge to spot potential risks to the Museum.
- Participate in weekly off-hours (non-office hours) maintenance windows.
- Participate in weekly on-call rotation to respond to and triage cybersecurity alerts.
- Maintain a schedule that includes after-hours deployment/maintenance and 24/7 emergency response to IT infrastructure service disruptions and cybersecurity threats.
Minimum Qualifications
- High School Diploma or equivalent.
- Two years of relevant direct IT experience.
- Experience, knowledge and comfort working in a heterogeneous IT infrastructure environment, with various IT systems, technologies, platforms, concepts and applications, including Windows, Unix, Linux, VMware, Oracle, SQL Server, MySQL, Active Directory, OpenLDAP and Cisco networking platforms.
- Proficiency in the development of software code, scripts and automations.
- Solid understanding of the latest security principles, techniques and protocols.
- Demonstrated ability to analyze, troubleshoot and investigate information technology issues.
- Functional knowledge of cloud services and technologies.
- College degree in information technology, cybersecurity or another related field.
- Training in cybersecurity methods (including, but not limited to incident response, forensics, cybersecurity operations) that provides a basic knowledge of the data security compliance regulations and information security controls needed to mitigate cyber threats and vulnerabilities of applications, databases and infrastructure platforms.
- Three years direct work experience in information security, information security compliance, incident response, digital forensics and/or associated fields.
- Experience in building and maintaining security systems, including firewalls, intrusion prevention systems, SIEM tools, vulnerability analysis systems, file integrity monitoring tools, data loss prevention, network access control, logging and correlation platforms and endpoint protection systems.
- Proficiency in the development of software code, scripts and automations of cybersecurity services.
- Ability to analyze, troubleshoot and investigate security-related information systems anomalies based on security platform reporting, network traffic, log files and host-based and automated security alerts.
- Must be able to remain in a stationary position (sitting or standing) for prolonged periods.
- Must be able to occasionally lift up to 20 pounds.
- Must be able to move about the Museum campus.
- Positioning/change of positioning: Must be able to frequently position oneself/body to accomplish job duties.
Total Number of Scheduled Hours Per Pay Period 70
Union Status Non-Union
FLSA Exempt
Expected Salary Minimum $70,000/annual
Expected Salary Maximum $77,000/annual
EEO StatementThe American Museum of Natural History is an Equal Opportunity/Affirmative Action Employer. The Museum does not discriminate with respect to employment, or admission or access to Museum facilities, programs or activities on the basis of race, creed, color, religion, age, disability, marital status, partnership status, gender (including sexual harassment), sex, sexual orientation, gender identity, gender expression, genetic information, pregnancy and lactation accommodations, alienage or citizenship status, current or former participation in the uniformed services, status as a veteran, caregiver, pre-employment marijuana testing, sexual and reproductive health decisions, salary history, national or ethnic origin, height, weight, or on account of any other basis prohibited by applicable City, State, or Federal law. Additional protections are afforded in employment based on arrest or conviction record, status as a victim of domestic violence, stalking and sex offenses, unemployment status, and credit history, in each case to the extent provided by law.
Quick LinkPosting Detail InformationPosting Number GS894P
Open Date 07/08/2025
Close Date
Open Until Filled Yes
Special Instructions to ApplicantsSupplemental QuestionsRequired fields are indicated with an asterisk (*). * * Do you have a High School Diploma or GED?
- Yes
- No
- * Do you have two years of relevant direct IT experience?
- Yes
- No
- * Are you proficient in developing software code, scripts and automations?
- Yes
- No
- * Do you have experience with, knowledge of and feel comfortable with working in a heterogeneous IT infrastructure environment, with various IT systems, technologies, platforms, concepts and applications, including Windows, Unix, Linux, VMware, Oracle, SQL Server, MySQL, Active Directory, OpenLDAP and Cisco networking platforms?
- Yes
- No
- * Do you have a solid understanding of the latest security principles, techniques and protocols?
- Yes
- No
- * Are you able to analyze, troubleshoot and investigate information technology issues?
- Yes
- No
- * Do you have a functional knowledge of cloud services and technologies?
- Yes
- No
- * Can you maintain availability to participate in weekly off-hours (non-office hours) maintenance windows?
- Yes
- No
- * Can you maintain availability to participate in a weekly on-call rotation to respond to and triage cybersecurity alerts?
- Yes
- No
- * Can you maintain availability to include after-hours deployment/maintenance and 24/7 emergency response to IT infrastructure service disruptions and cybersecurity threats?
- Yes
- No
- Cover Letter
200 Central Park West
New York, NY 10024-5192
Phone: 212-769-5100Open daily, 10am - 5:30pmEmployment FAQ's
Have questions about the application process?
Review the .
No Surprise Billing Act Disclosure is available at ,To ensure the security of your data, you will be logged out due to inactivity in 3 minutes at