IT Security Engineer

Howard Hughes Communities

4

(10)

The Woodlands, TX

Why you should apply for a job to Howard Hughes Communities:

  • 4/5 in overall job satisfaction
  • 4.5/5 in supportive management
  • 90% say women are treated fairly and equally to men
  • 70% would recommend this company to other women
  • 75% say the CEO supports gender diversity
  • Ratings are based on anonymous reviews by Fairygodboss members.
  • HHC will be offering 100% paid maternity leave benefits for a 12-week period.
  • HHC will be offering a Child Bonding benefit of four weeks per event for any births, adoption or child fostering for all genders.
  • The Howard Hughes Corporation's Employee Growth Program offers employees $10k a year as part of our growth and career funds.
  • #REQ5063

    Position summary

    teams to detect, prevent, and respond to security threats across the enterprise.

    What You Will Do

    Security Monitoring & Incident Response

    • Monitor networks, endpoints, and systems for security breaches using HHH's EDR solution and SIEM to detect intrusions and anomalous behavior.

    • Triage and investigate alerts, escalating and collaborating with the IT Security Lead as appropriate.

    • Lead hands‑on technical response for security incidents, including containment, eradication, and recovery activities, in coordination with the IT Security Lead and MDR partner.

    • Conduct or support technical and forensic investigations to determine root cause and scope of incidents.

    • Document and maintain incident response procedures, playbooks, and post‑incident lessons learned.

    • Continuously improve the Incident Response Plan and procedures to align with emerging threats and business needs.

    Security Assessments & Vulnerability Management

    • Perform network and system security assessments and audits to identify control gaps and weaknesses.

    • Organize and conduct vulnerability scans and testing (in coordination with relevant teams) to identify vulnerabilities across infrastructure and applications.

    • Conduct or coordinate penetration testing and simulate attacks to identify exploitable weaknesses.

    • Analyze and report results of scanning and testing, including risk ratings and remediation recommendations.

    • Partner with system owners to track, prioritize, and drive remediation of identified vulnerabilities within agreed SLAs.

    Security Architecture & Strategy Support

    • Support the IT Security Lead and senior security leadership in analyzing, designing, and maintaining security roadmaps and implementation plans.

    • Identify, define, and document system security requirements for new and existing solutions.

    • Recommend security solutions, patterns, and standards to management and project teams.

    • Implement, maintain, and monitor NIST‑aligned security controls to protect infrastructure and systems.

    • Create, modify, and maintain security and risk‑focused business intelligence dashboards and reports to support decision‑making.

    Security Tools & Infrastructure Support

    • Implement and manage security tools (including open‑source and third‑party solutions) that assist in detection, prevention, and analysis of security threats.

    • Review and help tune configurations for firewalls, data encryption, EDR, email security, and other security products to ensure alignment with standards and policies.

    • Review and evaluate email and other forms of communication for potential phishing, data loss, or other security risks.

    • Support and maintain security relevant hardware, software, and connectivity components within the network security framework.

    • Design and plan major security‑related upgrades and changes to ensure reliability, availability, and secure operations.

    Collaboration & Knowledge Sharing

    • Collaborate with IT engineers, systems administrators, application, and IT Governance, Risk, and Compliance teams to design secure technical solutions and processes.

    • Provide guidance to the application development team on secure coding standards and secure SDLC practices.

    • Conduct or support user awareness training on information security standards, policies, and best practices.

    • Share threat intelligence, incident trends, and control improvements with relevant stakeholders to increase overall security awareness.

    About You

    • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field; or 3-5 years of hands‑on experience in a dedicated IT Security or Cybersecurity role.

    • Experience working with EDR, SIEM, vulnerability management tools, and common enterprise security technologies.

    • Hands-on experience securing and monitoring enterprise cloud infrastructure, with a strong focus on Azure and AWS.

    • Strong preference for industry‑recognized certifications such as CISSP, CEH, ECIH, CySA+, Security+, SecurityX, CISM, or GCIH.

    • Proven track record in driving security remediations and lifecycle vulnerability management.

    • Experience conducting comprehensive third-party security reviews, evaluating SOC reports, and assessing data privacy risks.

    • In‑depth knowledge of cybersecurity principles, technologies, and best practices.

    • Strong understanding of regulatory and compliance requirements (e.g., NIST, SOX, privacy regulations) relevant to enterprise security.

    • Demonstrated ability to contribute effectively to a high‑performing cybersecurity team.

    • Ability to create, modify, and maintain business and security reporting dashboards.

    • Excellent interpersonal, verbal, and written communication skills, with the ability to translate technical issues into business terms.

    • Experience evaluating and mitigating security risks associated with AI.

    • Strong problem‑solving and critical‑thinking skills; able to exercise sound judgment without all information available.

    • Collaborative, self‑directed, and able to manage multiple competing priorities in a dynamic environment.

    • Curiosity about artificial intelligence and emerging technologies, with a strong desire to continuously learn and apply new tools to work more efficiently.

    • Ability to travel as business needs require.

    • Hybrid work schedule with 4 days on‑premise each week.

    • This job description is not intended to be an all‑inclusive list of the duties and responsibilities of this role. Other related duties and responsibilities may be assigned. The Company reserves the right to change or modify job duties as necessary based on business necessity.

    Benefits Built for You
    At Howard Hughes Communities, we offer competitive, market-based compensation that rewards performance and supports career growth. Our comprehensive benefits package designed to support employees at every stage of their career, is focused on holistic wellness-social, emotional, financial, and physical.

    • Competitive 401k plan

    • Generous PTO policy

    • Premium medical, dental, and vision coverage

    • Voluntary benefits for unexpected life events

    • Student loan assistance and stipends to assist with lifelong learning

    About Howard Hughes Communities

    Howard Hughes Communities develops, owns, and operates the nation's premier large-scale master planned communities and mixed-use developments. Our award-winning portfolio includes The Woodlands®, Bridgeland®, and The Woodlands Hills® in Greater Houston; Summerlin® in Las Vegas; Teravalis™ in Greater Phoenix; Ward Village® in Honolulu; and Merriweather District® in Columbia, Maryland. Strategically positioned to meet and accelerate development based on market demand, we offer one of the strongest real estate platforms in the country. Learn more at communities.howardhughes.com .

    NOTICE TO THIRD-PARTY AGENCIES
    Please note that Howard Hughes Communities does not accept unsolicited resumes from recruiters or employment agencies. In the absence of a signed Recruitment Fee Agreement, Howard Hughes Communities will not consider or agree to payment of any referral compensation or recruiter fee. In the event a recruiter or agency submits a resume or candidate without a previously signed agreement, Howard Hughes Communities explicitly reserves the right to pursue and hire those candidate(s) without any financial obligation to the recruiter or agency. Any unsolicited resumes, including those submitted to hiring managers, are deemed to be the property of Howard Hughes Communities.

    Why you should apply for a job to Howard Hughes Communities:

  • 4/5 in overall job satisfaction
  • 4.5/5 in supportive management
  • 90% say women are treated fairly and equally to men
  • 70% would recommend this company to other women
  • 75% say the CEO supports gender diversity
  • Ratings are based on anonymous reviews by Fairygodboss members.
  • HHC will be offering 100% paid maternity leave benefits for a 12-week period.
  • HHC will be offering a Child Bonding benefit of four weeks per event for any births, adoption or child fostering for all genders.
  • The Howard Hughes Corporation's Employee Growth Program offers employees $10k a year as part of our growth and career funds.