Answers in Genesis is seeking a Senior Cybersecurity Engineer to operate, administer, and continuously improve the ministry’s cybersecurity environment. This senior technical role protects endpoints, identities, networks, cloud services, applications, email, and security platforms through monitoring, secure configuration, vulnerability management, incident response, and ongoing control improvement. The position exercises independent technical judgment within assigned responsibilities, collaborates closely with IT and business stakeholders, and promptly communicates significant incidents, risks, findings, and recommended actions to management.
This position will allow one to impact others through a service mindset centered on making an eternal difference. This position should display our Core Values of SERVE (Serve, Equip, Relate, Value, Engage) when interfacing with both internal and external customers to ensure that the message and mission of Answers in Genesis is portrayed in an effective and God-honoring fashion. This position provides opportunities for spiritual, personal, and professional development.
Responsibilities
- Promote the mission and standards of Answers in Genesis.
- Create a SERVE culture environment in all work done.
- Approach all tasks with a second mile mindset.
- Prioritize personal integrity in all interactions and assignments.
- And all other duties and responsibilities assigned by management.
- Security Operations and Incident Response
- Monitor security events, systems logs, alerts, threat activity, and intelligence across the enterprise; maintain accurate tickets, investigation records, and support documentation.
- Investigate, contain, eradicate, and remediate cybersecurity incidents, including malware, ransomware, phishing, denial-of-service attacks, man-in-the-middle attacks, ARP spoofing, unauthorized access, compromised credentials, and other threats.
- Use MITRE ATTACK and related threat intelligence to understand attacker tactics, techniques, and produce, evaluate defensive coverage, and support post-incident corrective actions.
- Take timely operational action to protect ministry systems within assigned responsibilities and escalate significant incidents, risks, exceptions, or business-impacting changes to management.
- Vulnerability, Endpoint, and Identity Security
- Operate vulnerability scanning and assessment techniques; validate and prioritize findings based on severity, exploitability, system criticality, and organizational risk.
- Coordinate remediation with Infrastructure, Software Development, Helpdesk, application owners, and other responsible teams; track findings through remediation, mitigation, exception, or formal risk acceptance and verify completed fixes.
- Administer endpoint security, EDR/MDR, application/elevation/network control technologies such as ThreatLocker, and Mobile Device Management policies; monitor endpoint health, protection status, configuration, and compliance.
- Investigate endpoint incidents and perform or coordinate malicious-software removal across Windows, macOS, and Linux environments.
- Administer security controls in Active Directory and Microsoft Entra ID; review privileged access, authentication controls, account activity, and identity-related alerts; identify and remediate excessive, dormant, inappropriate, or potentially compromised access.
- Network, Cloud, and Application Security
- Administer Fortinet firewalls and related network-security technologies, including firewall rules, FortiNAC, secure remote access, intrusion detection/prevention, traffic monitoring, and at-risk device controls.
- Investigate suspicious network activity, troubleshoot network-security issues, and recommend improvements to network controls and configurations.
- Monitor and maintain security configurations in Microsoft 365, Azure, AWS, and other approved cloud platforms, including logging, identity activity, remote access, connectivity, cloud firewalls, and configuration changes.
- Identify cloud misconfigurations, support secure cloud projects and change, and coordinate remediation with Infrastructure and application teams.
- Monitor and respond to application and API security findings; administer Wallarm or equivalent protection technologies; partner with Software Development and application teams to remediate issues and support approved security tooling in the SDLC and CI/CD pipelines.
- Security Platform and Email Security
- Administer and maintain cybersecurity platforms, including ThreatLocker, Wallarm, IronScales, FortiGate, FortiAnalyzer, FortiNAC, Endpoint Central or equivalent, EDR/MDR, security logging and analysis platforms, and vulnerability-management technologies.
- Perform upgrades, patching, configuration changes, maintenance, troubleshooting, health monitoring, and license oversight for security technologies; maintain configuration records and operational procedures.
- Administer email security; investigate phishing, malicious messages, attachments, links, impersonation attempts, and business email compromise; assist with containment and remediation.
- Monitor and support SPF, DKIM, DMARC, mail flow, and related email-security controls; recommend improvements to email-security configurations and processes.
- Security Awareness, Governance, Reporting, and Collaboration
- Deliver cybersecurity awareness training, support phishing simulations and tabletop exercises, provide technical guidance, mentor IT personnel, and promote a security-conscious culture with Christ-like kindness, patience, and tact.
- Support governance, risk, compliance, internal/external assessments, audits, third-party reviews, and technical evidence collection for applicable requirements, including CIS Controls, PCI DSS, HIPAA, GDPR, CCPA, and other applicable privacy requirements.
- Perform technical security assessments and configuration reviews; implement or coordinate remediation arising from audits and assessments. Material organizational risk acceptance remains with management or the Vice President of IT.
- Produce cybersecurity operational metrics and reports covering vulnerability remediation, endpoint compliance, tool health, incident activity, and other assigned measures; identify recurring issues and recommend permanent corrective actions.
- Maintain accurate documentation of cybersecurity systems, procedures, investigations, recurring tasks, technical decisions, and exceptions; improve operational standards and reduce single points of failure through knowledge sharing.
- Coordinate work with Infrastructure, Software Development, Helpdesk, Enterprise Architecture, application owners, vendors, and other stakeholders; provide responsive support for cybersecurity-related tickets and operational needs.
Requirements
- Must agree with and be able to sign our Statement of Faith.
- Maintains a personal relationship with Jesus Christ.
- Regularly attends a local Bible-believing church.
- Demonstrate firmness in their walk with Christ and a passion for using technical skills for the glory of God; promote the mission, standards, and SERVE culture of Answers in Genesis.
- Demonstrate Christ-like professionalism, discretion, kindness, tact, strong customer service, and appropriate handling of confidential and sensitive information.
- Understand that cybersecurity must protect ministry operations while enabling organizational objectives; use speed, sound judgment, and intentionality without creating unnecessary impediments.
- Communicate technical risks and concepts effectively to technical and nontechnical audiences; anticipate and meet realistic deadlines; perform effectively under pressure and changing priorities; work independently and collaboratively.
- Preferred Qualifications
- Experience with several of the following technologies: FortiGate, FortiAnalyzer, FortiNAC, ThreatLocker, Wallarm, IronScales, Endpoint Central, Microsoft Defender technologies, Microsoft Entra ID, Active Directory, Microsoft 365, Azure, AWS, and EDR, MDR, SIEM, or comparable security platforms.
- Professional certifications such as CompTIA Security+, CompTIA CySA+, GIAC Security Essentials, GIAC Certified Intrusion Analyst, Cisco CCNP or equivalent networking certification, CISSP (preferred but not required), or other equivalent cybersecurity certifications.
Education & Experience
- Minimum five years of progressively responsible cybersecurity experience.
- At least five years of professional experience supporting, configuring, securing, and troubleshooting Microsoft Windows and macOS devices, plus experience supporting and securing Linux environments.
- In-depth understanding of TCP/IP, Layer 2 and Layer 3 networking, routing, switching, firewall administration, and log analysis.
- In-depth cloud and security knowledge involving Microsoft 365, Azure, AWS, or comparable platforms; experience administering Microsoft Entra ID and Active Directory.
- At least one year of experience with email security, anti-phishing technologies, mail flow, DKIM, SPF, and DMARC.
- Demonstrated experience investigating and removing malicious software from Windows, macOS, and Linux environments.
- At least two years of experience with FortiGate, FortiNAC, FortiAnalyzer, or comparable network-security technologies, and two or more years with vulnerability-management technologies and processes.
- Strong knowledge of threat actor tactics, techniques, procedures, offensive security tradecraft, MITRE ATT&CK, incident response, and the mapping of defensive controls to threat behaviors.
- Experience administering endpoints, identity, network, cloud, application, email, and security-monitoring technologies; experience coordinating cybersecurity work with other technical teams and delivering or supporting cybersecurity awareness training.
- Familiarity with common security, compliance, and privacy requirements, including CIS Controls and PCI DSS.
Items Needed for Possible Employment
- Completion of on-line application, https://answersingenesis.org
- Salary Requirements
- Salvation Testimony
- Creation Belief Statement
- Confirmation of your agreement with the AiG Statement of Faith (AiG Statement of Faith can be found on the website). https://answersingenesis.org/about/faith/
- Completion of a Background Check and Pre-Employment Drug Screen
Skills Required
- Agree to and sign the Answers in Genesis Statement of Faith
- Maintain a personal relationship with Jesus Christ
- Regularly attend a local Bible-believing church
- Demonstrate a firm Christian faith and commitment to the organization's mission and SERVE culture
- Demonstrate professionalism, discretion, kindness, tact, customer service, and appropriate handling of confidential information
- Communicate technical risks effectively to technical and nontechnical audiences
- Work independently and collaboratively under pressure and changing priorities
- Minimum five years of progressively responsible cybersecurity experience
- At least five years supporting, configuring, securing, and troubleshooting Windows and macOS devices, plus Linux experience
- In-depth knowledge of TCP/IP, Layer 2 and Layer 3 networking, routing, switching, firewall administration, and log analysis
- In-depth cloud and security knowledge involving Microsoft 365, Azure, AWS, or comparable platforms
- Experience administering Microsoft Entra ID and Active Directory
- At least one year of experience with email security, anti-phishing technologies, mail flow, DKIM, SPF, and DMARC
- Experience investigating and removing malicious software from Windows, macOS, and Linux environments
- At least two years of experience with FortiGate, FortiNAC, FortiAnalyzer, or comparable network-security technologies
- At least two years of experience with vulnerability-management technologies and processes
- Strong knowledge of threat actor tactics, techniques, procedures, offensive security tradecraft, MITRE ATT&CK, and incident response
- Experience administering endpoint, identity, network, cloud, application, email, and security-monitoring technologies
- Experience coordinating cybersecurity work with technical teams and supporting cybersecurity awareness training
- Familiarity with CIS Controls and PCI DSS
- Experience with FortiGate, FortiAnalyzer, FortiNAC, ThreatLocker, Wallarm, IronScales, Endpoint Central, Microsoft Defender, Microsoft Entra ID, Active Directory, Microsoft 365, Azure, AWS, EDR, MDR, SIEM, or comparable platforms
- Professional cybersecurity certifications such as CompTIA Security+, CompTIA CySA+, GIAC Security Essentials, GIAC Certified Intrusion Analyst, Cisco CCNP, CISSP, or equivalent
What We Do
Answers in Genesis is an apologetics ministry dedicated to helping Christians defend their faith and proclaim the good news of Jesus Christ. The organization also operates attractions such as the Creation Museum and the Ark Encounter.



.png)




