Cyber Security Engineer in Stafford, Virginia at Stafford County
Explore Related Opportunities
Job Description
The Cyber Security Engineer performs advanced professional and technical work to protect the County’s information systems, Microsoft 365 environment, cloud services, endpoints, data, and digital assets. The position engineers, administers, and continuously improves cybersecurity capabilities with primary responsibility for Microsoft 365 security and compliance, security information and event management (SIEM), Intrusion Detection and Prevention Systems (IDS/IPS), vulnerability management, security monitoring, and incident response. Work includes integrating security technologies, analyzing risk and threats, maintaining security controls, supporting investigations, and ensuring alignment with County policies, regulatory requirements, and recognized cybersecurity practices. Work is performed under limited supervision.
The hiring range for this position is $96,720.00 to $132,995.20 annually based on experience.The full salary range for this position is $96,720.00 to $169,270.40 annually to provide opportunity for growth and development.
- Administers, configures, and continuously improves Microsoft 365 security, compliance, identity, endpoint, email, device, and data protection capabilities;
- Operates and enhances the County’s SIEM and security monitoring program, including log integration, detection development, alert tuning, dashboards, reporting, and response automation;
- Monitors, triages, investigates, and documents security alerts and incidents across cloud, endpoint, identity, email, application, and network environments;
- Coordinates cybersecurity incident response operations, including containment, eradication, recovery, evidence preservation, root-cause analysis, after-action review, and corrective actions;
- Manages the vulnerability management program, including asset coverage, scanning, validation, risk-based prioritization, remediation tracking, exceptions, and stakeholder reporting;
- Performs threat hunting and technical investigations using security telemetry, threat intelligence, and other available data sources;
- Evaluates security findings and control effectiveness, identifies gaps, and recommends practical risk-reduction measures;
- Works with infrastructure, application, cloud, and business teams to securely design, assess, and integrate systems, services, and data architectures;
- Creates and maintains cybersecurity standards, procedures, playbooks, diagrams, metrics, reports, and technical documentation;
- Supports audit, compliance, governance, risk management, security awareness, continuity, disaster recovery, and cybersecurity exercises by providing technical analysis and remediation support;
- Maintains knowledge of emerging threats, vulnerabilities, technologies, and industry practices and recommends improvements appropriate to County operations;
- Provides professional guidance, technical expertise, and security recommendations to staff, leadership vendors, and project teams;
- Participate in 24x7 on-call rotations;
- May be required to participate in after-hours incident response, maintenance, or emergency support operations;
- Performs related tasks as required.
- Comprehensive knowledge of cybersecurity engineering, security operations, cloud security, endpoint security, identity security, email security, data protection, and incident response principles;
- Strong working knowledge of Microsoft 365 security, compliance, identity, endpoint, device, email, and data protection administration;
- Thorough knowledge of SIEM technologies, log management, security analytics, detection development, alert tuning, and response automation concepts;
- Thorough knowledge of vulnerability management, risk-based remediation, configuration assessment, and security control validation;
- Knowledge of common attack techniques, threat vectors, malware behavior, identity compromise, phishing, and business email compromise;
- Knowledge of cybersecurity frameworks, audit, compliance, governance, and risk management practices applicable to local government environments;
- Skill in analyzing security events, correlating data from multiple sources, identifying root causes, and developing effective corrective actions;
- Skill in administering and integrating security platforms, cloud services, APIs, scripts, and automation tools;
- Strong written and verbal communication, interpersonal, customer service, documentation, and problem-solving skills;
- Ability to communicate technical security findings, risk, impact, and remediation guidance to technical and non-technical audiences;
- Ability to manage and prioritize multiple incidents, projects, remediation efforts, and competing deliverables;
- Ability to work on call as needed;
- Ability to work independently, exercise sound judgment, maintain confidentiality, learn new technologies, and establish effective working relationships.
Any combination of education and experience equivalent to a bachelor’s degree in information security, computer science, cyber security, or a related field, and 5 to 7 years of combined cyber security and/or information security experience. Qualifying experience should include several of the following areas: Microsoft 365 security administration, endpoint security, SIEM and security monitoring, vulnerability management, incident response, threat analysis, cloud security, identity security, security engineering, audit, compliance, risk management, or governance. Previous hands-on experience in a Security Analyst, Security Engineer, Cloud Security, or similar technical role is preferred. Experience supporting a public-sector, regulated, or enterprise environment and coordinating remediation across multiple technical teams is preferred.
SPECIAL REQUIREMENTS:
Possession of a driver's license valid in the Commonwealth of Virginia.
PHYSICAL REQUIREMENTS/WORK ENVIRONMENT:
This is light work requiring the exertion of up to 20 pounds of force occasionally, up to 10 pounds of force frequently, and a negligible amount of force constantly to move objects. Work requires sitting, bending, kneeling, crouching, crawling, and repetitive hand motions. Vocal communication is required for expressing or exchanging ideas by means of the spoken word. Hearing is required to perceive information at normal spoken word levels. Visual acuity is required for preparing and analyzing written or computer data, determining the accuracy and thoroughness of work, and observing general surroundings and activities. The worker is subject to inside and outside environmental conditions.