Cyber Security Engineer
Job Description
City of Englewood is seeking a Cyber Security Engineer to support the protection and security of critical systems, data, and municipal water management environments.
Responsibilities
- Communicate complex security concepts, metrics, and findings clearly through verbal, written, and visual methods tailored to multiple leadership levels
- Partner with IT teams, business stakeholders, and internal/external partners to support cybersecurity, compliance, and digital accessibility initiatives
- Present cybersecurity status updates to the City Leadership Team to support understanding of security needs and investment decisions for enterprise systems
- Work with city wastewater and water distribution leaders to support compliance with water infrastructure security standards and regulatory requirements
- Develop and deliver cybersecurity awareness and training initiatives for users across the organization
- Act as a strategic liaison between IT divisions, leadership, and end users to evolve cybersecurity initiatives, procedures, and awareness culture
- Create long-term cybersecurity strategies and programs to address future security needs
- Lead special project teams and provide direction to technical staff on cybersecurity projects and training programs
- Perform risk assessments by tracking emerging threats and technologies, gathering input, and analyzing needs to build robust enterprise cybersecurity programs and support vendor selection recommendations
- Design and implement cybersecurity systems and software applications aligned to evolving cybersecurity needs
- Design, analyze, install, and maintain cybersecurity tools and systems
- Monitor the city’s network, servers, operating systems, and applications to detect and prevent threats and malicious activity using specialized tools and techniques
- Collaborate with business units to conduct security surveys and facilitate network scans to support compliance with security standards
- Support regulatory compliance and risk assessments to identify and mitigate compliance and cyber risks
- Assist with internal and external audits/assessments, including HIPAA, CJIS Policy, Digital Accessibility standards, and PII/privacy requirements
- Review and document external vendor security and compliance assessments and support cybersecurity purchasing requirements (including StateRAMP)
- Contribute to policies and standards that support cybersecurity and compliance activities aligned to organizational requirements
- Identify best practices for web page design, document formatting, and other requests to meet accessibility requirements
- Coordinate with IT Operations to support business continuity, disaster recovery, and incident response to prevent service interruptions and data loss from cyber events
- Participate in incident response activities including investigation, containment, and recovery as needed
- Create and maintain documentation for IT cybersecurity systems, tools, and procedures to support continuity and knowledge sharing
- Analyze system security, access, and authorization to ensure alignment with industry standards and regulatory requirements, and notify management of security issues and inappropriate usage violations
- Monitor user activities and administer training programs to remediate user compliance issues as necessary
- Develop cybersecurity reports based on monitoring and analysis findings
- Ensure compliance with personnel, security, and departmental procedures
- Perform other duties as assigned and required
Requirements
- Bachelor’s degree in IT, Computers Science, Business, or related field
- 5 years of progressive technical experience in an information technology field
- Minimum of 3 years of experience in information security, cybersecurity, or compliance-related work
- CJIS Certification
- CompTIA Security+
- CySA+ or Pentest+
- CISSP preferred
Technologies
- Python, SQL
- NIST, ISO 27001, CIS Critical Security Controls, NIST control documentation
- Risk Management Framework (RMF), IAVA reporting
- DevOps
- HIPAA, CJIS, PII, StateRAMP
- SIEM, IDS/IPS, firewalls, antivirus, vulnerability scanning tools
- TCP/IP, VLANs, VPNs, routing/switching
- Payment Card Industry (PCI)
Knowledge, Skills & Abilities
- Expert knowledge: modern anti-malware technologies; security scanning methods for computer/server/network hardware and software; server operating system and application tier security concepts and techniques; cybersecurity engineering, management, and administration
- Advanced knowledge: analyze vulnerability scanner and security posture management findings; NIST control documentation; RMF documentation; IAVA reporting; experience analyzing security and compliance audit findings; teamwork with DevOps; security libraries and frameworks; frontend/backend experience is a plus; Python and SQL are a plus
- Skills and abilities: advanced project coordination skills; collaboration and communication with stakeholders inside and outside direct reporting relationships; advanced written documentation and correspondence; advanced verbal communication to educate technical and non-technical audiences; analytical and problem-solving skills for security posture assessment, security program development, and improvement recommendations
Benefits
- Medical, Dental, and Vision Plans
- Retirement Plans
- Paid Time Off
- Paid Sick Leave
- 12 Paid Holidays
Compensation
- Salary range: USD 109,185 - 163,778 per year
Location & Reporting
- Location: Englewood, CO (onsite)
- Reports to: Director of Information Technology
- Direct reports: None
Application Deadline
Open until filled.
Working Conditions
- Encounters with hazardous conditions are listed as: Limited (less than 1% of time)
- Encounters with hazardous conditions are listed as: Infrequent (1-10% of time)
- Encounters with hazardous conditions are listed as: Seldom (10-25% of time)
- Encounters with hazardous conditions are listed as: Moderate (26-50% of time)
- Encounters with hazardous conditions are listed as: Frequent (greater than 50% of time)