Cyber Security Engineer
Job Description
Stafford County, VA is seeking a Cyber Security Engineer to perform advanced professional and technical work protecting the County’s information systems and digital assets. The position focuses on strengthening cybersecurity capabilities across Microsoft 365 security and compliance, SIEM and security monitoring, IDS/IPS, vulnerability management, and incident response, with coordination of risk reduction activities under limited supervision.
Role and focus
This role engineers, administers, and continuously improves cybersecurity controls for Microsoft 365 security and compliance, security information and event management (SIEM), intrusion detection and prevention systems (IDS/IPS), vulnerability management, security monitoring, and incident response. Work includes integrating security technologies, analyzing risk and threats, supporting investigations, and ensuring alignment with County policies, regulatory requirements, and recognized cybersecurity practices.
Key responsibilities
- Administer, configure, and continuously improve Microsoft 365 security, compliance, identity, endpoint, email, device, and data protection capabilities.
- Operate and enhance the County’s SIEM and security monitoring program, including log integration, detection development, alert tuning, dashboards, reporting, and response automation.
- Monitor, triage, investigate, and document security alerts and incidents across cloud, endpoint, identity, email, application, and network environments.
- Coordinate cybersecurity incident response operations, including containment, eradication, recovery, evidence preservation, root-cause analysis, after-action review, and corrective actions.
- Manage the vulnerability management program, including asset coverage, scanning, validation, risk-based prioritization, remediation tracking, exceptions, and stakeholder reporting.
- Conduct threat hunting and technical investigations using security telemetry, threat intelligence, and other available data sources.
- Evaluate security findings and control effectiveness, identify gaps, and recommend practical risk-reduction measures.
- Work with infrastructure, application, cloud, and business teams to securely design, assess, and integrate systems, services, and data architectures.
- Create and maintain cybersecurity standards, procedures, playbooks, diagrams, metrics, reports, and technical documentation.
- Support audit, compliance, governance, risk management, security awareness, continuity, disaster recovery, and cybersecurity exercises by providing technical analysis and remediation support.
- Maintain knowledge of emerging threats, vulnerabilities, technologies, and industry practices and recommend improvements appropriate to County operations.
- Provide professional guidance, technical expertise, and security recommendations to staff, leadership, vendors, and project teams.
- Participate in 24x7 on-call rotations, and may be required to support after-hours incident response, maintenance, or emergency operations.
- Perform related tasks as required.
Minimum qualifications
- Comprehensive knowledge of cybersecurity engineering, security operations, cloud security, endpoint security, identity security, email security, data protection, and incident response principles.
- Strong working knowledge of Microsoft 365 security, compliance, identity, endpoint, device, email, and data protection administration.
- Thorough knowledge of SIEM technologies, log management, security analytics, detection development, alert tuning, and response automation concepts.
- Thorough knowledge of vulnerability management, risk-based remediation, configuration assessment, and security control validation.
- Knowledge of common attack techniques, threat vectors, malware behavior, identity compromise, phishing, and business email compromise.
- Knowledge of cybersecurity frameworks, audit, compliance, governance, and risk management practices applicable to local government environments.
- Skill in analyzing security events, correlating data from multiple sources, identifying root causes, and developing effective corrective actions.
- Skill in administering and integrating security platforms, cloud services, APIs, scripts, and automation tools.
- Strong written and verbal communication, interpersonal, customer service, documentation, and problem-solving skills.
- Ability to communicate technical security findings, risk, impact, and remediation guidance to technical and non-technical audiences.
- Ability to manage and prioritize multiple incidents, projects, remediation efforts, and competing deliverables.
- Ability to work on call as needed, work independently, exercise sound judgment, maintain confidentiality, learn new technologies, and establish effective working relationships.
- Any combination of education and experience equivalent to a bachelor’s degree in information security, computer science, cyber security, or a related field, and 5 to 7 years of combined cyber security and/or information security experience.
- Possession of a driver’s license valid in the Commonwealth of Virginia.
Education
A bachelor’s degree in information security, computer science, cyber security, or a related field.
Technologies
- Microsoft 365
- SIEM
- Intrusion Detection and Prevention Systems (IDS/IPS)
- Cloud services
- Microsoft 365 security and compliance
- Security information and event management (SIEM)
- Vulnerability management
- Security monitoring
- Incident response
Location and salary
Location: Stafford County, VA (onsite). Compensation: USD 96,720 to 169,270 per year. The hiring range is USD 96,720.00 to USD 132,995.20 annually based on experience, with a full salary range of USD 96,720.00 to USD 169,270.40 annually to provide opportunity for growth and development.
Work environment
- Light work requiring up to 20 pounds of force occasionally, up to 10 pounds of force frequently, and a negligible amount of force constantly.
- Requires sitting, bending, kneeling, crouching, crawling, and repetitive hand motions.
- Vocal communication required; hearing required at normal spoken word levels.
- Visual acuity required for preparing and analyzing written or computer data and observing general surroundings and activities.
- Subject to inside and outside environmental conditions.
Notes
- Employees are required to have direct deposit of bi-weekly paychecks into one or more financial institutions of their choice, with information provided at time of hire.
- Proper identification must be shown at time of hire to complete required paperwork for compliance with the Immigration Control and Reform Act of 1986.