Cybersecurity Engineer
Cloud Platforms
Cloud Security Architecture
Cloud Security Posture Management
Data Security
Engineer
Identity and Access Management
Information Security
InfoSec
Network Security
Nist Cybersecurity Framework
Security
Security Architecture
Security Compliance
Security Operations
Security Standards
Solution Architecture
Vulnerability Management
Zero Trust Architecture
Job Description
The City of Chesapeake is seeking a Cybersecurity Engineer to help defend critical systems by designing secure architectures, strengthening the organization’s security posture, and supporting threat detection and incident response. This onsite role focuses on security governance across hybrid cloud, network, virtualization, and AI-related environments, with ongoing collaboration and documentation across teams.
Based in Chesapeake, VA, the position is salaried at USD 87,075 - 120,000 per year, with a minimum of 4 years of related, full-time equivalent experience.
Responsibilities
- Design, implement, and maintain enterprise security architectures covering hybrid cloud, virtualization, network infrastructure, and AI systems.
- Build Zero Trust security practices including micro-segmentation, least privilege, identity-driven access, and defense-in-depth controls.
- Create and maintain reference architectures, security standards, and architectural design documentation.
- Perform threat modeling and architectural risk assessments aligned with frameworks including NIST, CIS, ISO 27001, HIPAA, CJIS, and PCI.
- Define and govern security requirements for AI/ML platforms, data pipelines, and model interfaces.
- Implement controls to mitigate threats such as prompt injection, model theft, data poisoning, and unauthorized API access.
- Design secure Azure and AWS environments, including segmentation, identity integration, private access, and firewalling.
- Oversee cloud-native security controls including Azure Firewall, NSGs/ASGs, Security Groups, Network Firewall, CSPM, and secrets management.
- Provide security principles and oversight for firewalls, network devices, endpoint security/XDR, email security, SIEM telemetry, and vulnerability management.
- Coordinate penetration testing and drive remediation efforts.
- Define secure network design patterns for on-premises, hybrid, and cloud networks, including segmentation and perimeter architectures.
- Establish standards for firewall policies, TLS decryption, IPS, URL filtering, and SD-WAN/wireless security.
- Define secure configuration guidance for VMware/Hyper-V, virtual switches, hardened templates, and workload segmentation.
- Define secure configuration guidelines for Windows, Linux, IoT, OT, and SCADA environments.
- Define detection engineering requirements for SIEM/XDR and guide threat-hunting activities.
- Support incident response architecture, including forensics needs and containment strategies.
- Participate in risk assessments and define mitigation strategies.
- Support audit requirements, policy development, compliance documentation, and third-party risk reviews.
- Produce clear documentation, diagrams, and executive-level reports.
- Collaborate with networking, systems, cloud, and application teams on architectural reviews and implementation.
Requirements
- Bachelor’s degree (or equivalent) in computer science, cybersecurity, or a closely related field, or an equivalent combination of education and experience.
- Minimum of four years of related, full-time equivalent experience.
- Strong technical knowledge of IT infrastructure and vulnerability patch management preferred.
- Good knowledge of commercial compliance and regulatory standards, such as PCI and HIPAA.
- A valid driver’s license and a driving record compliant with City Driving Standards.
- Emergency operations support may be required, and work locations may be outside normal job duties.
- Employees may be expected to work hours beyond the scheduled hours in response to short-term departmental needs or City-wide emergencies.
Technology Focus
- NIST, CIS, ISO 27001, HIPAA, CJIS, PCI, Zero Trust, NIST CSF
- Azure, AWS, Azure Firewall, NSGs/ASGs, Security Groups, Network Firewall, CSPM, secrets management
- endpoint security/XDR, SIEM, SIEM telemetry, vulnerability management
- TLS decryption, IPS, URL filtering, SD-WAN, wireless security
- VMware, Hyper-V, virtual switches, Windows, Linux, IoT, OT, SCADA
- SIEM/XDR, AI/ML platforms, prompt injection, model theft, data poisoning, unauthorized API access
- micro-segmentation, identity-driven access, defense-in-depth controls
Posting Dates
- Open: 07/31/2026
- Close: 08/12/2026
Applicant Notes
- This position is not eligible for third-party placements (contractor/staffing agency). Questions can be sent to [email protected].
- Information Technology based positions must meet requirements specified in the Criminal Justice Information System (CJIS) policy for access to the Virginia Criminal Information Network (VCIN).
Work Environment and Physical Demands
- Primary work location: Office environment
- Overall physical strength demands: S (Sedentary), exerting up to 10 lbs occasionally or small weights frequently; sitting most of the time.
- Common movement: standing, sitting, and walking are each frequently within 1/3 to 2/3 of the time.
- Fine dexterity: continuously within 2/3 or more of the time.
- Vision, hearing, and talking: continuously within 2/3 or more of the time.
- Tools/equipment: computers and peripherals.