Find Jobs
Find Jobs Near You – Available Work in Your Location
Skip to job details
SC
Stafford County
Cyber Security Engineer
Career Insights for Cyber Security Engineer
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Virginia data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Cyber Security Engineer designs systems that protect the security of large databases, including databases with customer information and patient files. Examines client computer systems, identifies weak points in security, develops and implements new systems, monitors and responds to security issues.
$113,393 / year median in Virginia
-3% projected decline
Job Description
The Cyber Security Engineer performs advanced professional and technical work to protect the County's information systems, Microsoft 365 environment, cloud services, endpoints, data, and digital assets. The position engineers, administers, and continuously improves cybersecurity capabilities with primary responsibility for Microsoft 365 security and compliance, security information and event management (SIEM), Intrusion Detection and Prevention Systems (IDS/IPS), vulnerability management, security monitoring, and incident response. Work includes integrating security technologies, analyzing risk and threats, maintaining security controls, supporting investigations, and ensuring alignment with County policies, regulatory requirements, and recognized cybersecurity practices. Work is performed under limited supervision. The hiring range for this position is $96,720.00 to $132,995.20 annually based on experience. The full salary range for this position is $96,720.00 to $169,270.40 annually to provide opportunity for growth and development. Administers, configures, and continuously improves Microsoft 365 security, compliance, identity, endpoint, email, device, and data protection capabilities; Operates and enhances the County's SIEM and security monitoring program, including log integration, detection development, alert tuning, dashboards, reporting, and response automation; Monitors, triages, investigates, and documents security alerts and incidents across cloud, endpoint, identity, email, application, and network environments; Coordinates cybersecurity incident response operations, including containment, eradication, recovery, evidence preservation, root-cause analysis, after-action review, and corrective actions; Manages the vulnerability management program, including asset coverage, scanning, validation, risk-based prioritization, remediation tracking, exceptions, and stakeholder reporting; Performs threat hunting and technical investigations using security telemetry, threat intelligence, and other available data sources; Evaluates security findings and control effectiveness, identifies gaps, and recommends practical risk-reduction measures; Works with infrastructure, application, cloud, and business teams to securely design, assess, and integrate systems, services, and data architectures; Creates and maintains cybersecurity standards, procedures, playbooks, diagrams, metrics, reports, and technical documentation; Supports audit, compliance, governance, risk management, security awareness, continuity, disaster recovery, and cybersecurity exercises by providing technical analysis and remediation support; Maintains knowledge of emerging threats, vulnerabilities, technologies, and industry practices and recommends improvements appropriate to County operations; Provides professional guidance, technical expertise, and security recommendations to staff, leadership vendors, and project teams; Participate in 24x7 on-call rotations; May be required to participate in after-hours incident response, maintenance, or emergency support operations; Performs related tasks as required. Comprehensive knowledge of cybersecurity engineering, security operations, cloud security, endpoint security, identity security, email security, data protection, and incident response principles; Strong working knowledge of Microsoft 365 security, compliance, identity, endpoint, device, email, and data protection administration; Thorough knowledge of SIEM technologies, log management, security analytics, detection development, alert tuning, and response automation concepts; Thorough knowledge of vulnerability management, risk-based remediation, configuration assessment, and security control validation; Knowledge of common attack techniques, threat vectors, malware behavior, identity compromise, phishing, and business email compromise; Knowledge of cybersecurity frameworks, audit, compliance, governance, and risk management practices applicable to local government environments; Skill in analyzing security events, correlating data from multiple sources, identifying root causes, and developing effective corrective actions; Skill in administering and integrating security platforms, cloud services, APIs, scripts, and automation tools; Strong written and verbal communication, interpersonal, customer service, documentation, and problem-solving skills; Ability to communicate technical security findings, risk, impact, and remediation guidance to technical and non-technical audiences; Ability to manage and prioritize multiple incidents, projects, remediation efforts, and competing deliverables; Ability to work on call as needed; Ability to work independently, exercise sound judgment, maintain confidentiality, learn new technologies, and establish effective working relationships. Any combination of education and experience equivalent to a bachelor's degree in information security, computer science, cyber security, or a related field, and 5 to 7 years of combined cyber security and/or information security experience. Qualifying experience should include several of the following areas: Microsoft 365 security administration, endpoint security, SIEM and security monitoring, vulnerability management, incident response, threat analysis, cloud security, identity security, security engineering, audit, compliance, risk management, or governance. Previous hands-on experience in a Security Analyst, Security Engineer, Cloud Security, or similar technical role is preferred. Experience supporting a public-sector, regulated, or enterprise environment and coordinating remediation across multiple technical teams is preferred.