The Cybersecurity Engineeris responsible forsupporting the protection and security of critical systems and data related to the City’s technology infrastructure, business systems, and water management and distribution environments. The position works closely with Information Technology teams, City leadership, water and wastewater engineers, and other stakeholders to advise on, coordinate, and support the implementation of cybersecurity measures, monitor systems for vulnerabilities, and assist in incident response activities to help ensure the confidentiality, integrity and availability of City systems, data, and municipal water infrastructure.
The Cybersecurity Engineer supports the delivery of organizational goals by implementing andmaintainingthe Information Security and Compliance programs. This role ensures compliance targets are met by delivering secure technology services aligned with regulatory requirements, organizational risk appetite, established risk management practices, and evolving business needs.
The Cybersecurity Engineer collaborates closely with City leadership, Information Technology teams, and business stakeholders to share information, assess risk andidentify, evaluate, and implement solutions that support cybersecurity and complianceobjectives.
REPORTING RELATIONSHIPS
Reports to: Director of Information Technology
Direct Reports: None
ESSENTIAL DUTIES & RESPONSIBILITIES
The description below is intended torepresentonly the key areas of responsibilities; specific job assignments, duties, and environmental conditions will vary depending on the business need of the department and theorganization.
Relationship Management (20 % of time)
- Communicates complex information, concepts, and metrics in a confident and well-organized manner through verbal, written, and visual means, and tailored to the audience including to multiple levels of leadership.
- Collaborates with Information Technology and business teams, as well as other internal/external partners to build relationships supporting cybersecurity, compliance, and digital accessibility initiatives.
- Regularly presents to the City Leadership Team on the state ofcybersecurityto promoteanunderstandingcybersecurity needs and ensureleadership support for investments related to the security ofenterprise systems.
- Partners withcity wastewater and water distributionleaders to ensure compliance withappropriate waterinfrastructuresecurity standards and regulatory requirements.
- Developscybersecurity awareness and training initiativesfor usersacross the organization.
- Serves as the strategic liaison between ITdivisions, Leadership, and end userstofostera strong culture of cybersecurity awarenessto stay abreast of changing needs in the organizationand ensurecybersecurity initiatives and proceduresevolve with the organization.
Project Management (20% of time)
- Develops long term strategiesand programsfor meeting futurecybersecurity needs.
- Leads special projectsteams andprovides direction to technical staff onCybersecurity projectsand training programs.
- Conducts riskassessments bystaying informed about emerging cybersecurity threatsand technologies,gathering customer feedback,andanalyzing needstoidentifysolutionstodeveloprobustcybersecurityprogramsacross the enterprise platformandassistswithvendor selectionrecommendations.
- Designs and implements newcybersecuritysystems,and software applications to meet changingcybersecurityneedsin collaboration with other IT professionals and departments.
- Designs, analyzes, installs, andmaintainscybersecuritytools and systems.
Cybersecurity Analysis (55 % of time)
- Staysupdated on the latest security threats, technologies, and industry trends, and providesrecommendations for improving security posture.
- Using specialized tools and techniques,monitorsthe city’s network, servers, operating systems, and applicationstodetect and prevent cybersecurity threats and malicious activity.
- Collaborates with business units tocomplete security surveysandfacilitatesnetwork scans tomaintaincompliance with security standards.
- Assistswith regulatory compliance and risk assessments toidentifyand mitigate compliance and cyber risks.
- Assistswith various internal and external audits/assessments such as Health Insurance Portability and Accountability Act (HIPAA), Criminal Justice Information Services (CJIS) Policy, Digital Accessibility local and federal standards, Personal Identifiable Information (PII)and other related Privacy requirements.
- Reviews and documentsexternalvendorsecurity and compliance assessments as well as assistswithdevelopmentandadherence tocybersecurity purchasing requirements and platforms such asStateRAMP.
- Assistswith the development of policies, standards in support of cybersecurity and compliance activities, and aligned to company or organizational requirements.
- Assistswithidentifyingbest practices for Web page design, properly formatting documents, andother requests about how to meet accessibility requirements.
- Partners withthe IT Operations team todevelop and implementinitiatives tosupport business continuity, disaster recovery, and incident responseto prevent interruptions in services and data loss related tocyber events.
- Participatesin incident response activities, including investigation, containment, and recovery efforts, as needed.
- Creates andmaintainsdocumentation on ITcybersecuritysystems, tools,and procedures to ensurecontinuity ofcybersecurityoperations andtofacilitateknowledge sharing among IT staff members.
- Analyzessystem security, access, and authorization toensurethe city’s data and systemsadhere to industry standards and regulatory requirements.Provides management notification of security and inappropriate usage violations.
- Monitors user activities andadministerstraining programsto remediateuser complianceissuesas necessary.
- Develops and preparescybersecurityreports on findings frommonitoring andanalyses.
- Ensures compliance with personnel, security, and department procedures.
Additional duties as assigned (5%)
- Performs other duties as assigned andrequired.
EDUCATION
- Bachelor’s degreein IT, Computers Science,Businessor related field
An equivalent combination of education and relevant job experience may be substituted.
RELATED WORK EXPERIENCE
- 5yearsprogressive technicalexperiencein an information technology field, including a minimum of3yearsofexperienceininformation security,cybersecurity, or compliance related field.
An equivalent combination of education and relevant job experience may be substituted.
LICENSES, REGISTRATIONS, or CERTIFICATIONS
- CJIS Certification
- CompTIA Security+
- CySA+ or Pentest+
- Certified Information Systems Security Professional (CISSP)preferred.
KNOWLEDGE, SKILLS & ABILITIES
Expert Knowledge
- Modern Anti-Malware technologies
- Computer/Server/NetworkHardware and softwaresecurity scanningmethods and techniques.
- Server operating system and application tier security concepts and techniques.
- Theory, principles, practice, and methods ofcybersecurityengineering, management, and administration of information systems in the areas of systemssecurity.
Advanced Knowledge
- Analyze reports and findings from vulnerability scanners and security posture management tool
- NationalInstitute of Standards and Technology (NIST)control documentation
- Information Assurance Vulnerability Alert (IAVA)reporting
- Enterprise Serversand NetworkdevicesVulnerabilities
- Security and compliance audit findings analysis
- Experience working in teams using DevOps
- Experience witha variety ofmajorsecuritylibraries and frameworks
- Frontend and Backend experience is a plus
- Experience with Python is a plus
- Experience with SQL is a plus
Skills and Abilities
- Project Management Skills:Advanced skillsrequiredto coordinate system enhancement implementations andfacilitatecross-functional teams.
- Collaboration Skills:Communicationsregardinginterpretation of policies may be made after discussion of different points of view. Work may require providing advice to others outside direct reporting relationships on specific problems or general policies. Interactions with others outside the organization may be stressful, negative and requirehigh levelsof tact or persuasion to gain cooperation and acceptance of ideas.
- Communication Skill:Advanced skillsrequiredtoestablishand maintain effective working relations with customers, co-workers, staff, and vendors.Advanced written communication skillsrequiredforcomposing documentations and correspondence.Advanced verbal communication skillsrequiredto educate City users oncomplex security concepts to technical and non-technical stakeholders.Ability to organize andfacilitateplanning and demonstrations.Listens well and communicates effectively orally and in writing with various audiences.
- Computer Skills:Advanced skillsrequiredtoevaluateand enhance security foro variety of software-based packages ranging from operating systems to off-the-shelf software applications and databases.Advanced knowledge of computer network infrastructure toanalyzeandprovide guidance to improvesystemsecurityacrossthe enterprise environment.
- Analytical Skills: Advanced skillsrequiredtoanalyze current security posture,developa securityprogram,andproposesystem improvementsasappropriate basedon thetypes of data and the risktolerance of the various businessunits in the organization.Excellent analytical, problem-solving, and troubleshooting skills.
Preferred Qualifications
- Strong knowledge of security principles, best practices, and industry standards, such as NIST, ISO 27001, and CIS Critical Security Controls.
- Hands-on experience with security technologies, such as firewalls, IDS/IPS, SIEM, antivirus, and vulnerability scanning tools.
- Experience with risk assessment, penetration testing, and incident response methodologies.
- Strong understanding of networking concepts and protocols, such as TCP/IP, VLANs, VPNs, and routing/switching.
- Familiarity with security-related regulations, such asCriminal Justic Information Services(CJIS),HIPAA,andPayment Card Industry (PCI)requirements.
PHYSICAL EXERTION
Exerting up to 20 pounds of force occasionally, and/or up to 10 pounds of force frequently, and/or a negligible amount of force constantly to move objects.
WORKING CONDITIONS
Encounters with hazardous conditions (including electrical currents, heavy equipment, fumes, bodily fluids, extreme temperatures, threatening behaviors, inadequate lighting, restricted movement, or intense noise) is:
Limited (less than 1% of Time)
Seldom (10%-25% of Time)
Frequent (greater than 50% of Time)
Infrequent (1-10% of Time)
Moderate (26%-50% of Time)
SALARY RANGE
$109,185 - $163,778
BENEFITS
The City of Englewood offers a comprehensive benefits package including but not limited to:
- Medical, Dental, and Vision Plans
- Retirement Plans
- Paid Time Off
- 12 Paid Holidays
More information about our benefits can be found here
APPLICATION DEADLINE
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws.For further information, please review the Know Your Rights notice from the Department of Labor.