Stafford County Government is seeking an experienced Cyber Security Engineer to join our team and play a key role in strengthening the security and resilience of our technology environment.
This is a hands-on opportunity for a cybersecurity professional who enjoys solving complex problems, improving security capabilities, and turning emerging threats into practical defenses.
You’ll work across Microsoft 365 security and compliance, SIEM, vulnerability management, threat detection, incident response, cloud and endpoint security, and identity protection—while partnering with technical and business teams across the organization.
Beyond the technology, this role has a meaningful mission: protecting the systems, information, and digital services our employees and community rely on every day.
- Hiring Range: $96,720 – $132,995.20 annually, based on experience
- Full Salary Range: $96,720 – $169,270.40, providing opportunity for continued growth and development
Examples of Duties
- Administers, configures, and continuously improves Microsoft 365 security, compliance, identity, endpoint, email, device, and data protection capabilities;
- Operates and enhances the County’s SIEM and security monitoring program, including log integration, detection development, alert tuning, dashboards, reporting, and response automation;
- Monitors, triages, investigates, and documents security alerts and incidents across cloud, endpoint, identity, email, application, and network environments;
- Coordinates cybersecurity incident response operations, including containment, eradication, recovery, evidence preservation, root-cause analysis, after-action review, and corrective actions;
- Manages the vulnerability management program, including asset coverage, scanning, validation, risk-based prioritization, remediation tracking, exceptions, and stakeholder reporting;
- Performs threat hunting and technical investigations using security telemetry, threat intelligence, and other available data sources;
- Evaluates security findings and control effectiveness, identifies gaps, and recommends practical risk-reduction measures;
- Works with infrastructure, application, cloud, and business teams to securely design, assess, and integrate systems, services, and data architectures;
- Creates and maintains cybersecurity standards, procedures, playbooks, diagrams, metrics, reports, and technical documentation;
- Supports audit, compliance, governance, risk management, security awareness, continuity, disaster recovery, and cybersecurity exercises by providing technical analysis and remediation support;
- Maintains knowledge of emerging threats, vulnerabilities, technologies, and industry practices and recommends improvements appropriate to County operations;
- Provides professional guidance, technical expertise, and security recommendations to staff, leadership vendors, and project teams;
- Participate in 24x7 on-call rotations;
- May be required to participate in after-hours incident response, maintenance, or emergency support operations;
- Performs related tasks as required.
Knowledge, Skills and Abilities
- Comprehensive knowledge of cybersecurity engineering, security operations, cloud security, endpoint security, identity security, email security, data protection, and incident response principles;
- Strong working knowledge of Microsoft 365 security, compliance, identity, endpoint, device, email, and data protection administration;
- Thorough knowledge of SIEM technologies, log management, security analytics, detection development, alert tuning, and response automation concepts;
- Thorough knowledge of vulnerability management, risk-based remediation, configuration assessment, and security control validation;
- Knowledge of common attack techniques, threat vectors, malware behavior, identity compromise, phishing, and business email compromise;
- Knowledge of cybersecurity frameworks, audit, compliance, governance, and risk management practices applicable to local government environments;
- Skill in analyzing security events, correlating data from multiple sources, identifying root causes, and developing effective corrective actions;
- Skill in administering and integrating security platforms, cloud services, APIs, scripts, and automation tools;
- Strong written and verbal communication, interpersonal, customer service, documentation, and problem-solving skills;
- Ability to communicate technical security findings, risk, impact, and remediation guidance to technical and non-technical audiences;
- Ability to manage and prioritize multiple incidents, projects, remediation efforts, and competing deliverables;
- Ability to work on call as needed;
- Ability to work independently, exercise sound judgment, maintain confidentiality, learn new technologies, and establish effective working relationships.
Education and Experience
Any combination of education and experience equivalent to a bachelor’s degree in information security, computer science, cyber security, or a related field, and 5 to 7 years of combined cyber security and/or information security experience. Qualifying experience should include several of the following areas: Microsoft 365 security administration, endpoint security, SIEM and security monitoring, vulnerability management, incident response, threat analysis, cloud security, identity security, security engineering, audit, compliance, risk management, or governance. Previous hands-on experience in a Security Analyst, Security Engineer, Cloud Security, or similar technical role is preferred. Experience supporting a public-sector, regulated, or enterprise environment and coordinating remediation across multiple technical teams is preferred.
SPECIAL REQUIREMENTS:
Possession of a driver's license valid in the Commonwealth of Virginia.
PHYSICAL REQUIREMENTS/WORK ENVIRONMENT:
This is light work requiring the exertion of up to 20 pounds of force occasionally, up to 10 pounds of force frequently, and a negligible amount of force constantly to move objects. Work requires sitting, bending, kneeling, crouching, crawling, and repetitive hand motions. Vocal communication is required for expressing or exchanging ideas by means of the spoken word. Hearing is required to perceive information at normal spoken word levels. Visual acuity is required for preparing and analyzing written or computer data, determining the accuracy and thoroughness of work, and observing general surroundings and activities. The worker is subject to inside and outside environmental conditions.