Cybersecurity Analyst V | Entp Information Security

Texas Attorney General

Austin (TX)

Hybrid

USD 120,000 - 180,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Benefits package

Job summary

The Office of the Attorney General’s Enterprise Information Security Team is hiring a Cybersecurity Engineer to design, implement, and operate enterprise security platforms, conduct risk assessments, and produce audit-ready evidence under NIST and CJIS frameworks. You will onboard telemetry sources, standardize parsing, and ensure regulated data (FTI, CJI, PHI) is protected.

Telework is permitted; strong engineering practices and collaboration with cloud, network, and application teams are

Qualifications

  • Graduation from high school or equivalent.
  • 10 years of full-time IT security experience with CIS, SIEM, or related areas.
  • Experience across public cloud, IAM, and audit-ready artifacts.
  • Ability to map platforms to SP 800-53 and implement Zero Trust concepts.

Responsibilities

  • Design, implement, and operate enterprise security platforms and controls.
  • Lead risk assessments, exposure management, and audit-ready evidence.
  • Provide Tier 3 escalation and cross-platform troubleshooting (Windows, Linux, networks).
  • Develop runbooks and automation using Python/PowerShell and vendor APIs.

Skills

Cloud security
Python/PowerShell
Git
SPL/KQL
AWS
Azure
Windows Server/AD
RHEL
Zero Trust

Education

High school diploma or equivalent

Tools

Zscaler
Proofpoint
Tenable One
Armis
Microsoft Purview
DataBahn
Swimlane

Job description

GENERAL DESCRIPTION

The Office of the Attorney General is a dynamic organization with employees across the State of Texas, providing legal representation, supporting statewide programs, and protecting critical information assets. The Enterprise Information Security Team delivers security services that safeguard agency systems, data, and operations by applying strong engineering practices and modern security controls.

The Cybersecurity Engineer performs advanced cybersecurity work as part of the Enterprise Information Security engineering group. The role focuses on designing, implementing, and operating enterprise security platforms; conducting technical risk assessments; supporting exposure management; and producing audit ready evidence aligned with state and federal requirements. Responsibilities include engineering and tuning security controls, analyzing threats and vulnerabilities, onboarding and normalizing telemetry, and ensuring regulated data (FTI, CJI, PHI) is protected according to required frameworks.

This position works under limited supervision with considerable latitude for initiative and independent judgment. The Cybersecurity Engineer serves as a subject matter expert for designated platforms, provides Tier 3 technical escalation, participates in architectural and change management processes, and collaborates with operations, cloud, network, and application teams. The role may lead and guide others and contributes to the development of enterprise security standards, reference architectures, and control documentation.

Join us in safeguarding Texas and shaping the future of cybersecurity governance! OAG employees enjoy excellent benefits (https://ers.texas.gov/Benefits-at-a-Glance) along with tremendous opportunities to do important work at a large, dynamic state agency making a positive difference in the lives of Texans.

ESSENTIAL POSITION FUNCTIONS
Engineering & Operations (~70%)
  • Stewardship and SME for Zscaler, Proofpoint, Tenable One, Armis, Microsoft Purview, DataBahn, and Swimlane or other similar products.
  • Design, operate, and tune policies, inspection, posture management, forwarding paths, and monitoring across supported platforms.
  • Lead scanning architecture, agent deployment, asset discovery/coverage, web application scanning, risk scoring, exceptions, and remediation reporting.
  • Drive unmanaged/IoT/OT visibility, device risk policy, rogue device alerting, and inventory reconciliation (Tenable, endpoints, Entra ID, CMDB).
  • Implement sensitivity labels, auto labeling, DLP, retention, insider risk, audit, and encryption controls for FTI/CJI/PHI and privileged work product.
  • Onboard telemetry sources; standardize parsing/normalization; route/tier events; redact/mask regulated data; set retention aligned to IRS Pub. 1075 and CJIS.
  • Develop and maintain SOAR playbooks/integrations with error handling and approval gates; ensure sanitized case records and complete audit trails.
  • Provide Tier 3 escalation, cross platform troubleshooting (Windows, Linux, network), and automation using Python/PowerShell and vendor APIs (in Git).
  • Author and maintain documentation and runbooks; participate in on call rotation; provide surge relief to SOC during incidents.
  • Maintain reference architectures and standards mapped to NIST SP 800-53 and Zero Trust.
  • Act as design authority for projects, applications, cloud workloads, and third‑party connections; document decisions and residual risk.
  • Define control boundaries and evidentiary requirements
  • Extend platforms across the multi‑cloud estate (predominantly AWS) for visibility, telemetry, identity, segmentation, and encryption.
  • Develop roadmaps; forecast capacity and licensing/consumption; lead product evaluations/POCs including privacy, TX RAMP/FEDRAMP, and compliance analysis.
  • Participate in architecture and change governance; author control narratives and evidence; mentor engineers and SOC analysts.
  • Regulatory & Government Sector Requirements
  • IRS Pub. 1075: apply safeguarding requirements; enforce need‑to‑know access; FIPS‑validated encryption; extended audit/logging/retention; support SSR preparation and incident notification duties; coordinate with Privacy Officer and Child Support Division.
  • FBI CJIS: implement policy areas (screening, authentication, access, audit, media protection, physical, mobile, incident response); coordinate with CSA/CSO/LASO; apply Security Addendum; design segmentation and logging for auditable boundaries.
  • NIST/State of Texas: map capabilities to SP 800‑53; apply SP 800‑207 Zero Trust and CSF 2.0; use SP 800‑61/63/88/171 and FIPS 140‑3/199/200; align with 1 TAC 202, DIR Standards Catalog, TX‑RAMP; meet Texas Government Code 2054; account for Public Information Act in retention; apply HIPAA safeguards where applicable.
  • Performs related work as assigned
  • Maintains relevant knowledge necessary to perform essential job functions
  • Attends work regularly in compliance with agreed‑upon work schedule. Telework schedules are permitted for employees based on the agency's approved Telework Plan, as long as schedule does not adversely affect operations and service levels, and standard hours of operation are maintained.
  • Ensures security and confidentiality of sensitive and/or protected information.
  • Complies with all agency policies and procedures, including those pertaining to ethics and integrity.
MINIMUM QUALIFICATIONS
  • Education: Graduation from high school or equivalent
  • Experience: Ten years of full‑time experience working in the following (or closely related) fields: information technology security, computer information systems, computer science, management information systems; may substitute credit hours from an accredited college or university for the required experience on a year‑for‑year basis.
  • Deep production ownership of three or more primary platforms (or market equivalents) with the ability to ramp up to the rest within 12 months.
  • Working capability across public cloud, firewalls, switching, identity provider, and at least one SIEM query language (SPL or KQL).
  • Government/public sector experience under IRS Pub. 1075/CJIS (or comparable regime); ability to map platforms to SP 800‑53 and produce audit‑ready artifacts; fluency in Zero Trust and CSF 2.0; familiarity with Texas frameworks and TX‑RAMP; disciplined handling of regulated data.
  • Technical foundations: production AWS (networking, IAM, encryption, logging/security services) with Azure familiarity; Windows Server/AD and RHEL troubleshooting; networking/protocol fundamentals; Python/PowerShell and vendor APIs; Git.
  • Knowledge of configuration management; change/problem management; risk assessment and acceptance; exception management; and security baselines (CIS, NIST, vendor STIGs).
  • Skills in configuring, deploying, monitoring, and automating security applications and infrastructure; auditing; risk management; advising management on security configuration; and performing routine assessments of security compliance and risk mitigation.
  • Abilities: obtain and maintain baseline certification (e.g., Security+); analyze facts and devise solutions; prepare reports; develop, evaluate, and interpret policies; communicate effectively; provide guidance to others; lead risk management function development and implementation.
  • Ability to work more than 40 hours as needed and in compliance with the FLSA.
  • Ability to occasionally lift and relocate up to 30 lbs.
  • Ability to travel (including overnight travel) up to 5%
PREFERRED QUALIFICATIONS
  • Certifications: (e.g., Zscaler, Tenable, Microsoft SC-series, Proofpoint, Armis, Swimlane); CISSP/CCSP/SABSA/TOGAF; GIAC; PCNSE/CCNP/Splunk Architect; AWS/Azure certifications; AWS Org governance/SCP/landing zone design; CSPM/CWPP at scale.
  • Experience securing OT/building automation/physical security/forensic lab equipment.
  • Experience designing and defending SSL/TLS inspection exception policies.
  • Experience establishing data classification programs for legal/investigative work product.
  • Practical experience using approved AI/LLM tooling within sanitized data guardrails.
  • Participation in regulatory assessments (IRS Safeguards review, CJIS audit, TX RAMP/StateRAMP/FedRAMP); telemetry redaction and data minimization.
  • Experience leading SIEM migration/log source consolidation/cost reduction; exposure management program with SLAs/exceptions/reporting.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

OAG - Entp Information Security | Cybersecurity Analyst V | 27-0034
OAG - Entp Information Security | Cybersecurity Analyst V | 27-0034

State of Texas • Town of Texas (WI)

On-site
USD 110,000 - 160,000
OAG - Child Support | Cybersecurity Engineer ( Cybersecurity Analyst IV ) | 27-0036
OAG - Child Support | Cybersecurity Engineer ( Cybersecurity Analyst IV ) | 27-0036

State of Texas • Town of Texas (WI)

On-site
USD 90,000 - 150,000
Chief Information Security Officer | Enterprise Information Security
Chief Information Security Officer | Enterprise Information Security

Texas Attorney General • Austin (TX)

On-site
USD 120,000 - 160,000
Excellent benefits
Opportunities for career growth
Positive work environment
Cybersecurity Analyst (Austin)
Cybersecurity Analyst (Austin)

Texas Workforce Commission • Austin (TX)

On-site
USD 108,000 - 132,000
Family Friendly
Competitive salary
Retirement plan
+4
Network Security Analyst
Network Security Analyst

ACS Consultancy Services • Austin (TX)

On-site
USD 100,000 - 150,000
Cybersecurity Operations Center Engineer
Cybersecurity Operations Center Engineer

FALL CREEK FARM & NURSERY • Austin (TX)

On-site
USD 78,000 - 132,000
100% paid employee health insurance
Defined benefit pension
Generous time off benefits
Cybersecurity Operations Center Engineer
Cybersecurity Operations Center Engineer

Texas Health and Human Services • Austin (TX)

On-site
USD 78,000 - 132,000
Health insurance
Pension plan
Time off
+1
Cybersecurity Operations Center Analyst
Cybersecurity Operations Center Analyst

FALL CREEK FARM & NURSERY • Austin (TX)

On-site
USD 78,000 - 132,000
Full health insurance
Defined benefit pension
Generous leave
Network Security Analyst
Network Security Analyst

TechTalenthunt • Austin (TX)

On-site
USD 120,000 - 160,000
Network Security Analyst 1
Network Security Analyst 1

My3tech • Austin (TX)

On-site
USD 60,000 - 90,000