This is a professional technical position responsible for protecting the City’s information technology (IT) and operational technology (OT) systems, including on-premises, cloud, and endpoint platforms. This position monitors security threats, investigates and responds to cybersecurity events, supports vulnerability management and risk mitigation, and helps maintain and improve enterprise cybersecurity systems and programs. Works collaboratively with IT staff and stakeholders to reduce cybersecurity risk while supporting reliable service delivery. This is an in-office position; work at home is not available.
Cybersecurity Analysis, Detection, and Response
- Monitor enterprise systems and environments (including network, endpoint, and cloud) for security anomalies, intrusions, or breaches using tools such as SIEM, EDR/XDR, NAC, IDPS, and related technologies.
- Investigate security alerts, identify indicators of compromise (IOCs), and follow documented procedures to respond to cybersecurity events.
- Escalate complex incidents as appropriate and collaborate with the IT staff.
- Analyze vendors and government threat intelligence (e.g., CISA, MS-ISAC, IACI-CERT) to identify relevant risks and communicate findings to stakeholders.
- Prepare incident, investigation, and root cause analysis reports in accordance with established standards.
- Recommend detection improvements, support automation of response workflows, and lead initial incident handling.
- Create and maintain metrics, perform analysis (event, incident, risk, behavioral, trend), generate regular and on-demand ad-hoc reports to support operations and decision‑making.
Cybersecurity Vulnerability and Threat Mitigation
- Perform vulnerability assessments and security analysis of systems and endpoints.
- Prioritize and track remediation activities using risk‑based approaches.
- Verify compliance with cybersecurity baselines, standards, and policies.
- Apply or coordinate security patching to mitigate vulnerabilities while minimizing business impact.
- Conduct audits of access controls and sensitive data handling to ensure least privilege, proper classification, and encryption.
- Contribute to secure configuration baselines and oversee vulnerability management efforts.
IT Security System and Program Administration
- Configure and maintain cybersecurity systems such as firewalls, email gateways, and security monitoring tools according to established guidelines.
- Support and resolve cybersecurity‑related issues escalated from the Help Desk, including access, authentication, filtering, and security events.
- Administer or support Identity and Access Management (IAM), including authentication services and certificate management.
- Create and maintain cybersecurity documentation, procedures, and standards.
- Support the cybersecurity awareness program, including training and phishing assessments
ADDITIONAL RESPONSIBILITIES:
This position is part of the City’s Emergency Management Team and, as such, shall be expected to perform all duties that are assigned during an emergency management operation. Any additional compensation, above the normal weekly salary, shall be outlined by the City Manager in the City’s Emergency Management Activation and Emergency Declaration. Failure to appear to perform emergency management assignment and to work assigned shifts as scheduled by the City’s Emergency Management Director or individuals designated by the City Manager to assign such functions will result in disciplinary action up to and including termination.
- Bachelor’s degree in computer science, Information Systems, Cybersecurity or related field is required.
- Minimum of three (3) years’ experience in technology support, security operations, incident response, and/or event handling.
- Minimum of three (3) years of experience with security products including: IPS/IDS, AV, Anti‑Malware, DLP, MFA, Network Proxies, Sensitive Data Scanning, and Content Filtering is preferred.
- Knowledge of computer hardware, networking, operating systems (Windows and Linux), and enterprise IT infrastructure.
- Understanding of network technologies includes routing, switching, DNS, SMTP, NTP, and SNMP.
- Experience with enterprise security tools such as SIEM, EDR/XDR, firewalls, email gateways, and vulnerability management platforms.
- Knowledge of security considerations in hybrid and cloud environments (e.g., AWS, Azure, Microsoft 365).
- Ability to analyze security events, assess risk, and recommend mitigations.
- Strong analytical, troubleshooting, and problem‑solving skills.
- Ability to clearly document findings and communicate technical information verbally and in writing.
- Willingness and ability to continuously learn and apply new technologies.
- Demonstrated ability to mentor others, lead incident response efforts, and contribute to secure system design and automation.