EngineerJobs.io
← Back to all jobs

Job Description

The City of Englewood is seeking a Cybersecurity Engineer to help safeguard critical systems and data that support city technology infrastructure, business systems, and water management and distribution environments. In this onsite role in Englewood, CO, you will support information security and compliance programs by monitoring for vulnerabilities, assisting with incident response, and aligning cybersecurity efforts with regulatory and organizational objectives.

Working closely with Information Technology teams, City leadership, and water and wastewater stakeholders, this position helps ensure cybersecurity controls evolve with changing needs while supporting a culture of security awareness across the organization.

Role & Summary

  • Protect the confidentiality, integrity, and availability of City systems, data, and municipal water infrastructure.
  • Implement and maintain the organization’s Information Security and Compliance programs.
  • Monitor technology environments for vulnerabilities and malicious activity, and assist with incident investigation, containment, and recovery as needed.
  • Support regulatory compliance and risk assessments to identify and mitigate cyber and compliance risks.
  • Collaborate with stakeholders to share information, assess risk, and help evaluate and implement cybersecurity solutions.

Key Responsibilities

  • Communicate complex cybersecurity concepts, metrics, and reporting in organized formats tailored to multiple leadership levels.
  • Collaborate with Information Technology, business teams, and internal and external partners to support cybersecurity, compliance, and digital accessibility initiatives.
  • Provide regular updates to the City Leadership Team on the state of cybersecurity to support investment decisions related to enterprise system security.
  • Partner with city wastewater and water distribution leaders to ensure compliance with water infrastructure security standards and regulatory requirements.
  • Develop cybersecurity awareness and training initiatives for users across the organization, and administer training programs to remediate user compliance issues as necessary.
  • Serve as a strategic liaison between IT divisions, leadership, and end users to keep cybersecurity initiatives aligned with evolving needs.
  • Develop long-term strategies and programs to meet future cybersecurity needs.
  • Lead special project teams and provide direction to technical staff on cybersecurity projects and training programs.
  • Conduct risk assessments by tracking emerging threats and technologies, gathering feedback, analyzing needs, and supporting solution development and vendor selection recommendations.
  • Design and implement cybersecurity systems and software applications, and design, analyze, install, and maintain cybersecurity tools and systems.
  • Stay current on security threats, technologies, and industry trends, and recommend actions to improve security posture.
  • Monitor the City’s network, servers, operating systems, and applications using specialized tools and techniques to detect and prevent threats and malicious activity.
  • Complete security surveys, facilitate network scans, and support compliance with security standards.
  • Assist with audits and assessments, including HIPAA, CJIS policy, digital accessibility local and federal standards, and privacy requirements such as PII.
  • Review and document external vendor security and compliance assessments, and assist with cybersecurity purchasing requirements and platforms such as StateRAMP.
  • Assist in the development of cybersecurity policies and standards aligned with organizational requirements.
  • Identify best practices for web page design and document formatting to support accessibility requirements.
  • Partner with IT Operations to support business continuity, disaster recovery, and incident response initiatives to prevent service interruptions and data loss related to cyber events.
  • Maintain documentation for IT cybersecurity systems, tools, and procedures to support continuity and knowledge sharing.
  • Analyze system security, access, and authorization, notify management of security and inappropriate usage violations, and develop and prepare cybersecurity reports.
  • Ensure compliance with personnel, security, and department procedures, and perform other duties as assigned.

Technologies & Tools

  • Python, SQL
  • NIST, ISO 27001, CIS Critical Security Controls, NIST control documentation
  • Risk Management Framework (RMF), IAVA reporting
  • DevOps
  • HIPAA, CJIS, PII, StateRAMP, SIEM, IDS/IPS
  • Firewalls, antivirus, vulnerability scanning tools
  • TCP/IP, VLANs, VPNs, routing/switching
  • Payment Card Industry (PCI)

Reporting Relationships

  • Reports to: Director of Information Technology
  • Direct Reports: None

Minimum Qualifications

  • Bachelor’s degree in IT, Computers Science, Business, or a related field
  • 5 years progressive technical experience in an information technology field
  • Minimum of 3 years of experience in information security, cybersecurity, or compliance related work
  • CJIS Certification
  • CompTIA Security+
  • CySA+ or Pentest+
  • CISSP preferred

Knowledge, Skills & Abilities

  • Expert knowledge in modern anti-malware technologies, security scanning methods, server operating system and application tier security concepts, and cybersecurity engineering and administration practices.
  • Advanced analysis of vulnerability scanner and security posture management outputs, including NIST and RMF documentation and IAVA reporting.
  • Skills aligned to project coordination, cross-functional collaboration, advanced written and verbal communication, computer/network security evaluation, and analytical problem-solving.
  • Preferred alignment with NIST, ISO 27001, and CIS Critical Security Controls; hands-on work with firewalls, IDS/IPS, SIEM, antivirus, and vulnerability scanning tools; and familiarity with networking concepts such as TCP/IP, VLANs, and VPNs.
  • Experience with security-related regulations including CJIS, HIPAA, and PCI requirements.

Physical Exertion & Working Conditions

  • Physical exertion: Exerting up to 20 pounds of force occasionally, up to 10 pounds frequently, and a negligible amount of force constantly.
  • Working conditions: Encounters with hazardous conditions including electrical currents, heavy equipment, fumes, bodily fluids, extreme temperatures, threatening behaviors, inadequate lighting, restricted movement, or intense noise are described as occurring in varying frequencies depending on the category listed (including limited, infrequent, seldom, moderate, and frequent).

Salary & Benefits

  • Salary range: USD 109,185 - 163,778 per year
  • Medical, Dental, and Vision Plans
  • Retirement Plans
  • Paid Time Off
  • Paid Sick Leave
  • 12 Paid Holidays

Application Details

  • Application deadline: Open until filled

Similar Jobs