Cybersecurity Engineer
Cloud Platforms
Cloud Security Architecture
Cloud Security Posture Management
Data Security
Identity and Access Management
Information Security
InfoSec
Network Security
Nist Cybersecurity Framework
Security
Security Architecture
Security Compliance
Security Operations
Security Standards
Solution Architecture
Vulnerability Management
Zero Trust Architecture
Job Description
The City of Chesapeake seeks a Cybersecurity Engineer onsite in Chesapeake, VA to design security architectures, strengthen security posture, and support threat detection and incident response.
Responsibilities
- Design, implement, and maintain enterprise security architectures across hybrid cloud, virtualization, network infrastructure, and AI systems.
- Build and operationalize Zero Trust practices, including micro-segmentation, least privilege, identity-driven access, and defense-in-depth controls.
- Create and maintain reference architectures, security standards, and architectural design documentation.
- Perform threat modeling and architectural risk assessments aligned with NIST, CIS, ISO 27001, HIPAA, CJIS, PCI, and related frameworks.
- Define and govern security requirements for AI/ML platforms, data pipelines, and model interfaces.
- Implement controls to reduce threats such as prompt injection, model theft, data poisoning, and unauthorized API access.
- Design secure Azure and AWS environments, including segmentation, identity integration, private access, and firewalling.
- Oversee cloud-native security controls, including Azure Firewall, NSGs/ASGs, Security Groups, Network Firewall, CSPM, and secrets management.
- Provide security principles and oversight for firewalls, network devices, endpoint security/XDR, email security, SIEM telemetry, and vulnerability management.
- Coordinate penetration testing and lead remediation efforts.
- Define secure network design patterns for on-premises, hybrid, and cloud networks, including segmentation and perimeter architectures.
- Establish standards for firewall policies, TLS decryption, IPS, URL filtering, and SD-WAN/wireless security.
- Define secure configuration for VMware/Hyper-V, virtual switches, hardened templates, and workload segmentation.
- Define secure configuration guidelines for Windows, Linux, IoT, OT, and SCADA environments.
- Define detection engineering requirements for SIEM/XDR and support threat-hunting activities.
- Support incident response architecture, forensics needs, and containment strategies.
- Participate in risk assessments and define mitigation strategies.
- Support audit requirements, policy development, compliance documentation, and third-party risk reviews.
- Produce documentation, diagrams, and executive-level reports.
- Collaborate with networking, systems, cloud, and application teams on architectural reviews and implementation.
Requirements
- Education and experience combination equivalent to a Bachelor’s degree in computer science, cybersecurity, or a closely related field.
- Minimum 4 years of related, full-time equivalent experience.
- Strong technical knowledge of IT infrastructure and vulnerability patch management preferred.
- Good knowledge of commercial compliance and regulatory standards, including PCI and HIPAA.
- Valid driver’s license and driving record compliant with City Driving Standards.
- Emergency operations support may be required; work locations may be outside normal job duties.
- May require work hours beyond scheduled hours in response to short-term department needs and/or City-wide emergencies.
Technologies
- NIST, CIS, ISO 27001, HIPAA, CJIS, PCI
- Zero Trust, NIST CSF
- Azure, AWS
- Azure Firewall; NSGs/ASGs; Security Groups; Network Firewall; CSPM; secrets management
- Endpoint security/XDR; SIEM; SIEM telemetry; vulnerability management
- TLS decryption; IPS; URL filtering; SD-WAN; wireless security
- VMware; Hyper-V; virtual switches; Windows; Linux; IoT; OT; SCADA
- SIEM/XDR; AI/ML platforms
- prompt injection; model theft; data poisoning; unauthorized API access
- micro-segmentation; identity-driven access; defense-in-depth controls
Job Details
- Location: Chesapeake, VA (onsite)
- Salary: USD 87,075 - 120,000 per yearly
- Job Open Date: 07/31/2026
- Job Close Date: 08/12/2026
Special Instructions
- This position is not eligible for third-party placements (contractor/staffing agency).
- Questions: [email protected]
- Information Technology based positions must meet requirements in CJIS policy for access to the Virginia Criminal Information Network (VCIN).
Physical Strength Demands (ADA)
- Overall: Sedentary, exerting up to 10 lbs occasionally or small weights frequently; sitting most of the time.
- Standing: Frequently (1/3 to 2/3 of the time)
- Sitting: Frequently (1/3 to 2/3 of the time)
- Walking: Frequently (1/3 to 2/3 of the time)
- Lifting: Rarely, less than 1 hour per week; exerting up to 10 lbs
- Carrying: Rarely, less than 1 hour per week; exerting up to 10 lbs
- Fine Dexterity: Continuously (2/3 or more of the time)
- Vision, Hearing, Talking: Continuously (2/3 or more of the time)
- Machines/Tools: Computers and peripherals
- Protective equipment: (not provided)
Health and Safety
- Mechanical, chemical, electrical, fire, explosives, communicable diseases, and physical danger or abuse: None indicated (N = Never)
Environmental Factors
- Dirt and dust, extreme temperatures, noise and vibration, fumes and odors, wetness/humidity, darkness/poor lighting: None indicated (N = Never)
- Primary work location: Office environment