Security Engineer

VA Workers' Compensation Comm
Richmond, VA, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$88,507.0
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Microsoft Azure Bash Shell Cloud Computing Cloud Computing Security Cyber Security Monitoring of Systems Identity and Access Management Information Security Management Intrusion Detection and Prevention Intrusion Detection Systems Python (Programming Language)
+10 more
Network Architecture Windows PowerShell Azure Active Directory Security Information and Event Management TCP/IP Software Vulnerability Management Scripting Google Cloud Firewall Services Module Splunk

Job description

The Virginia Workers’ Compensation Commission (VWC), an independent state agency, is seeking an Information Security Engineer to help strengthen and evolve cybersecurity operations across the agency. This is an exciting opportunity for a security professional who enjoys hands-on engineering, problem-solving, threat defense, and working across a broad range of modern security technologies in a collaborative, mission-driven environment.

In this role, you will partner closely with the Information Security Officer (ISO), Security Analyst, and IS/IT teams to support and improve the Commission’s Information Security Program. You’ll play a key role in securing systems and data that support Virginia’s workforce while contributing to initiatives focused on security engineering, threat monitoring, vulnerability management, incident response, governance, and continuous improvement.

This position is ideal for someone who enjoys balancing technical depth with strategic thinking, thrives in a collaborative environment, and wants to make a meaningful impact through public service while maintaining strong work-life balance and flexibility.

Some key responsibilities include:

  • Configure, maintain, tune, and optimize enterprise security technologies including SIEM, EDR, vulnerability management, IAM/PAM, DLP, and monitoring platforms.
  • Design, implement, and support security tools and controls that align with Commonwealth security standards and industry best practices.
  • Monitor system and network activity to identify threats, suspicious behavior, vulnerabilities, and security risks.
  • Support threat detection and incident response efforts through alert tuning, threat intelligence integration, analysis, and remediation activities.
  • Automate security tasks and operational processes using scripting languages such as Python, PowerShell, or Bash.
  • Research, recommend, and implement security technologies and solutions that improve operational security and efficiency.
  • Perform vulnerability and configuration assessments across systems, infrastructure, and security platforms.
  • Assist with governance, compliance, risk management, incident response planning, and third-party security oversight activities.
  • Maintain documentation related to systems, security configurations, operational procedures, and security processes.
  • Collaborate with internal business units and external partners to support secure, resilient agency operations.

Requirements

Do you have experience in Writing skills?, This role is ideal for someone who thrives in both technical problem-solving and continuous improvement and someone who enjoys balancing engineering, security operations, threat analysis, and strategic security initiatives in a mission-driven environment., * Experience in information security, network engineering, systems administration, security operations, or a related technical field.

  • Working knowledge of enterprise security technologies such as SIEM, EDR, IAM/PAM, vulnerability management, IDS/IPS, and system monitoring tools.
  • Experience with scripting or automation using tools such as Python, PowerShell, or Bash.
  • Knowledge of cybersecurity principles, threat detection, incident response, and security best practices.
  • Knowledge of and network/security concepts including TCP/IP protocols.
  • Familiarity with security frameworks and standards such as NIST 800-53 and Commonwealth of Virginia SEC501/SEC530 standards.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Ability to communicate effectively both verbally and in writing.

  • Knowledge of cloud computing.

  • Knowledge of Artificial Intelligence (AI) integration.

Additional Considerations

  • Splunk management experience, physical routers, firewall configurations, Microsoft Purview administration and other network infrastructure is a plus.
  • Cloud security controls (AWS, Azure, GCP), experience in managing and configuring Microsoft Entra ID security features.

About the company

Led by a Senior Leadership team consisting of three Commissioners, an Executive Director, and a Chief Deputy Commissioner. Our mission is to serve injured workers, victims of crimes, employers, and related industries by providing exceptional services, resolving disputes, and faithfully executing the duties entrusted to us by the Commonwealth of Virginia. Our vision is to lead the nation as the most effective and innovative state agency. VWC demonstrate seven core values: innovation, respect, accountability, reliability, impartiality, integrity, and effectiveness.

We are a “Virginia Values Veterans” (V3) official certified state agency that supports Veterans and Members of the Reserves and/or National Guard. If you are a Veteran or Spouse of a Veteran or Active Military Member, we urge you to respond accordingly on your state application. Virginia Workers’ Compensation Commission is an Equal Opportunity Employer, and we encourage diversity within our workforce. Virginia Workers’ Compensation Commission does not provide sponsorship for employment.

VWC has been recognized as a Top Workplace for the past several years in the Richmond Region and in the country. It is the recipient of the following awards:

  • 2022 - 2026 Top USA Workplace
  • 2021 - 2026 Top Workplace Richmond Region
  • 2023 - 2025 Top Award for Mid-Sized Companies
  • 2022 - 2023 Doers Award
  • 2024 Manager’s Award
  • 2025 Leadership Award, McGill

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner ¡ LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 ¡ LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders ¡ LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira ¡ Coffee With Developers

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 ¡ LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all