> Markdown version of [/jobs/ext/1989489-cyber-security-engineer-i-ii-iii-or-senior](https://www.wearedevelopers.com/jobs/ext/1989489-cyber-security-engineer-i-ii-iii-or-senior). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Engineer I, II, III or Senior - **Company:** Tri-State Generation and Transmission Association, Inc. - **Location:** Westminster, CO, United States (Remote available) - **Experience:** Expert - **Salary:** $109,000.0 - $139,000.0 - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Antivirus Softwares, Cyber Security, Information Systems, Information Leak Prevention, Supervisory Control and Data Acquisition (SCADA), Identity and Access Management, Internet Protocol, Internet Security, Intrusion Detection and Prevention, Information Systems Security Architecture Professional, Python (Programming Language), Microsoft Servers, Network Administration, Public Key Infrastructure, Security Information and Event Management, Transmission Control Protocol (TCP), Software Vulnerability Management, Scripting, Network Access Control, Firewalls (Computer Science), Information Technology, Process Control Systems, Service Stack, Vulnerability Analysis - **Published:** August 8, 2026 - **Apply:** https://dejobs.org/x/x/03D1A6DF08504EFA860917AA18127A1E/job/ ## About the Role Bachelor's degree in cybersecurity, computer science, information technology, information security, information assurance, or a related field, or equivalent work experience., Eight (8) or more years of experience in cybersecurity engineering or a related field. * Expert-level experience with security architecture, engineering, and operational support. * Deep expertise across security technologies (firewall, antivirus, intrusion detection/prevention, SIEM, vulnerability scanning, data loss prevention, encryption, PKI, Identity and Access Management, Rights Management Services, etc.). * Recognized expertise leading incident/forensic response planning and execution, including as a backup incident lead for major events. * Extensive experience designing security processes, control frameworks, and standards. * Experience leading auditor coordination and control compliance at an enterprise level. * Advanced proficiency with one or more scripting languages (e.g., Python, JavaScript, Scapy). * Demonstrated ability to set technical direction, lead enterprise initiatives, and mentor and develop engineers. * Strong executive communication skills, including presenting to senior leadership. * Ability to work in a fast-paced environment and manage workload during periods of stress or escalated activity. Note : The above requirements describe the experience and education qualifications for the Senior Cyber Security Engineer. Those with less experience will be hired at the I, II or III job grade level. Knowledge, Skills, and Abilities * Expert understanding of Internet Protocol (IP), Transmission Control Protocol (TCP)/IP, and other network administration protocols. * Deep technical knowledge of Microsoft server infrastructure and networking, Linux/Unix variant operating systems. * Deep familiarity with governance and controls frameworks, such as Center for Internet Security (CIS) security controls, North American Electric Reliability Corporation (NERC) CIP compliance requirements, and National Institute of Standards and Technology (NIST) standards, with the ability to interpret and guide the organization on their application. * Expert knowledge of security architectures and devices. * Ability to define and lead threat intelligence consumption and management. * Expert knowledge of the root causes of malware infections and proactive mitigation. * Expert knowledge of lateral movement, footholds, and data exfiltration techniques. * Track record of creative problem solving, and the desire to create and build new processes and standards. * Strong decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate option. * Excellent oral and written communication skills, including presenting to senior leadership. * Ability to build and maintain effective working relationships across the enterprise and with external stakeholders. Other * Willingness to travel up to 10% for investigations, meetings and training as needed. (Must possess a valid driver's license.) * Willingness to work on-call duty as assigned., One or more of the following security industry certifications and knowledge regarding security frameworks and regulations required, or the ability to obtain within an agreed timeframe: * Certified Information Systems Security Professional (CISSP) * Global Information Assurance Certification (GIAC) * Certified Information Systems Auditor (CISA) * An MS, MBA, or related advanced degree desired. * Experience in Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems (ICS). * Experience in Sarbanes-Oxley (SOX) and North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) compliance. * Experience in designing and delivering security awareness training. ## Description * Set technical direction and define standards for the architecture, configuration, and lifecycle of enterprise security platforms, including firewalls, SIEM, intrusion detection/prevention systems, CND tools, network access control, and other security platforms. * Evaluate, recommend, and lead the adoption of new security technologies, tools, and capabilities to advance Tri-State's security posture. * Own the enterprise risk management approach; oversee the risk register, and present risk assessments, mitigation plans, and recommendations to senior and executive management. * Serve as backup incident lead / commander during major or high-severity security incidents; direct containment, coordinate response across teams, and work directly with data asset owners and business response plan owners. * Lead post-incident reviews and drive resulting program-wide improvements to detection, response, and prevention. * Define and lead the threat hunting, detection engineering, and adversary tracking strategy. * Establish security processes, control frameworks, standards, and documentation, and drive continuous improvement across the enterprise. * Provide strategic direction for the vulnerability management program and for third-party/vendor risk assessment. * Serve as the senior escalation point for complex engineering and investigation challenges across all security domains and technology stacks. * Advise on compliance strategy, including NERC CIP and SOX, and represent the Cyber Security function in audits and with regulators as needed. * Mentor, coach, and develop Cyber Security Engineers at all levels; lead knowledge sharing and establish engineering best practices. * Partner with leaders across the enterprise to build support and partnership for cyber asset data collection and management across all technologies. * Lead cross-functional and enterprise-wide security initiatives from concept through delivery. * Research emerging threats and vulnerabilities and translate them into actionable defensive strategy. * Maintain compliance with all company policies and procedures and serve as a subject-matter expert on the regulations, laws, standards, and best practices applicable to the functional area. * Because Tri-State has an obligation to provide continuous, reliable electric service to its customers, the ability to work overtime at any time of the day or week is considered an essential function of the job., * Perform other related duties as assigned. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Introducing a Digital Service Catalog for speed and scale](https://www.wearedevelopers.com/videos/763-introducing-a-digital-service-catalog-for-speed-and-scale) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [The Ultimate Software Engineer Career Path Guide for 2023](https://www.wearedevelopers.com/magazine/146-the-ultimate-software-engineer-career-path-guide-for-2023)