> Markdown version of [/jobs/ext/221901-cybersecurity-administrator](https://www.wearedevelopers.com/jobs/ext/221901-cybersecurity-administrator). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Administrator - **Company:** Pennsylvania Office of Attorney General - **Location:** Harrisburg, PA, United States (Remote available) - **Experience:** Experienced - **Salary:** $87,903.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Identity and Access Management, Network Security, Phishing, Security Information and Event Management, Software Engineering, Software Vulnerability Management, Mitre Att&ck, Mttr, Cyber Threat Analysis, Information Technology, Cyber Warfare, Security Orchestration, Automation & Response - **Published:** May 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=95d280309f3f14d5 ## About the Role * An associate's degree in Cybersecurity, Information Technology, or a related field and five (5) years of experience working in a technology and/or cybersecurity focused role, with at least two (2) years of experience supervising a small team * A bachelor's degree in Cybersecurity, Information Technology, or a related field and three (3) years of experience working in a technology and/or cybersecurity focused role, with at least two (2) years of experience supervising a small team * A master's degree in Cybersecurity, Information Technology, or a related field and two (2) years of experience working in a technology and/or cybersecurity focused role, with at least two (2) years of experience supervising a small team * Seven (7) years of experience working in a technology and/or cybersecurity focused role, with at least two (2) years of experience supervising a small team * Any combination of experience, training, and education Preferred Knowledge, Skills, and Abilities * Hands-on-familiarity with compliance standards such as SOC 2, HIPPA, NIST 800-171, 800-53, CSF, or similar * Experience with SIEM/SOAR, EDR, Vulnerability Management, Email Security, Identity Security, Network Security, and Data Protection technology platforms * Experience with incident response procedures and concepts * Conceptual understanding of MITRE ATT&CK frameworks * Ability to manage and prioritize cybersecurity vulnerabilities * Ability to make quick but informed decisions in a fast-paced environment during periods of high stress * Ability to express ideas clearly and concisely, orally and in writing ## Description Telework: This position will report to the headquartered location a minimum of 2 days per week. You may have the opportunity to telework the remainder of the week, if desired and based on business need., The Cybersecurity Administrator leads daily cybersecurity operations, including incident response, vulnerability management, SOC Coordination, and proactive threat hunting. This role ensures alignment with NIST CSF, NIST SP 800-53, and JCIS requirements, manages cyber risks and supports audits, oversees the security technology stack, and partners with internal units to promote secure-by-design practices. The position also contributes to security awareness initiatives, maintains security policies and standards, supervises cybersecurity staff, and communicates risk and incident updates to leadership. The Cybersecurity Administrator has a primary reporting line to the Director of IT & Cyber Operations and a secondary reporting line to the Chief Technology & Security Officer., * Owns incident response procedures (classification, triage, containment, eradication, recovery), playbook development, tabletop exercise, and after-action review with corrective actions * Coordinates Security Operations Center (SOC) activities to enhance mean time to detect and respond (MTTD/MTTR) to cybersecurity incidents * Ensures continued alignment with NIST CSF, NIST 800-53, and CJIS Security Policy control families at the direction of the Chief Technology & Security Officer (CTSO) * Oversees the daily tactical operations of the Vulnerability Management Program including asset coverage, scanning cadence, risk-based prioritization, exception handling, and executive reporting * Analyzes and manage cybersecurity-related risks in alignment to the Cyber Risk Management Program including updates to the risk register, corrective actions, and formal risk acceptance processes * Collaborates with the Technology Strategy section on the Security Awareness & Training Program to ensure periodic training is administered to OAG staff, phishing campaigns are orchestrated, and metrics are collected for continuous improvement and learning activities * Contributes to the development and ongoing maintenance of security policies, procedures, standards, and programs to ensure continued attestation and training is administered * Provides support during internal and external audits and assessments to ensure findings and Plan of Action & Milestones (POA&M) are managed through closure * Owns the security technology stack including the SIEM/SOAR, EDR, Vulnerability Management, Email Security, Identity Security, Network Security, and Data Protection platforms * Partners with the Infrastructure, Technology Experience, Litigation Support, and Software Engineering Units to integrate cybersecurity into the architectural design and ongoing support activities, acting as an advocate for a "secure-by-design" mentality * Oversees reconnaissance activities in conjunction with partner agencies on threat adversaries within legal and ethical guidelines * Leads proactive threat hunting activities including hypothesis-driven hunts, detections mapped to the MITRE ATT&CK framework, and continuous tuning of cybersecurity toolsets to improve automated detection and response capabilities * Supervises cybersecurity personnel, including interviewing, onboarding, performance management, and coaching activities * Briefs management and executive staff on risk posture, cybersecurity maturity levels, and incidents using data and metrics * Builds strong relationships with staff from all divisions, sections, and units to align security with mission priorities * Oversees and participate in on-call rotations and after-hours response during elevated events * Performs related duties as required. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [MFA? Game over! Watch your protection collapse – live](https://www.wearedevelopers.com/videos/100322-mfa-game-over-watch-your-protection-collapse-live) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)