Security Operations Engineer - IT Security - Senior/Specialist - Permanent - 2026-06543

State of Washington
Olympia, WA, United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Compensation
$99,300.0 - $133,608.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Amazon Web Services Microsoft Azure Cloud Computing Configuration Management CompTIA Security+ Cyber Security Data Centers Networking Hardware Internet Security Intrusion Detection and Prevention Information Systems Security Architecture Professional
+13 more
Log Files Cloud Services Server Administration Software Engineering Systems Architecture Virtualization Technology Software Vulnerability Management Data Logging Scripting Enterprise Software Applications Software Security Information Technology Vulnerability Analysis

Job description

Hybrid/Telework- While this position may offer a telework option, the successful candidate must be available to report to the duty station on a weekly basis. Learn more about being a member of Team WDFW! Cougar in tree - Photo Credit: WDFW As the WDFW Enterprise Security Operations Engineer, you will play a key role in protecting the agency’s technology environment by designing, implementing, and monitoring application security solutions across both on-premises and cloud-based systems. In this role, you will serve as a trusted resource for IT teams, providing technical guidance and support related to application security and security operations. You will collaborate with other security and technology leaders, including the Incident Response Engineer, SEAL Team Supervisor, Data Center Architect, and Application Development Architect, to help address security risks, strengthen configurations, and support the agency’s overall cybersecurity mission. What to Expect: Among the varied range of responsibilities held within this role, the Security Operations Engineer will, Solutions Development:

  • Independently design, implement, and support WDFW Enterprise application security solutions for both on-premises and cloud-hosted environments, utilizing expertise in Windows Group Policy (GPO) configuration, system baseline configuration, registry edits, and scripting languages.
  • Identify gaps in the agency’s security capabilities in comparison to industry standard threat research and best business practices such as the Center for Internet Security (CIS) Critical Security Controls (CSC).
  • Conduct capability and integration assessments of commercial and custom solutions to ensure deployment and integration compliance.
  • Coordinate with the Incident Response Engineer to ensure reviewed applications and services are integrated into the agency’s centralized monitoring and logging platform.
  • Participate in “Tiger Team” architectural efforts to provide technical solutions to address agency problem sets.

Security Review:

  • Lead and mentor team of Analysts in conducting internal security reviews for new and existing software and hardware requests, including agency systems such as the WILD licensing system, which issues commercial and recreational hunting and fishing licenses, and the Enforcement Records Management System (RMS) utilized for the processing and storing of Criminal Justice Information (CJI).
  • Conduct project-specific risk assessments of WDFW applications and systems, developing and implementing remediation actions as needed.
  • Review system architecture, configurations, and processes to identify potential security risks, recommend corrective actions, and develop custom configurations through scripting to support business units.
  • Maintain Plans of Action and Milestones (POAM).
  • Analyze WDFW vulnerability assessment reports to evaluate agency risk and develop remediation actions.
  • Conduct Washington State Office of Cybersecurity (OCS) Design reviews for infrastructure and functional areas supported by this position.

Security Operations (Risk Assessment, Vulnerability Management, and Configuration Management):

  • Provide senior-level guidance to the staff responsible for risk assessment, vulnerability management, and configuration management activities.
  • Mentor team members and contribute to the continuous improvement of security operations processes and practices.
  • Ensure staff maintain accurate documentation and performance metrics that clearly reflect completed work and the agency’s risk and vulnerability posture to support informed management decisions.
  • Collaborate with peer engineers and architects to resolve prioritization conflicts related to security operations initiatives.

Policy Administration:

  • Review and provide feedback for security-related policy while documenting processes, procedures, and techniques that support the security policy.
  • Produce and maintain accurate security documentation, including processes, procedures, and techniques for both on-premises and cloud solutions.

Surge Support:

  • Provide operational support to the CSU Incident Response Engineer during periods of increased workload caused by scheduled or unscheduled staff absences, year-end budget activities, or other operational demands. Support may include threat detection, incident response, and mentoring staff as needed.

Working Conditions: Work Setting, including hazards: Work in an office setting which may also include data closets and datacenter. May be required to work in tight spaces. Schedule: Typically, Monday - Friday, 8:00am to 5:00pm. Travel Requirements: Some travel may be required to regional and other remote offices. Tools and Equipment: Hand tools and networking equipment. Customer Interactions: Interact with WDFW staff and WaTech vendors.

Requirements

Closely related qualifying experience may be substituted for the required education on a year-by-year basis. Option 1 - All of the following:

  • Bachelor’s degree from an accredited college or university in computer science or a closely related field.
  • Seven (7) or more years of recent professional experience (within the last 10 years) working with infrastructure systems and cybersecurity risk assessment methodologies.

Option 2 - All of the following (experience may be gained concurrently):

  • Seven (7) or more years of recent professional experience (within the last 10 years) working with infrastructure systems and cybersecurity risk assessment methodologies.
  • Four (4) or more years of recent professional, hands-on infrastructure administration experience (within the last 5 years), including experience with server configuration, virtualization platforms, and cloud services., Must pass fingerprint and background check due to working with law enforcement and sensitive data., In addition to the required qualifications, our ideal applicant will possess one or more of the following: Experience:

  • Experience working in cloud-based environments, such as AWS and Azure.
  • Experience managing a monitoring solution that includes the centralized collection of log file data.

Certifications:

  • Certified Information Systems Security Professional (CISSP) certification.
  • CompTIA Security+ certification.
  • Microsoft certification(s).

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

2:11 min

Enhancing manual debugging through model-assisted log analysis

Michael Niebisch Michael Niebisch · World Congress 2024

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · World Congress 2026 Europe

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:41 min

Understanding the daily challenges of massive log volumes

Michal Bojko Michal Bojko · World Congress 2025

1:40 min

Tracking data modifications with Delta Lake transaction logs

Matthias Niehoff Matthias Niehoff · World Congress 2026 Europe

Videos

See all

Related articles

See all