> Markdown version of [/jobs/ext/2564543-security-operations-engineer-it-security-senior-specialist-permanent-2026-06543](https://www.wearedevelopers.com/jobs/ext/2564543-security-operations-engineer-it-security-senior-specialist-permanent-2026-06543). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Operations Engineer - IT Security - Senior/Specialist - Permanent - 2026-06543 - **Company:** State of Washington - **Location:** Olympia, WA, United States (Remote available) - **Experience:** Expert - **Salary:** $99,300.0 - $133,608.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Microsoft Azure, Cloud Computing, Configuration Management, CompTIA Security+, Cyber Security, Data Centers, Networking Hardware, Internet Security, Intrusion Detection and Prevention, Information Systems Security Architecture Professional, Log Files, Cloud Services, Server Administration, Software Engineering, Systems Architecture, Virtualization Technology, Software Vulnerability Management, Data Logging, Scripting, Enterprise Software Applications, Software Security, Information Technology, Vulnerability Analysis - **Published:** August 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=2b891c5af3506818 ## About the Role Closely related qualifying experience may be substituted for the required education on a year-by-year basis. Option 1 - All of the following: * Bachelor's degree from an accredited college or university in computer science or a closely related field. * Seven (7) or more years of recent professional experience (within the last 10 years) working with infrastructure systems and cybersecurity risk assessment methodologies. Option 2 - All of the following (experience may be gained concurrently): * Seven (7) or more years of recent professional experience (within the last 10 years) working with infrastructure systems and cybersecurity risk assessment methodologies. * Four (4) or more years of recent professional, hands-on infrastructure administration experience (within the last 5 years), including experience with server configuration, virtualization platforms, and cloud services., Must pass fingerprint and background check due to working with law enforcement and sensitive data., In addition to the required qualifications, our ideal applicant will possess one or more of the following: Experience: * Experience working in cloud-based environments, such as AWS and Azure. * Experience managing a monitoring solution that includes the centralized collection of log file data. Certifications: * Certified Information Systems Security Professional (CISSP) certification. * CompTIA Security+ certification. * Microsoft certification(s). ## Description Hybrid/Telework- While this position may offer a telework option, the successful candidate must be available to report to the duty station on a weekly basis. Learn more about being a member of Team WDFW! Cougar in tree - Photo Credit: WDFW As the WDFW Enterprise Security Operations Engineer, you will play a key role in protecting the agency's technology environment by designing, implementing, and monitoring application security solutions across both on-premises and cloud-based systems. In this role, you will serve as a trusted resource for IT teams, providing technical guidance and support related to application security and security operations. You will collaborate with other security and technology leaders, including the Incident Response Engineer, SEAL Team Supervisor, Data Center Architect, and Application Development Architect, to help address security risks, strengthen configurations, and support the agency's overall cybersecurity mission. What to Expect: Among the varied range of responsibilities held within this role, the Security Operations Engineer will, Solutions Development: * Independently design, implement, and support WDFW Enterprise application security solutions for both on-premises and cloud-hosted environments, utilizing expertise in Windows Group Policy (GPO) configuration, system baseline configuration, registry edits, and scripting languages. * Identify gaps in the agency's security capabilities in comparison to industry standard threat research and best business practices such as the Center for Internet Security (CIS) Critical Security Controls (CSC). * Conduct capability and integration assessments of commercial and custom solutions to ensure deployment and integration compliance. * Coordinate with the Incident Response Engineer to ensure reviewed applications and services are integrated into the agency's centralized monitoring and logging platform. * Participate in "Tiger Team" architectural efforts to provide technical solutions to address agency problem sets. Security Review: * Lead and mentor team of Analysts in conducting internal security reviews for new and existing software and hardware requests, including agency systems such as the WILD licensing system, which issues commercial and recreational hunting and fishing licenses, and the Enforcement Records Management System (RMS) utilized for the processing and storing of Criminal Justice Information (CJI). * Conduct project-specific risk assessments of WDFW applications and systems, developing and implementing remediation actions as needed. * Review system architecture, configurations, and processes to identify potential security risks, recommend corrective actions, and develop custom configurations through scripting to support business units. * Maintain Plans of Action and Milestones (POAM). * Analyze WDFW vulnerability assessment reports to evaluate agency risk and develop remediation actions. * Conduct Washington State Office of Cybersecurity (OCS) Design reviews for infrastructure and functional areas supported by this position. Security Operations (Risk Assessment, Vulnerability Management, and Configuration Management): * Provide senior-level guidance to the staff responsible for risk assessment, vulnerability management, and configuration management activities. * Mentor team members and contribute to the continuous improvement of security operations processes and practices. * Ensure staff maintain accurate documentation and performance metrics that clearly reflect completed work and the agency's risk and vulnerability posture to support informed management decisions. * Collaborate with peer engineers and architects to resolve prioritization conflicts related to security operations initiatives. Policy Administration: * Review and provide feedback for security-related policy while documenting processes, procedures, and techniques that support the security policy. * Produce and maintain accurate security documentation, including processes, procedures, and techniques for both on-premises and cloud solutions. Surge Support: * Provide operational support to the CSU Incident Response Engineer during periods of increased workload caused by scheduled or unscheduled staff absences, year-end budget activities, or other operational demands. Support may include threat detection, incident response, and mentoring staff as needed. Working Conditions: Work Setting, including hazards: Work in an office setting which may also include data closets and datacenter. May be required to work in tight spaces. Schedule: Typically, Monday - Friday, 8:00am to 5:00pm. Travel Requirements: Some travel may be required to regional and other remote offices. Tools and Equipment: Hand tools and networking equipment. Customer Interactions: Interact with WDFW staff and WaTech vendors. ## Related Videos - [The Software Bug All Stars - and what we can learn from them](https://www.wearedevelopers.com/videos/423-the-software-bug-all-stars-and-what-we-can-learn-from-them) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Logs in observability - Correlation](https://www.wearedevelopers.com/videos/1430-logs-in-observability-correlation) - [Strategies for Efficient Log Management in Large-Scale Kubernetes Clusters](https://www.wearedevelopers.com/videos/100131-strategies-for-efficient-log-management-in-large-scale-kubernetes-clusters) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)