> Markdown version of [/jobs/ext/2567048-cyber-security-engineer-i-iv-depends](https://www.wearedevelopers.com/jobs/ext/2567048-cyber-security-engineer-i-iv-depends). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Engineer I-IV (Depends... - **Company:** Grant PUD - **Location:** Ephrata, WA, United States - **Experience:** Experienced - **Salary:** $91,411.0 - $151,055.0 - **Contract:** Internship / Graduate position - **Skills:** Artificial Intelligence, Proxy Servers, Antivirus Softwares, Software System Penetration Testing, Network Operating System (NOS), Cloud Computing Security, Cyber Security, Information Systems, Computer Networks, Cyber Laws, Data Security, Disaster Recovery, Identity and Access Management, Intrusion Detection and Prevention, Intrusion Detection Systems, Network Security, Network Layer, Network Architecture, Performance Tuning, Program Design Languages, Cloud Services, Phishing, Zero Trust Network Access, Runbook, Security Log, Security Information and Event Management, Software Vulnerability Management, Wide Area Networks, Diagnostic Tools, Scripting, Enterprise Software Applications, Data Classification, Mitre Att&ck, Cyber Threat Analysis, Firewalls (Computer Science), Cybercrime, Routing & Switching, CIS Benchmarks, Vulnerability Analysis - **Published:** August 15, 2026 - **Apply:** https://www.juju.com/job/00000000gn8vk1 ## About the Role + Engineer I: Associate's degree in cyber security, information systems, engineering, or related field, or an equivalent combination of education, certification, and job experience; zero (0) to two (2) years of experience in an IT or cyber security support role, or equivalent internship/co-op experience. + Engineer II: Bachelor's degree in information systems, engineering, or related degree, or an equivalent combination of education, certification, and job experience; three (3) years of experience in cyber security or IT security roles. + Engineer III: Bachelor's degree in information systems, engineering, or related degree, or an equivalent combination of education, certification, and job experience; six (6) to ten (10) years of progressive experience in a cyber security role with demonstrated technical knowledge. + Engineer IV: Bachelor's degree in cyber security, information systems, engineering, or related degree, or an equivalent combination of education, certification, and job experience; ten (10) or more years of experience in a cyber security role with at least three (3) years in a senior, lead, or principal capacity. Utility or critical infrastructure experience strongly preferred. **Preferred Qualifications** (Education, Experience, Licenses & Certifications): + Engineer I: Bachelor's degree in cyber security, information systems, engineering, or related field; three (3) years' experience in a cyber security role. + Engineer II: Bachelor's degree in cyber security; five (5) years of experience in a cyber security role. + Engineer III: Bachelor's degree in cyber security; 7+ years of experience in a cyber security role with at least two (2) years in a senior or lead capacity. + Engineer IV: Master's degree in cyber security, information systems, engineering, or related field; graduate-level coursework or research in OT/ICS security, cloud security architecture, or enterprise risk management. License and Certification + Engineer I: Security+, CySA+, or equivalent foundational cyber security certification. Must be willing to obtain within 12 months of hire. + Engineer II: Must have or be willing to obtain a cyber security industry certification such as CISSP, CISA, GCIH, GCEH, or equivalent. + Engineer III: CISSP, GIAC certifications (GCIH, GCIA, GPEN), CCSP, or equivalent advanced certifications. + Engineer IV: CISSP, CISM, CCSP, multiple GIAC certifications, or equivalent advanced certifications; GRID, GICSP, or other OT/ICS-focused certifications. Other Knowledge, Skills & Abilities All levels require progressively greater knowledge and independence in cyber security controls; NIST, CIS, NERC CIP and other applicable frameworks; Federal/State/Local cyber laws; firewalls, proxies, SIEM, antivirus and IDS/IPS; vulnerability management; penetration testing; threat hunting; security monitoring; incident response and recovery; business continuity; risk and project management; enterprise network and cloud security; data security; process development and auditing; network operating systems, protocols, and diagnostic tools. Cyber Security Engineer I Foundational knowledge of the above, including NIST Cybersecurity Framework, CIS Critical Security Controls, NERC CIP, vulnerability assessment, security log analysis, enterprise network architecture, cloud security, WAN/LAN protocols, and diagnostic tools. Basic alert triage and incident response fundamentals; familiarity with playbooks/runbooks, cloud identity and access management, endpoint security, EDR/XDR and MDR platforms, NAC, Layer 3 networking, vulnerability scanning, security awareness/phishing simulations, and AI-assisted security tools and governance. Cyber Security Engineer II Strong knowledge of the above, including vulnerability mitigation, penetration testing, threat hunting, incident response and recovery, business continuity, risk and project management, enterprise network architecture and design, cloud solutions security, data security, and process development/auditing. Ability to assess alerts and risk, create playbooks/runbooks, investigate cloud identity and endpoint activity, work with EDR/XDR and MDR platforms, next-generation firewall and SASE solutions, NAC, switching/routing, enterprise SIEM, vulnerability management, security awareness platforms, and AI-assisted security workflows. Cyber Security Engineer III Advanced knowledge of the above, including security architecture and tuning, vulnerability program management, threat intelligence, detection engineering, incident response leadership, enterprise risk frameworks, technical project leadership, cloud security architecture, data classification, and advanced diagnostics. Leads complex incidents, threat hunting, Zero Trust identity architecture, advanced EDR/XDR and MDR investigations, firewall/SASE architecture, segmentation strategy, SIEM detection engineering, vulnerability management programs, security awareness program design, AI-assisted investigations and governance, mentoring, and cross-functional projects. Cyber Security Engineer IV Expert-level knowledge of the above, including NIST 800-53 and 800-82, audit preparation and evidence management, security architecture governance, vulnerability program maturity, penetration testing oversight, detection strategy, incident response program leadership, DR architecture, enterprise risk quantification, strategic planning, cloud security governance, data classification/DLP strategy, and standards development. Governs incident response, MITRE ATT&CK detection coverage, Zero Trust identity and network architecture, endpoint/MDR strategy, OT/ICS network security, SIEM and vulnerability management program roadmaps, security awareness strategy, AI security governance, and technical team development. ## Description Cyber Security Engineer I Under direct supervision, this entry-level position supports the Cyber Security Team in implementing enterprise cyber security goals. The incumbent assists in identifying, implementing, and maintaining cyber security solutions and supports investigation of cyber-related issues that may pose risk to Grant PUD business operations and data. Assists senior engineers in recommending and enhancing security controls, performing risk assessments, and developing policies and procedures for the Enterprise Cyber Security Program to ensure identification, protection, detection, response, and recovery objectives are met. Supports compliance with industry standard frameworks such as NIST, CIS, and NERC CIP under the direction of senior team members. Cyber Security Engineer II Under general supervision, this position works as part of the Cyber Security Team to implement enterprise cyber security goals and is responsible for identifying, implementing, and maintaining compliant cyber security solutions and addressing cyber-related issues that may pose immediate or long-term risk to Grant PUD business operations and data. Recommends and enhances security controls, performs risk assessments, and assists in development of policies and procedures for the Enterprise Cyber Security Program. Maintains compliance with NIST, CIS, NERC CIP, and applicable Federal, State, and Local regulations. Cyber Security Engineer III Under limited supervision, this senior-level position serves as a technical leader on the Cyber Security Team, driving the design, implementation, and continuous improvement of enterprise cyber security solutions. Independently identifies, architects, and maintains compliant cyber security solutions and leads response to cyber-related issues that may pose immediate or long-term risk to Grant PUD business operations and data. Leads enhancement of security controls, risk assessments, and development of policies and procedures. Provides technical leadership and mentoring to junior and mid-level engineers, leads cross-functional security initiatives, and serves as an escalation point for complex security incidents and engineering challenges. Maintains and ensures compliance with NIST, CIS, NERC CIP, and applicable regulations and may serve as a subject matter expert for audits and assessments. Cyber Security Engineer IV Under minimal supervision, this principal-level position serves as the senior technical authority and thought leader on the Cyber Security Team. Helps define strategic technical direction for enterprise cyber security, architects and governs the most complex security solutions, and is accountable for ensuring Grant PUD's security posture meets current and emerging threats. Drives strategic enhancement of security controls, oversees the risk assessment program, and leads development of policies, procedures, and standards. Mentoring is a primary responsibility, including developing the technical capabilities and professional growth of Cyber Security Engineers Levels I-III through structured mentoring, technical coaching, knowledge transfer, career development planning, technical standards, and advanced training. Provides strategic leadership on enterprise-wide security initiatives, serves as the primary technical escalation point for critical security incidents, and represents the Cyber Security Team in executive and external engagements. Governs compliance with NIST, CIS, NERC CIP, and applicable regulations and serves as the primary subject matter expert for audits, assessments, and regulatory engagements. Essential Functions Essential functions, as defined under the Americans with Disabilities Act, may include the following representative duties, knowledge, and skills. This is not a comprehensive listing; employees may be assigned duties not listed below, reasonable accommodations will be made as required, and the job description is subject to change at any time by the employer. + This position requires NERC CIP access, and incumbents must meet and maintain eligibility with the established criteria in the Grant PUD Personnel Risk Assessment Procedure. Pursuant to NERC standards, Grant PUD conducts background screening of personnel who have access to the District's critical physical and/or cyber assets. + Executes assigned work plans safely, compliantly, on time, and in accordance with established standards, procedures, and standard work practices. + Communicates effectively with supervisors, peers, and customers, demonstrating respect and alignment with the organization's values and Code of Excellence. + Maintains knowledge of and adheres to applicable laws, regulations, security requirements, and Grant PUD policies and procedures. + Actively participates in all aspects of the safety program, including following safety procedures, reporting unsafe conditions and incidents or close calls, and accepting feedback regarding safety performance. SPECIFIC FUNCTIONS All levels support the confidentiality, integrity, and availability of Grant PUD Enterprise Technologies and data through cyber solutions meeting Cyber Security Program objectives. Scope and independence increase by level. Cyber Security Engineer I + Assists senior engineers with cyber risk assessments of enterprise processes, systems, information, data, rights, privileges, and 3rd party partners; researches, analyzes, and documents cyber security risks. + Assists in maintaining and operating cyber systems to identify, detect, protect, respond, and recover from cyber threats and incidents. + Supports investigation of potential and actual cyber security incidents, following established chain-of-custody and containment processes to minimize operational impacts. + Assists in ensuring technologies and procedures comply with Grant PUD internal computing controls, cyber-related legislation, industry frameworks such as NIST CSF and CIS Controls, and applicable regulations. + Assists in operation and monitoring of automated cyber security controls such as firewalls and SIEM and supports improvements based on lessons learned. + Supports operational and trend reports and/or dashboards for KPIs detailing the health of Cyber Security functions. + Assists in developing scripts, checklists, and other tools/methods to automate tasks and enable efficient, repeatable outcomes. + Demonstrates effective communication and supports analysis and presentation of viable solutions to cyber issues. Cyber Security Engineer II + Performs cyber risk assessments and researches, analyzes, recommends, and implements cyber security solutions. + Maintains and operates cyber systems to identify, detect, protect, respond, and recover from cyber threats and incidents; assists investigations and follows chain-of-custody and containment processes. + Ensures technologies and procedures comply with Grant PUD internal computing controls, NIST CSF, CIS Controls, and applicable regulations; performs, operates, and audits assigned compliance responsibilities. + Assists development, implementation, maintenance, and oversight of automated cyber security controls and implements process improvements based on lessons learned. + Develops operational and trend reports and/or dashboards supporting KPIs and detailing the health of Cyber Security functions. + Assists development and implementation of scripts, cookbooks, checklists, and other automation tools/methods. + Demonstrates excellent communication, analyzes and presents viable solutions, and follows projects and activities through completion. Cyber Security Engineer III + Leads cyber risk assessments; researches, analyzes, recommends, implements, architects, and operates cyber security solutions and systems. + Leads complex and high-severity cyber security incident investigations, directs response activities, ensures chain of custody, coordinates containment, and serves as an escalation point for Engineer I and II staff. + Ensures technologies and procedures comply with Grant PUD internal computing controls, cyber-related legislation, NIST CSF, CIS Controls, and applicable regulations; leads and audits assigned compliance responsibilities and may serve as an SME during audits. + Leads development, implementation, maintenance, and oversight of automated cyber security controls and drives process improvement based on lessons learned and industry best practices. + Provides subject matter expertise in development, implementation, and testing of enterprise disaster recovery and business continuity plans. + Designs operational and trend reports and/or dashboards supporting KPIs and presents findings and recommendations to leadership. + Designs advanced scripts, automation frameworks, and tools/methods to automate operational security controls. + Provides technical mentoring and guidance to Engineer I and II staff and leads cross-functional projects with IT, OT, and business stakeholders. Cyber Security Engineer IV + Oversees and directs the enterprise cyber risk assessment program; defines methodologies, reviews findings, aligns with enterprise risk management objectives, and architects enterprise-level solutions to address identified threats. + Serves as primary technical authority for the most complex and critical cyber security incidents, directing investigation, containment, eradication, recovery, post-incident reviews, and integration of lessons learned. + Governs compliance with Grant PUD internal computing controls, cyber-related legislation, NIST CSF, NIST 800-53, CIS Controls, and applicable regulations; serves as primary SME for audits, assessments, and regulatory engagements. + Directs and governs development, implementation, maintenance, and oversight of automated cyber security controls, establishes technical standards, and drives continuous improvement. + Provides strategic cyber security expertise for enterprise disaster recovery and business continuity planning and testing. + Defines and oversees operational and strategic reporting supporting KPIs, KRIs, and program health metrics; presents program status, risk posture, and strategic recommendations to executive leadership. + Architects and oversees advanced automation frameworks, scripts, and tools to optimize operational security controls. + Actively mentors and develops Cyber Security Engineers Levels I-III, establishes development plans, conducts coaching, leads technical training, and fosters continuous learning. + Leads the most complex cross-functional and enterprise-wide security initiatives with IT, OT, business stakeholders, and executive leadership., + Majority of work is performed in a standard office setting. + Will perform work onsite at the locations of the assigned Business Units + Typical shift of employees in this position: 8 hours 9 hours 10 hours 12 hours _*For a full list of requirements, the applicant/incumbent should refer to the Physical Capacity Evaluation (PCE)._ _The statements contained herein reflect general details as necessary to describe the principal functions for this job, the level of knowledge and skill typically required, and the scope of responsibility, but should not be considered an all-inclusive listing of work requirements. Individuals may perform other duties as assigned, including work in other functional areas_ Equal Opportunity Employer This employer is required to notify all applicants of their rights pursuant to federal employment laws. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The Ultimate Software Engineer Career Path Guide for 2023](https://www.wearedevelopers.com/magazine/146-the-ultimate-software-engineer-career-path-guide-for-2023) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)