Cybersecurity Engineer

OAG, INC.
Austin, TX, United States
4 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Audit Trail Microsoft Azure Configuration Management Databases Configuration Management Cyber Security System Configuration Data Normalization Query Languages
+24 more
Software Design Documents Linux Federal Information Processing Standards (FIPS) Identity and Access Management Information Security Management Python (Programming Language) Windows Servers Windows PowerShell Red Hat Enterprise Linux Cloud Services Kusto Query Language Zero Trust Network Access Sherwood Applied Business Security Architecture Security Information and Event Management Web Applications Data Logging Data Classification Large Language Models Git Togaf Information Technology 3-tier Architectures CIS Benchmarks Splunk

Job description

The Office of the Attorney General is a dynamic organization with employees across the State of Texas, providing legal representation, supporting statewide programs, and protecting critical information assets. The Enterprise Information Security Team delivers security services that safeguard agency systems, data, and operations by applying strong engineering practices and modern security controls.

The Cybersecurity Engineer performs advanced cybersecurity work as part of the Enterprise Information Security engineering group. The role focuses on designing, implementing, and operating enterprise security platforms; conducting technical risk assessments; supporting exposure management; and producing audit ready evidence aligned with state and federal requirements. Responsibilities include engineering and tuning security controls, analyzing threats and vulnerabilities, onboarding and normalizing telemetry, and ensuring regulated data (FTI, CJI, PHI) is protected according to required frameworks.

This position works under limited supervision with considerable latitude for initiative and independent judgment. The Cybersecurity Engineer serves as a subject matter expert for designated platforms, provides Tier 3 technical escalation, participates in architectural and change management processes, and collaborates with operations, cloud, network, and application teams. The role may lead and guide others and contributes to the development of enterprise security standards, reference architectures, and control documentation., * Stewardship and SME for Zscaler, Proofpoint, Tenable One, Armis, Microsoft Purview, DataBahn, and Swimlane or other similar products.

  • Design, operate, and tune policies, inspection, posture management, forwarding paths, and monitoring across supported platforms.
  • Lead scanning architecture, agent deployment, asset discovery/coverage, web application scanning, risk scoring, exceptions, and remediation reporting.
  • Drive unmanaged/IoT/OT visibility, device risk policy, rogue device alerting, and inventory reconciliation (Tenable, endpoints, Entra ID, CMDB).
  • Implement sensitivity labels, auto labeling, DLP, retention, insider risk, audit, and encryption controls for FTI/CJI/PHI and privileged work product.
  • Onboard telemetry sources; standardize parsing/normalization; route/tier events; redact/mask regulated data; set retention aligned to IRS Pub. 1075 and CJIS.
  • Develop and maintain SOAR playbooks/integrations with error handling and approval gates; ensure sanitized case records and complete audit trails.
  • Provide Tier 3 escalation, cross platform troubleshooting (Windows, Linux, network), and automation using Python/PowerShell and vendor APIs (in Git).
  • Author and maintain documentation and runbooks; participate in on call rotation; provide surge relief to SOC during incidents.

Architecture & Design (~30%)

  • Maintain reference architectures and standards mapped to NIST SP 80053 and Zero Trust.
  • Act as design authority for projects, applications, cloud workloads, and thirdparty connections; document decisions and residual risk.
  • Define control boundaries and evidentiary requirements for regulated data enclaves (FTI/CJI/PHI).

  • Extend platforms across the multicloud estate (predominantly AWS) for visibility, telemetry, identity, segmentation, and encryption.
  • Develop roadmaps; forecast capacity and licensing/consumption; lead product evaluations/POCs including privacy, TX RAMP/FEDRAMP, and compliance analysis.
  • Participate in architecture and change governance; author control narratives and evidence; mentor engineers and SOC analysts.

Regulatory & Government Sector Requirements

  • IRS Pub. 1075: apply safeguarding requirements; enforce needtoknow access; FIPSvalidated encryption; extended audit/logging/retention; support SSR preparation and incident notification duties; coordinate with Privacy Officer and Child Support Division.
  • FBI CJIS: implement policy areas (screening, authentication, access, audit, media protection, physical, mobile, incident response); coordinate with CSA/CSO/LASO; apply Security Addendum; design segmentation and logging for auditable boundaries.
  • NIST/State of Texas: map capabilities to SP 80053; apply SP 800207 Zero Trust and CSF 2.0; use SP 80061/63/88/171 and FIPS 1403/199/200; align with 1 TAC 202, DIR Standards Catalog, TXRAMP; meet Texas Government Code 2054; account for Public Information Act in retention; apply HIPAA safeguards where applicable.

Performs related work as assigned Maintains relevant knowledge necessary to perform essential job functions Attends work regularly in compliance with agreedupon work schedule. Telework schedules are permitted for employees based on the agency s approved Telework Plan, as long as schedule does not adversely affect operations and service levels, and standard hours of operation are maintained. Ensures security and confidentiality of sensitive and/or protected information. Complies with all agency policies and procedures, including those pertaining to ethics and integrity.

Requirements

Education: Graduation from high school or equivalent Experience: Eight years of fulltime experience working in the following (or closely related) fields: information technology security, computer information systems, computer science, management information systems; may substitute credit hours from an accredited college or university for the required experience on a yearforyear basis. Deep production ownership of three or more primary platforms (or market equivalents) with the ability to ramp up to the rest within 12 months. Working capability across public cloud, firewalls, switching, identity provider, and at least one SIEM query language (SPL or KQL). Government/public sector experience under IRS Pub. 1075/CJIS (or comparable regime); ability to map platforms to SP 80053 and produce auditready artifacts; fluency in Zero Trust and CSF 2.0; familiarity with Texas frameworks and TXRAMP; disciplined handling of regulated data. Experience authoring reference architectures, standards, or enterpriseadopted design docs. Technical foundations: production AWS (networking, IAM, encryption, logging/security services) with Azure familiarity; Windows Server/AD and RHEL troubleshooting; networking/protocol fundamentals; Python/PowerShell and vendor APIs; Git. Knowledge of configuration management; change/problem management; risk assessment and acceptance; exception management; and security baselines (CIS, NIST, vendor STIGs). Skills in configuring, deploying, monitoring, and automating security applications and infrastructure; auditing; risk management; advising management on security configuration; and performing routine assessments of security compliance and risk mitigation. Abilities: obtain and maintain baseline certification (e.g., Security+); analyze facts and devise solutions; prepare reports; develop, evaluate, and interpret policies; communicate effectively; provide guidance to others; lead risk management function development and implementation. Ability to work more than 40 hours as needed and in compliance with the FLSA. Ability to occasionally lift and relocate up to 30 lbs. Ability to travel (including overnight travel) up to 5%, Certifications: (e.g., Zscaler, Tenable, Microsoft SCseries, Proofpoint, Armis, Swimlane); CISSP/CCSP/SABSA/TOGAF; GIAC; PCNSE/CCNP/Splunk Architect; AWS/Azure certifications; AWS Org governance/SCP/landing zone design; CSPM/CWPP at scale. Experience securing OT/building automation/physical security/forensic lab equipment. Experience designing and defending SSL/TLS inspection exception policies. Experience establishing data classification programs for legal/investigative work product. Practical experience using approved AI/LLM tooling within sanitized data guardrails. Participation in regulatory assessments (IRS Safeguards review, CJIS audit, TX RAMP/StateRAMP/FedRAMP); telemetry redaction and data minimization. Experience leading SIEM migration/log source consolidation/cost reduction; exposure management program with SLAs/exceptions/reporting.

About the company

Join us in safeguarding Texas and shaping the future of cybersecurity governance! OAG employees enjoy excellent benefits ( ) along with tremendous opportunities to do important work at a large, dynamic state agency making a positive difference in the lives of Texans.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

56 sec

Favorite git commands and the importance of patch commits

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all