> Markdown version of [/jobs/ext/3016790-security-analyst-iii](https://www.wearedevelopers.com/jobs/ext/3016790-security-analyst-iii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Analyst III - **Company:** Johnson County Government - **Location:** Olathe, KS, United States - **Experience:** Expert - **Salary:** $107,369.0 - $147,632.0 - **Contract:** Permanent contract - **Skills:** Active Directory, Software System Penetration Testing, Microsoft Azure, Unix, CompTIA Security+, Cyber Security, Supervisory Control and Data Acquisition (SCADA), Identity and Access Management, Intrusion Detection and Prevention, Network Security, Microsoft Security Essentials, Microsoft Office, Phishing, Secure Coding, Web Application Security, Security Information and Event Management, Software Vulnerability Management, Scripting, Firewalls (Computer Science), Information Technology, Cybercrime, CIS Benchmarks, Security Orchestration, Automation & Response, Vulnerability Analysis - **Published:** September 20, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=f3f6fd511e71b925 ## About the Role This highly technical and strategic professional will bring demonstrated experience in cybersecurity operations, risk management, security architecture, and incident response. The ideal candidate will possess deep expertise in email security, threat detection, vulnerability management, and security automation, with strong experience leveraging Microsoft security technologies, including Microsoft Defender for Office 365 Plan 2. This position offers an exciting opportunity to drive innovation, improve security processes, and help shape the future of cybersecurity within one of the region's most respected local governments., * Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related field. * 8+ years of information technology experience, including 5+ years in information security, risk management, vulnerability management, and security operations. * Experience leading security initiatives, projects, and continuous improvement efforts. * Hands-on experience with Microsoft Defender for Office 365 Plan 2, including threat protection, phishing detection, policy management, and automated investigation and response. * Experience developing security automation workflows, incident response processes, and threat hunting capabilities using SIEM, SOAR, and EDR technologies. * Experience conducting vulnerability assessments, penetration testing, and security reviews across infrastructure, systems, and applications. * Working knowledge of network and security management tools, vulnerability management platforms, Active Directory, next-generation firewalls, scripting languages, and Unix-based environments. * Experience with Microsoft security technologies, including Active Directory, Exchange, Azure, Entra ID, Purview, and Microsoft Defender solutions. * Knowledge of security frameworks, standards, and regulations, including NIST, ISO, CJIS, HIPAA, PCI, CIS Benchmarks, and STIGs. * Strong analytical, problem-solving, communication, collaboration, and relationship-building skills, with the ability to explain technical concepts to diverse audiences. * Professional cybersecurity certifications such as CISSP, CompTIA Security+, or related credentials are preferred. * Experience in security automation, project management, and operational technology environments (SCADA/ICS) is preferred. * Valid driver's license required. * Willingness to work additional or irregular hours as needed; on call once every four to six weeks. * Residency within Johnson County, KS or the greater Kansas City metro is required. ## Description Johnson County (Kansas) Government is excited to announce the search for a Security Analyst III. This critical cybersecurity leadership role will help safeguard the County's technology environment and information assets while supporting the delivery of essential public services. The Security Analyst III will serve as a senior key contributor in strengthening the County's overall security posture, leading major security initiatives, and advancing security automation and threat protection capabilities across the organization., Reporting to the Cyber Security & Risk Manager, the Security Analyst III will work collaboratively with technology teams, department leaders, and business stakeholders to identify risks, implement controls, and ensure compliance with regulatory and industry standards. Johnson County is committed to ongoing professional development and encourages participation in advanced training opportunities, including SANS cybersecurity courses and other specialized programs. Responsibilities: Security Operations & Risk Management * Strengthen the County's cybersecurity posture through evaluation of security technologies, processes, and controls. * Conduct risk assessments of systems, applications, and proposed technology changes to identify security vulnerabilities. * Develop and maintain security policies, procedures, and standards aligned with industry best practices. * Monitor compliance with applicable security, privacy, and regulatory requirements. * Analyze and respond to security incidents, advisories, alerts, and emerging threats across County systems. Threat Protection, Vulnerability Management & Automation * Optimize Microsoft Defender for Office 365 Plan 2 capabilities, including threat protection, phishing detection, and automated investigation and response. * Develop and maintain security automation workflows to improve vulnerability management and incident response processes. * Conduct vulnerability scans, penetration testing, and security assessments of infrastructure and applications. * Lead web application security testing efforts and coordinate remediation with development teams. * Perform threat hunting activities using SIEM, EDR, and related security tools. Collaboration, Training & Project Leadership * Collaborate with technology teams to standardize and improve security processes across the organization. * Conduct Identity and Access Management reporting and auditing activities. * Lead security-related projects, including the implementation of new security technologies and tools. * Promote secure development practices and provide guidance on secure coding standards. * Train end users and support security awareness initiatives throughout the organization. * Manage security-related tools, contracts, and vendor relationships. * Participate in the cybersecurity on-call rotation. ## Related Videos - [WeAreDevelopers LIVE - Node and Package Security](https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Time Paradox: Building Timezone-Safe Python/Django Applications](https://www.wearedevelopers.com/videos/1915-the-time-paradox-building-timezone-safe-python-django-applications) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)