Cybersecurity Engineer

The State Of Utah
Salt Lake City, UT, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$114,400.0 - $145,600.0
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) Microsoft Windows Active Directory Application Programming Interfaces (APIs) Antivirus Softwares Macintosh Computers Microsoft Azure Bash Shell Cloud Computing Cloud Computing Security CompTIA Security+ Cyber Security
+33 more
Information Leak Prevention Linux Identity and Access Management Information Sciences Intrusion Detection and Prevention Intrusion Detection Systems Virtual Private Networks (VPN) Information Systems Security Architecture Professional Python (Programming Language) Linux System Administration Log Analysis Windows Servers Network Architecture Windows PowerShell Cloud Services Reverse Proxy Secure Coding Web Application Security Security Information and Event Management Software Engineering SQL Databases Software Vulnerability Management Data Logging In-Plane Switching (IPS) Software Security Firewalls (Computer Science) Containerization Information Technology Devsecops Security Orchestration, Automation & Response Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

The Office of Legislative Services (LSO) is a non-partisan office that provides internal support to the entire legislative branch. LSO provides support in varying ways, such as human resources, finance, IT services, printing, and more! As an internal support office, we look for individuals who embody a customer service mindset and demonstrate our core values., One of the best parts about working for the Legislative Services IT team is the reach your work will have within state government. We are looking for a seasoned cybersecurity professional with deep expertise across enterprise security, application development security, networks, cloud services, and end-user protection. In this role, you will help design, implement, and continuously improve security tools, processes, reporting, services, and policies relating to our network infrastructure, applications, endpoints, identity systems, and servers. You will serve as a trusted technical advisor, owning and maintaining a multi-year cybersecurity architecture roadmap aligned with organizational priorities and help mature the organization’s overall security posture through sound engineering and secure architecture.

This is a full-time, nonpartisan position that requires flexibility to work extended hours between November and March in preparation for, and during, the annual general legislative session. During the session (January through March), employees are required to work on-site. Outside of the session, employees are primarily office-based, with the option to work remotely once a week. Employees must maintain a permanent residence in Utah., * Help lead the design and evolution of enterprise cybersecurity architecture that protects the organization’s data, systems, applications, and networks.

  • Participate in the planning, implementation, management, monitoring, and continuous improvement of security measures that protect the organization’s data, systems, and networks.
  • Review new and existing technologies, projects, and system changes to identify security risks and recommend practical, risk-based mitigations.
  • Design and review secure architecture for internally developed applications, infrastructure, identity services, and cloud-based systems.
  • Monitor for indicators of intrusion or compromise and guide advanced investigation, containment, eradication, recovery, and post-incident remediation activities.
  • Troubleshoot complex security, system, and network issues and provide risk-informed recommendations to technical and business stakeholders.
  • Administer and improve security controls across IAM, email security, endpoint security, vulnerability management, logging, and detection platforms.
  • Participate in change management, security assessments, vulnerability remediation, and application security testing, including
  • SAST/DAST and related secure development practices.
  • Develop and maintain security standards, procedures, metrics, and reporting to support compliance, operational maturity, and informed decision-making.
  • Provide technical leadership, and collaborate with internal and external groups on cybersecurity initiatives, training, and incident preparedness.

Requirements

Do you have experience in Mentoring?, Do you have a Associate’s degree?, The ideal candidate will bring strong analytical judgment, technical depth, and a comprehensive understanding of cybersecurity methodologies, engineering practices, risk-based decision-making, and long-term cybersecurity strategic planning and implementation expected of a seasoned security professional.

The Cybersecurity Engineer is expected to demonstrate meticulous attention to detail, outstanding problem-solving skills, sound technical leadership, and the ability to perform effectively under pressure and tight deadlines.

They will have extensive experience with incident response across detection, triage, containment, eradication, recovery, and post-incident remediation, as well as leading security initiatives that reduce organizational risk.

To ensure success, a Cybersecurity Engineer must be comfortable working across a wide range of technologies and collaborating effectively with internal teams, vendors, and external partners while mentoring others and driving continuous improvement.

The successful candidate will demonstrate advanced knowledge of technologies such as antimalware, SIEM, firewalls, VPN, data loss prevention, IDS/IPS, IAM, reverse proxy, WAF, application security, cloud security, endpoint protection, vulnerability management, and security automation. They will be able to translate technical findings into actionable recommendations for non-technical users, guide secure design decisions, and balance operational needs with strong security controls. A deep knowledge of the NIST Cybersecurity Framework and the ability to apply it in architecture, risk assessment, control selection, and program maturity efforts is strongly desired., * 5+ years of progressively responsible hands-on experience in cybersecurity engineering, cloud security, application security, infrastructure security, or incident response.

  • Demonstrated experience designing, implementing, and operating enterprise security controls, detection capabilities, and incident response processes with an emphasis on long-term strategic planning.
  • Practical experience with SIEM, vulnerability scanning, endpoint security, identity security, and application security testing tools such as SAST/DAST.
  • Knowledge of the following technologies; hands-on experience is preferred:

  • Windows Server, Active Directory, Entra ID, and Linux administration
  • DevOps security practices, including containerization and securing CI/CD pipelines
  • Critical subsystems of Windows, Linux, and Mac
  • SQL database security, hardening, and access controls
  • Cloud computing and security, particularly within Microsoft Azure
  • Web application security with a focus on Java, Spring, and related technologies
  • Ability to write and utilize scripts for automation, API interaction, and log analysis (PowerShell, Python, Bash, etc.)
  • One or more of the following professional certifications, or equivalent demonstrated expertise, is preferred: CompTIA Security+, CySA+, CISSP, GIAC, Azure Security Engineer Associate
  • Bachelor’s degree in computer science, information science, engineering, or a related field, or relevant work experience that demonstrates strong analytical and problem-solving aptitude

Benefits & conditions

3.63.6 out of 5 stars 1 State Office Building, Salt Lake City, UT 84114 $55 - $70 an hour - Full-time, Pulled from the full job description

  • Health insurance
  • Retirement plan
  • Dental insurance
  • Work from home, The salary range for this position is $55.00 to $70.00 per hour, plus comprehensive medical, dental, leave, and retirement benefits. The starting salary will be determined based on the successful candidate’s experience and qualifications.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

3:52 min

Avoiding remote code execution from unsanitized inputs

Alexander Pirker · WWC 2022

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all