Cybersecurity Engineer
TalentAlly · Chesapeake, VA · 2 wk ago
OTHRFull-time
About the role
The City of Chesapeake is seeking a Cybersecurity Engineer to join our security team and help defend critical systems across the enterprise. In this role, you'll be on the front lines of our cybersecurity operations - identifying, investigating, and responding to security threats, while also helping to assess and improve our overall security posture.
Responsibilities
You'll work with cutting-edge tools and take part in the City's push to securely modernize its technology landscape. Your responsibilities will include:
- Security Architecture: Design, implement and maintain enterprise security architectures spanning hybrid cloud, virtualization, network infrastructure, and AI systems.
- Develop Zero Trust security practices including microsegmentation, least privilege, identity-driven access, and defense-in-depth controls.
- Create and maintain reference architectures, security standards, and architectural design documentation.
- Conduct threat modeling and architectural risk assessments aligned with NIST, CIS, ISO 27001, HIPAA, CJIS, PCI, and related frameworks.
- AI Security: Define and govern security requirements for AI/ML platforms, data pipelines, and model interfaces.
- Implement controls to mitigate threats such as prompt injection, model theft, data poisoning, and unauthorized API access.
- Cloud Security: Design secure Azure and AWS environments including segmentation, identity integration, private access, and firewalling.
- Oversee cloud-native security controls (Azure Firewall, NSGs/ASGs, Security Groups, Network Firewall, CSPM, secrets management).
- Security Engineering Oversight: Provide security principles and oversight for firewalls, network devices, endpoint security/XDR, email security, SIEM telemetry, and vulnerability management.
- Coordinate penetration testing and drive remediation efforts.
- Network Security: Define secure network design patterns for on-premises, hybrid, and cloud networks, including segmentation and perimeter architectures.
- Establish standards for firewall policies, TLS decryption, IPS, URL filtering, and SDWAN/wireless security.
- Virtualization & Operating System Security: Define secure configuration for VMware/HyperV, virtual switches, hardened templates, and workload segmentation.
- Define secure configuration guidelines for Windows, Linux, IoT, OT, and SCADA environments.
- Threat Detection & Incident Response: Define detection engineering requirements for SIEM/XDR and guide threat-hunting activities.
- Support incident response architecture, forensics needs, and containment strategies.
- Governance, Risk & Compliance: Participate in risk assessments and define mitigation strategies.
- Support audit requirements, policy development, compliance documentation, and third-party risk reviews.
- Documentation & Collaboration: Produce clear documentation, diagrams, and executive-level reports.
- Collaborate with networking, systems, cloud, and application teams on architectural reviews and implementation.
Requirements
This role requires a strong cybersecurity professional with a sharp eye for threats and a passion for protecting data and infrastructure.