Principal Cyber Security Engineer
Listed on 2026-06-13
-
IT/Tech
Cybersecurity, Systems Engineer
Overview
The Principal Cyber Security Engineer is the state's primary technical authority for advanced endpoint defense, Zero Trust Architecture (ZTA), overarching cybersecurity architecture, and the resolution of high‑complexity security incidents across a unique hybrid ecosystem. The role functions as a senior technical specialist responsible for engineering the enterprise security stack to protect a progressive Google cloud environment (Google Workspace, GCP) and a robust Windows enterprise infrastructure.
Responsibilities- Architectural Leadership & CISO Advisory:
Serves as the state’s lead security architect, defining overarching cybersecurity architecture across all domains, advising the CISO on emerging threats, evaluating enterprise‑wide security investments, and setting state‑wide technical standards. - Endpoint & Zero Trust Engineering:
Leads engineering for Crowd Strike Falcon and enterprise Zero Trust frameworks, architecting conditional access policies that securely bridge Google environments with Active Directory. - Infrastructure Optimization:
Optimizes sensor and log ingestion across Windows servers, cloud‑native workloads, and multi‑cloud (GCP/Azure/AWS) environments to ensure 100% visibility. - Tier 4 Incident Response:
Serves as the final escalation point for the most complex security breaches, performing deep‑dive forensics spanning memory analysis on obfuscated Windows malware to anomalous behavioral tracking within Google Workspace audit logs. - Containment & Remediation:
Reconstructs attack timelines, identifies persistence, and leads technical containment for state‑level crises. - Security Automation:
Utilizes Python, Power Shell, and Bash to automate complex security workflows and builds custom API bridges utilizing Google Workspace Admin SDK, GCP Security Command Center, and Crowd Strike APIs to orchestrate automated response actions. - Compliance‑as‑Code:
Designs infrastructure security using IaC (Terraform/Ansible) to ensure all systems meet CJIS, IRS Pub 1075, and NIST 800‑53 requirements by default. - Infrastructure Hardening:
Implements hardening baselines tailored for both cloud‑native workloads and Windows systems based on emerging threat intelligence. - Threat Modeling & Mentorship:
Performs proactive threat modeling on new enterprise systems before deployment and provides technical mentorship to CSOC analysts and junior engineers.
- Mastery of general cybersecurity architecture, enterprise defense strategies, and unified threat management.
- Expert knowledge of the Crowd Strike Falcon platform, Real Time Response (RTR), sensor deployment, Windows kernel hardening, and Active Directory security.
- Deep expertise in securing Google environments (Google Workspace, GCP IAM, Security Command Center) and bridging cloud environments with Active Directory.
- Expert proficiency in Python and Power Shell for security automation and REST API interaction (especially Google Admin SDK and Crowd Strike APIs).
- Advanced knowledge of memory forensics, malware analysis, and cloud telemetry hunting via the MITRE ATT&CK framework.
- Working knowledge of applying CJIS, IRS Pub 1075, and NIST 800‑53 controls to both cloud and local assets.
- Ability to translate complex technical risks into business terms for executive leadership.
Preference may be given to candidates with a proven track record of handling high‑stakes breaches and managing enterprise‑scale security platforms across hybrid Windows/Cloud environments, as well as verifiable project history in custom security tooling and integration.
Education & ExperienceMinimum qualifications:
Bachelor's Degree (typically in Computer Technology) and 1–3 years of progressive work experience, or 4–7 years of progressive work experience in lieu of a degree. No specific certifications required.
- Typically, the employee may sit comfortably to perform the work; however, some walking, standing, bending, carrying light items, driving an automobile, etc. may be required.
- Special physical demands are not required to perform the work.
- Comprehensive health, dental, and vision insurance.
- Paid vacation, sick leave, FMLA,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).