Security Operations Engineer - IT Security - Senior/Specialist - Permanent
Listed on 2026-08-11
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Description
Title
- Security Operations Engineer
Classification- IT Security – Senior/Specialist
Job Status
- Full-Time / Permanent
WDFW Program
- Directors Office – Information Technology Services Division (ITS) – Cybersecurity Unit (CSU)
Duty Station
- Olympia, Washington – Thurston County
Hybrid/Telework
- While this position may offer a telework option, the successful candidate must be available to report to the duty station on a weekly basis.
Learn more about being a member of Team WDFW!
Cougar in tree – Photo Credit: WDFW
As the WDFW Enterprise Security Operations Engineer, you will play a key role in protecting the agency’s technology environment by designing, implementing, and monitoring application security solutions across both on-premises and cloud-based systems.
In this role, you will serve as a trusted resource for IT teams, providing technical guidance and support related to application security and security operations. You will collaborate with other security and technology leaders, including the Incident Response Engineer, SEAL Team Supervisor, Data Center Architect, and Application Development Architect, to help address security risks, strengthen configurations, and support the agency’s overall cybersecurity mission.
Whatto Expect
Among the varied range of responsibilities held within this role, the Security Operations Engineer will,
Solutions Development- Independently design, implement, and support WDFW Enterprise application security solutions for both on-premises and cloud-hosted environments, utilizing expertise in Windows Group Policy (GPO) configuration, system baseline configuration, registry edits, and scripting languages.
- Identify gaps in the agency’s security capabilities in comparison to industry standard threat research and best business practices such as the Center for Internet Security (CIS) Critical Security Controls (CSC).
- Conduct capability and integration assessments of commercial and custom solutions to ensure deployment and integration compliance.
- Coordinate with the Incident Response Engineer to ensure reviewed applications and services are integrated into the agency’s centralized monitoring and logging platform.
- Participate in “Tiger Team” architectural efforts to provide technical solutions to address agency problem sets.
- Lead and mentor team of Analysts in conducting internal security reviews for new and existing software and hardware requests, including agency systems such as the WILD licensing system, which issues commercial and recreational hunting and fishing licenses, and the Enforcement Records Management System (RMS) utilized for the processing and storing of Criminal Justice Information (CJI).
- Conduct project-specific risk assessments of WDFW applications and systems, developing and implementing remediation actions as needed.
- Review system architecture, configurations, and processes to identify potential security risks, recommend corrective actions, and develop custom configurations through scripting to support business units.
- Maintain Plans of Action and Milestones (POAM).
- Analyze WDFW vulnerability assessment reports to evaluate agency risk and develop remediation actions.
- Conduct Washington State Office of Cybersecurity (OCS) Design reviews for infrastructure and functional areas supported by this position.
- Provide senior-level guidance to the staff responsible for risk assessment, vulnerability management, and configuration management activities.
- Mentor team members and contribute to the continuous improvement of security operations processes and practices.
- Ensure staff maintain accurate documentation and performance metrics that clearly reflect completed work and the agency's risk and vulnerability posture to support informed management decisions.
- Collaborate with peer engineers and architects to resolve prioritization conflicts related to security operations initiatives.
- Review and provide feedback for security-related policy while documenting processes, procedures, and techniques that support the security policy.
- Produce and maintain…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).