Sr. IT Security Engineer
Listed on 2026-08-22
-
IT/Tech
Cybersecurity, IT Consultant
SUMMARY Responsible for managing the day to day operations and strategic direction of the district's Information Security (Info Sec) team, with the goal of protecting district users, data, and systems. Oversee incident response, security monitoring, and operational risk management while developing scalable processes aligned with district security goals. Monitor emerging threats, analyze vulnerabilities, and establish measurable security strategies that emphasize real-world threat mitigation and transparent communication.
Strengthen the district's overall security posture through collaborative partnerships and proactive risk management to ensure safe, reliable, and uninterrupted delivery of educational services.
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Manage day to day incident response operations, ensuring consistency, scalability, and effective delegation across the Info Sec team. Oversee ticket intake and prioritization, balancing timely response with deliberate skill development across the team.
Develop, maintain, and continuously improve a district wide incident response playbook, including procedures and escalation plans for common incidents such as phishing, student and staff technology misuse, malware, and targeted attacks.
Lead the secure design, implementation, and operation of district wide enterprise platforms, including identity and directory services, access controls, and secure code review practices.
Partner with Enterprise Architecture to define and document IT security policies, and to guide secure systems integration and application development practices that support confidentiality, integrity, and availability.
Train and mentor security personnel in threat detection, event correlation, malware analysis, and vulnerability management.
Define security requirements and oversee periodic third party security assessments to detect, evaluate, and report current risks to the district.
Monitor emerging security vulnerabilities and exploits; oversee risk analysis to evaluate threats and vulnerabilities, recommend mitigation strategies; and define measurable protection goals aligned with the district's strategic plan.
Maintain current knowledge of security technologies, industry standards, best practices, and applicable federal and state privacy laws related to education and student data protection. Provide informed recommendations that support district security and operational goals.
Advise and collaborate with other district divisions (e.g., Food Service, Human Resources, Assessment) on secure software purchasing, implementation, and development practices.
Partner with peer K-12 districts and state and federal organizations to share cybersecurity intelligence and adapt district processes to mitigate emerging threats.
Support Info Sec director in developing a strategy and measurements for the Info Sec team which manage risk associated with the business and educational functions of the District's complex networks, leveraging automation and cross departmental collaboration, to maximize limited financial and budget resources.
Provide leadership and guidance to other technical teams related to Info Sec strategic projects focusing on cloud technologies, identity management, and system integrations.
Partner with Infrastructure Services team regarding the configuration and maintenance of the District's log management system. Define system logging requirements based on best practices and PCI, HIPAA compliances. Correlate log files to ensure connected systems are collecting the appropriate events. Monitor the events for system performance and possible security vulnerabilities. Provide dashboards and metrics to show value to IT teams and District leadership.
Other duties as assigned.
EXPERIENCEMinimum 5 years of experience in information security or a related IT field, including incident response and enterprise security operations, with a demonstrated ability to successfully lead teams, work efforts, and projects of a technical nature.
EDUCATION & TRAININGBachelor's degree required. Preferred field of study of computer science, engineering or business. Additional years of experience may be considered in lieu of degree.
CERTIFICATES, LICENSES, REGISTRATIONSNone required. Industry standard certifications (e.g., Security+, GIAC Security Essentials (GSEC), GIAC Certified Incident Handler (GCIH)) preferred.
KNOWLEDGE,SKILLS AND ABILITIES
Knowledge of securing computers, networks, and managed information systems, including enterprise platforms such as identity management, access controls, and secure system integrations. Knowledge of industry standards, privacy laws, and emerging threats. Knowledge of software development and scripting (e.g., Python, C#, Power Shell, Bash), HTTP/web technologies, and OWASP…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).