Are you a cybersecurity professional with a sharp eye for threats and a passion for protecting data and infrastructure? The City of Chesapeake is seeking a
Cybersecurity Engineer to join our security team and help defend critical systems across the enterprise.
In this role, you'll be on the front lines of our cybersecurity operations - identifying, investigating, and responding to security threats, while also helping to assess and improve our overall security posture. You'll work with cutting-edge tools and take part in the City's push to securely modernize its technology landscape.
What You'll Do:
Security Architecture- Design, implement and maintain enterprise security architectures spanning hybrid cloud, virtualization, network infrastructure, and AI systems.
- Develop Zero Trust security practices including micro-segmentation, least privilege, identity-driven access, and defense-in-depth controls.
- Create and maintain reference architectures, security standards, and architectural design documentation.
- Conduct threat modeling and architectural risk assessments aligned with NIST , CIS , ISO 27001, HIPAA , CJIS , PCI , and related frameworks.
AI Security- Define and govern security requirements for AI/ML platforms, data pipelines, and model interfaces.
- Implement controls to mitigate threats such as prompt injection, model theft, data poisoning, and unauthorized API access.
Cloud Security- Design secure Azure and AWS environments including segmentation, identity integration, private access, and firewalling.
- Oversee cloud-native security controls (Azure Firewall, NSGs/ASGs, Security Groups, Network Firewall, CSPM , secrets management).
Security Engineering Oversight- Provide security principles and oversight for firewalls, network devices, endpoint security/ XDR , email security, SIEM telemetry, and vulnerability management.
- Coordinate penetration testing and drive remediation efforts.
Network Security- Define secure network design patterns for on-premises, hybrid, and cloud networks, including segmentation and perimeter architectures.
- Establish standards for firewall policies, TLS decryption, IPS , URL filtering, and SD-WAN/wireless security.
Virtualization & Operating System Security- Define secure configuration for VMware/Hyper-V, virtual switches, hardened templates, and workload segmentation.
- Define secure configuration guidelines for Windows, Linux, IoT, OT, and SCADA environments.
Threat Detection & Incident Response- Define detection engineering requirements for SIEM / XDR and guide threat-hunting activities.
- Support incident response architecture, forensics needs, and containment strategies.
Governance, Risk & Compliance- Participate in risk assessments and define mitigation strategies.
- Support audit requirements, policy development, compliance documentation, and third-party risk reviews.
Documentation & Collaboration- Produce clear documentation, diagrams, and executive-level reports.
- Collaborate with networking, systems, cloud, and application teams on architectural reviews and implementation
Required QualificationsVocational/Educational Requirement:Requires any combination of education and experience equivalent to a bachelor's degree in computer science, cybersecurity, or a closely related field.
Experience:In addition to satisfying the vocational/education standards, this job class requires a minimum of four years of related, full-time equivalent experience, preferably in a broad range computer security role. Strong technical knowledge of IT infrastructure and vulnerability patch management preferred. Must have good knowledge of commercial compliance and regulatory standards (e.g. Payment Card Industry [ PCI ], Health Insurance Portability and Accountability Act [ HIPAA ]).
Special Certifications and Licenses:Requires a valid driver's license and a driving record that is in compliance with
City Driving Standards . Industry-related certifications (e.g. ( ISC )2 Certified Information Systems Security Professional [ CISSP ], , CompTIA CySA+, GIAC CSEC ) are preferred but not required.
Special Requirements:Employees may be expected to work hours in excess of their normally scheduled hours in response to short-term department needs and/or City-wide emergencies. Emergency operations support work and work locations may be outside of normal job duties.
Preferred Qualifications - Experience with information system security and network security practices - Identity and Access Management, Privileged Access Management, Incident Management, Security baseline, and configurations
- Experience with next-generation firewalls, network security configurations, endpoint/ XDR , and cloud architectures
- Strong understanding of Zero Trust principles and NIST / CIS hardening standards
- Experience with cybersecurity risk management, threat analysis and incident response
- Working knowledge of security frameworks and compliance regulations; NIST CSF , PCI , HIPAA
- 3 years of experience configuring, managing, and securing servers and network devices to ensure system and network security safeguards are in place and meet security policy and compliance requirements
- 3 years of experience with evaluating internal and external security posture to review and make recommendations for improving organizational security posture
- 1 year of application security experience with vulnerability management tools to conduct application vulnerability scanning and remediation
- 1 year of experience working with Enterprise Applications to ensure applications are meeting security standards as part of an SDLC or OWASP principles
- Experience designing, implementing and securing cloud environments (Google, Microsoft, Amazon)
- Experience architecting hybrid on-prem/cloud security models.
- Knowledge of IoT/OT/ SCADA security.
- Experience with CASB , SaaS posture management, DLP , and email security platforms.
- Strong understanding of regulatory requirements and industry standards.
- Proven analytical and problem-solving abilities
- Ability to effectively prioritize and execute tasks in a high-pressure environment
- Good written, oral, and interpersonal communication skills
- Ability to conduct research into IT security issues and products as required
- Ability to present ideas in business-friendly and user-friendly language
- Highly self-motivated and directed
- Keen attention to detail
- Experience with third-party, vendor supply chain security management practices