Summary:Information Technology Services (ITS) is seeking an Information Security Engineer Level II for the Chinden office in Boise. The engineer plays a frontline role in Idaho's cyber fight by strengthening the State's cyber defenses through hands-on vulnerability management, cyber risk analysis, threat response, and security assessments.
In this role, the engineer actively tests, implements, deploys, maintains, reviews, and administers the infrastructure hardware and software that protect Idaho's statewide technology environment. The engineer works with the Cyber Operations teams to identify and remediate risks, correct misconfigurations, and resolve audit findings, directly supporting the resilience and readiness objectives of Idaho.
The position requires deep knowledge across a wide range of Cybersecurity technologies. The engineer serves as a technical and operational leader within 24/7/365 Cybersecurity Operations, performing continuous vulnerability and threat analysis, taking action on emerging and imminent cyber threats, and ensuring the effectiveness of Idaho's cyber mission by protecting, detecting, and responding to threats.
Please note: The successful candidate MUST pass a national level, fingerprint-based background check, including multiple agency specific background checks specific to handling of sensitive information related to CJIS, HIPPA, FTI, PCI and other information requiring a very high level of confidentiality.
Example of Duties:- Conducts continuous vulnerability scanning, analysis, and validation to identify weaknesses across State systems and services.
- Implements and maintains security tools, platforms, and sensors that support statewide cyber defense operations.
- Reviews, analyzes, and responds to security alerts and threat intelligence to mitigate emerging cyber threats.
- Performs hands-on remediation of misconfigurations, vulnerabilities, and audit findings to strengthen Idaho's cyber posture.
- Deploys and manages infrastructure hardware and software used in statewide detection, protection, and response capabilities.
- Supports 24/7/365 Cyber Operations by participating in incident response activities, containment actions, and threat-hunting missions.
- Collaborates with teams across State agencies to assess risks, improve security controls, and align practices with Operation Cyber Idaho objectives.
- Develops and maintains documentation, procedures, and workflows that enhance operational readiness and cyber resilience.
- Provides subject matter expertise during technical evaluations, security assessments, and modernization initiatives.
- Contributes to continuous improvement initiatives that expand Idaho's offensive and defensive cyber capabilities.
Minimum Qualifications:- Good knowledge of cybersecurity incident response and handling methodologies.
- Typically gained by at least two years of work experience in IT cybersecurity incident response and handling methodologies OR one year of work experience and two related college/vocational courses. Work experience should be within the last five years.
- Good knowledge of authentication, authorization, and access control methods.
- Typically gained by at least two years of work experience in network security OR one year of work experience and two college/vocational level courses covering security practices. Work experience should be within the last five years.
- Good knowledge of vulnerability information dissemination sources (e.g., alerts, errata, and bulletins).
- Typically gained by at least two years of professional work experience in network security OR one year of work experience and two college/vocational level courses covering security practices. Work experience should be within the last five years.
- Good knowledge of common threats, vulnerabilities, and related mitigation strategies.
- Typically gained by at least two years of work experience obtained within the last five years working in network security with routine responsibility monitoring and handling common threats, vulnerabilities, and related mitigation strategies OR one year of work experience and successful completion of at least two related college/vocational courses.
- Experience administering cryptography and cryptographic key management concepts.
- Typically gained by at least two years of work experience with the management of cryptographic keys and protecting them from loss or misuse. This encompasses generating, using, storing, archiving, and deleting keys. Work experience should be within the last five years.
Applications will be accepted through 11:59 PM MST on the posting end date. Benefits:The State of Idaho offers a robust total compensation package, including medical, vision, and dental insurance; PERSI retirement benefits; paid sick, vacation, and parental leave; and 11 paid holidays per year. For additional information related to benefits and/or State programs, please visit https://dhr.idaho.gov/StateEmployees/Benefits.html.