OAG - Child Support | Cybersecurity Engineer ( Cybersecurity Analyst IV ) | 27-0036

Texas Health and Human Services Commission

$100K — $120K *
Education, Government & Non-Profit
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in information security or related fields, with a focus on government/public sector compliance.
  • Expertise in at least three cybersecurity platforms like Zscaler, Proofpoint, or Tenable.
  • Solid understanding of NIST SP 80053, Zero Trust frameworks, and related compliance standards.
  • Hands-on experience with AWS and familiarity with Azure; proficiency in Windows and Linux environments.
  • Strong scripting skills in Python and PowerShell, along with experience in Git.

Responsibilities

  • Design and implement security policies across enterprise platforms.
  • Conduct technical risk assessments and lifecycle management for security controls.
  • Lead efforts for threat detection, vulnerability scanning, and remediation reporting.
  • Onboard and normalize telemetry from various sources while ensuring data protection compliance.
  • Develop SOAR playbooks and manage automated incident responses.
  • Participate in architecture governance and establish security standards.

Benefits

  • Telework flexibility as per agency-approved plans.
  • Opportunities for career development and certification support.
  • Participation in on-call rotation for incident response management.
  • Access to mentoring and guidance from experienced cybersecurity professionals.
Full Job Description
Job Description

The Cybersecurity Engineer performs advanced cybersecurity work as part of the Enterprise Information Security engineering group. The role focuses on designing, implementing, and operating enterprise security platforms; conducting technical risk assessments; supporting exposure management; and producing audit ready evidence aligned with state and federal requirements. Responsibilities include engineering and tuning security controls, analyzing threats and vulnerabilities, onboarding and normalizing telemetry, and ensuring regulated data (FTI, CJI, PHI) is protected according to required frameworks.

This position works under limited supervision with considerable latitude for initiative and independent judgment. The Cybersecurity Engineer serves as a subject matter expert for designated platforms, provides Tier 3 technical escalation, participates in architectural and change management processes, and collaborates with operations, cloud, network, and application teams. The role may lead and guide others and contributes to the development of enterprise security standards, reference architectures, and control documentation.

ESSENTIAL POSITION FUNCTIONS

Engineering & Operations (~70%)

  • Stewardship and SME for Zscaler, Proofpoint, Tenable One, Armis, Microsoft Purview, DataBahn, and Swimlane or other similar products.
  • Design, operate, and tune policies, inspection, posture management, forwarding paths, and monitoring across supported platforms.
  • Lead scanning architecture, agent deployment, asset discovery/coverage, web application scanning, risk scoring, exceptions, and remediation reporting.
  • Drive unmanaged/IoT/OT visibility, device risk policy, rogue device alerting, and inventory reconciliation (Tenable, endpoints, Entra ID, CMDB).
  • Implement sensitivity labels, auto labeling, DLP, retention, insider risk, audit, and encryption controls for FTI/CJI/PHI and privileged work product.
  • Onboard telemetry sources; standardize parsing/normalization; route/tier events; redact/mask regulated data; set retention aligned to IRS Pub. 1075 and CJIS.
  • Develop and maintain SOAR playbooks/integrations with error handling and approval gates; ensure sanitized case records and complete audit trails.
  • Provide Tier 3 escalation, cross platform troubleshooting (Windows, Linux, network), and automation using Python/PowerShell and vendor APIs (in Git).
  • Author and maintain documentation and runbooks; participate in on call rotation; provide surge relief to SOC during incidents.

Architecture & Design (~30%)
  • Maintain reference architectures and standards mapped to NIST SP 80053 and Zero Trust.
  • Act as design authority for projects, applications, cloud workloads, and thirdparty connections; document decisions and residual risk.
  • Define control boundaries and evidentiary requirements
    for regulated data enclaves (FTI/CJI/PHI).
  • Extend platforms across the multicloud estate (predominantly AWS) for visibility, telemetry, identity, segmentation, and encryption.
  • Develop roadmaps; forecast capacity and licensing/consumption; lead product evaluations/POCs including privacy, TX RAMP/FEDRAMP, and compliance analysis.
  • Participate in architecture and change governance; author control narratives and evidence; mentor engineers and SOC analysts.

Regulatory & Government Sector Requirements
  • IRS Pub. 1075: apply safeguarding requirements; enforce needtoknow access; FIPSvalidated encryption; extended audit/logging/retention; support SSR preparation and incident notification duties; coordinate with Privacy Officer and Child Support Division.
  • FBI CJIS: implement policy areas (screening, authentication, access, audit, media protection, physical, mobile, incident response); coordinate with CSA/CSO/LASO; apply Security Addendum; design segmentation and logging for auditable boundaries.
  • NIST/State of Texas: map capabilities to SP 80053; apply SP 800207 Zero Trust and CSF 2.0; use SP 80061/63/88/171 and FIPS 1403/199/200; align with 1 TAC 202, DIR Standards Catalog, TXRAMP; meet Texas Government Code 2054; account for Public Information Act in retention; apply HIPAA safeguards where applicable.

Performs related work as assigned
Maintains relevant knowledge necessary to perform essential job functions
Attends work regularly in compliance with agreedupon work schedule. Telework schedules are permitted for employees based on the agency's approved Telework Plan, as long as schedule does not adversely affect operations and service levels, and standard hours of operation are maintained.
Ensures security and confidentiality of sensitive and/or protected information.
Complies with all agency policies and procedures, including those pertaining to ethics and integrity.

MINIMUM QUALIFICATIONS

Education: Graduation from high school or equivalent
Experience: Eight years of fulltime experience working in the following (or closely related) fields: information technology security, computer information systems, computer science, management information systems; may substitute credit hours from an accredited college or university for the required experience on a yearforyear basis.
Deep production ownership of three or more primary platforms (or market equivalents) with the ability to ramp up to the rest within 12 months.
Working capability across public cloud, firewalls, switching, identity provider, and at least one SIEM query language (SPL or KQL).
Government/public sector experience under IRS Pub. 1075/CJIS (or comparable regime); ability to map platforms to SP 80053 and produce auditready artifacts; fluency in Zero Trust and CSF 2.0; familiarity with Texas frameworks and TXRAMP; disciplined handling of regulated data.
Experience authoring reference architectures, standards, or enterpriseadopted design docs.
Technical foundations: production AWS (networking, IAM, encryption, logging/security services) with Azure familiarity; Windows Server/AD and RHEL troubleshooting; networking/protocol fundamentals; Python/PowerShell and vendor APIs; Git.
Knowledge of configuration management; change/problem management; risk assessment and acceptance; exception management; and security baselines (CIS, NIST, vendor STIGs).
Skills in configuring, deploying, monitoring, and automating security applications and infrastructure; auditing; risk management; advising management on security configuration; and performing routine assessments of security compliance and risk mitigation.
Abilities: obtain and maintain baseline certification (e.g., Security+); analyze facts and devise solutions; prepare reports; develop, evaluate, and interpret policies; communicate effectively; provide guidance to others; lead risk management function development and implementation.
Ability to work more than 40 hours as needed and in compliance with the FLSA.
Ability to occasionally lift and relocate up to 30 lbs.
Ability to travel (including overnight travel) up to 5%

PREFERRED QUALIFICATIONS

Certifications: (e.g., Zscaler, Tenable, Microsoft SCseries, Proofpoint, Armis, Swimlane); CISSP/CCSP/SABSA/TOGAF; GIAC; PCNSE/CCNP/Splunk Architect; AWS/Azure certifications; AWS Org governance/SCP/landing zone design; CSPM/CWPP at scale.
Experience securing OT/building automation/physical security/forensic lab equipment.
Experience designing and defending SSL/TLS inspection exception policies.
Experience establishing data classification programs for legal/investigative work product.
Practical experience using approved AI/LLM tooling within sanitized data guardrails.
Participation in regulatory assessments (IRS Safeguards review, CJIS audit, TX RAMP/StateRAMP/FedRAMP); telemetry redaction and data minimization.
Experience leading SIEM migration/log source consolidation/cost reduction; exposure management program with SLAs/exceptions/reporting.

To apply for a job with the OAG, electronic applications can be submitted through CAPPS Recruit. A State of Texas application must be completed to be considered, and paper applications are not accepted. Your application for this position may subject you to a criminal background check pursuant to the Texas Government Code. Military Crosswalk information can be accessed at: https://hr.sao.texas.gov/Compensation/MilitaryCrosswalk/MOSC_InformationTechnology.pdf

Similar Jobs

More Jobs at Texas Health and Human Services Commission

More Education, Government & Non-Profit Jobs

Find similar OAG - Child Support | Cybersecurity Engineer ( Cybersecurity Analyst IV ) | 27-0036 jobs: