
OAG - Entp Information Security | Cybersecurity An
Texas Attorney General
Job description
Please paste the following URL into a browser to view the entire job posting on the CAPPS Careers page.https://erphcmprd.cpa.texas.gov/psp/candidateportal/EMPLOYEE/HRMS/c/HRS_HRAM_FL.HRS_CG_SEARCH_FL.GBL?Page=HRS_APP_JBPST_FLandAction=UandFOCUS=ApplicantandSiteId=1andJobOpeningId=105924andPostingSeq=1Job DescriptionGENERAL DESCRIPTIONThe Office of the Attorney General is a dynamic organization with employees across the State of Texas, providing legal representation, supporting statewide programs, and protecting critical information assets. The Enterprise Information Security Team delivers security services that safeguard agency systems, data, and operations by applying strong engineering practices and modern security controls.The Cybersecurity Engineer performs advanced cybersecurity work as part of the Enterprise Information Security engineering group. The role focuses on designing, implementing, and operating enterprise security platforms; conducting technical risk assessments; supporting exposure management; and producing audit ready evidence aligned with state and federal requirements. Responsibilities include engineering and tuning security controls, analyzing threats and vulnerabilities, onboarding and normalizing telemetry, and ensuring regulated data (FTI, CJI, PHI) is protected according to required frameworks.This position works under limited supervision with considerable latitude for initiative and independent judgment. The Cybersecurity Engineer serves as a subject matter expert for designated platforms, provides Tier 3 technical escalation, participates in architectural and change management processes, and collaborates with operations, cloud, network, and application teams. The role may lead and guide others and contributes to the development of enterprise security standards, reference architectures, and control documentation.Join us in safeguarding Texas and shaping the future of cybersecurity governance! OAG employees enjoy excellent benefits (https://ers.texas.gov/Benefits-at-a-Glance) along with tremendous opportunities to do important work at a large, dynamic state agency making a positive difference in the lives of Texans.ESSENTIAL POSITION FUNCTIONSEngineering and Operations (~70%)Stewardship and SME for Zscaler, Proofpoint, Tenable One, Armis, Microsoft Purview, DataBahn, and Swimlane or other similar products.Design, operate, and tune policies, inspection, posture management, forwarding paths, and monitoring across supported platforms.Lead scanning architecture, agent deployment, asset discovery/coverage, web application scanning, risk scoring, exceptions, and remediation reporting.Drive unmanaged/IoT/OT visibility, device risk policy, rogue device alerting, and inventory reconciliation (Tenable, endpoints, Entra ID, CMDB).Implement sensitivity labels, auto labeling, DLP, retention, insider risk, audit, and encryption controls for FTI/CJI/PHI and privileged work product.Onboard telemetry sources; standardize parsing/normalization; route/tier events; redact/mask regulated data; set retention aligned to IRS Pub. 1075 and CJIS.Develop and maintain SOAR playbooks/integrations with error handling and approval gates; ensure sanitized case records and complete audit trails.Provide Tier 3 escalation, cross platform troubleshooting (Windows, Linux, network), and automation using Python/PowerShell and vendor APIs (in Git).Author and maintain documentation and runbooks; participate in on call rotation; provide surge relief to SOC during incidents.Architecture and Design (~30%)Maintain reference architectures and standards mapped to NIST SP 800-53 and Zero Trust.Act as design authority for projects, applications, cloud workloads, and third-party connections; document decisions and residual risk.Define control boundaries and evidentiary requirementsfor regulated data enclaves (FTI/CJI/PHI).Extend platforms across the multi-cloud estate (predominantly AWS) for visibility, telemetry, identity, segmentation, and encrypt on.Develop roadmaps; forecast capacity and licensing/consumption; lead product evaluations/POCs including privacy, TX RAMP/FEDRAMP, and compliance analysis.Participate in architecture and change governance; author control narratives and evidence; mentor engineers and SOC analysts.Regulatory and Government Sector RequirementsIRS Pub. 1075: apply safeguarding requirements; enforce need-to-know access; FIPS-validated encryption; extended audit/logging/retention; support SSR preparation and incident notification duties; coordinate with Privacy Officer and Child Support Division.FBI CJIS: implement policy areas (screening, authentication, access, audit, media protection, physical, mobile, incident response); coordinate with CSA/CSO/LASO; apply Security Addendum; design segmentation and logging for auditable boundaries.NIST/State of Texas: map capabilities to SP 800-53; apply SP 800-207 Zero Trust and CSF 2.0; use SP 800-61/63/88/171 and FIPS 140-3/199/200; align with 1 TAC 202, DIR Standards Catalog, TX-RAMP; meet Texas Government Code 2054; account for Public Information Act in retention; apply HIPAA safeguards where applicable.Performs related work as assignedMaintains relevant knowledge necessary to perform essential job functionsAttends work regularly in compliance with agreed-upon work schedule. Telework schedules are permitted for employees based on the agencys approved Telework Plan, as long as schedule does not adversely affect operations and service levels, and standard hours of operation are maintained.Ensures security and confidentiality of sensitive and/or protected information.Complies with all agency policies and procedures, including those pertaining to ethics and integrity. MINIMUM QUALIFICATIONSEducation: Graduation from high school or equivalentExperience: Ten years of full-time experience working in the following (or closely related) fields: information technology security, computer information systems, computer science, management information systems; may sub