Cybersecurity Engineer
City of TucsonAbout the role
Posting Close Date:
Applicants must submit their completed application by 01-17-2026 at 11:59 p.m. MSTApplication and Special Instructions
As part of the application process, all applicants are required to submit a chronological resume and cover letter at the time of the application. Applications that do not include both documents by the closing date of the recruitment will be considered incomplete and will not receive further consideration for this recruitment.The City of Tucson does not provide VISA sponsorship. Candidates must be legally authorized to work in the United States at the time of application and throughout the duration of employment.
Relocation expenses will not be provided for this position. Candidates are responsible for all costs associated with relocating to the Tucson area, if applicable.
**Save the date: Highest scoring applicants will be invited to attend a virtual interview to be held on the week of January 28, 2026.
Recruiter contact information: If you have any questions, please contact Liliana Almeraz at (520 )837-4303 or Liliana.Almeraz@tucsonaz.gov.
ABOUT THIS JOB
The Cybersecurity Engineer position at the City of Tucson’s Information Technology Department is responsible for implementing and optimizing cybersecurity solutions to protect the City’s infrastructure- including cyber-physical systems and operational environments. This role supports strategic initiatives by deploying and tuning tools and developing automation to enhance detection and response.
Worked is performed under the supervision of the Information Technology Manager. This position does not supervise.
Duties and Responsibilities
- Implements cybersecurity solutions that protect enterprise Information Technology (IT) and Operational Technology (OT) environments, including Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems (ICS). Implements and maintains tools such as Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), vulnerability management platforms, email security, and cloud-native solutions. Collaborates with cross-functional teams to embed security into technology projects and deployments. Supports cloud migrations by reviewing architecture and offering secure configuration guidance.
- Develops threat detection capabilities by creating custom correlation rules, dashboards, and alerts. Optimizes incident response by identifying patterns and gaps. Automates security workflows to streamline operations and reduce response times.
- Conducts technical investigations using log correlation, forensic analysis, and root cause identification. Responds to cybersecurity incidents in real time. Coordinates remediation efforts with IT and operations teams to restore services and prevent recurrence.
- Monitors systems continuously using security tools and telemetry data. Identifies misconfigurations, vulnerabilities, and signs of malicious activity. Prioritizes risks based on severity and impact. Recommends remediation actions using current threat intelligence.
- Provides education and technical advice for securing systems and field devices, including servers, workstations, mobile devices, and OT assets. Aligns system settings with Center for Internet Security (CIS) Benchmarks, National Institute of Standards and Technology (NIST) guidelines, and City policy.
- Implements technical controls based on Zero Trust architecture and the NIST Cybersecurity Framework (CSF). Maintains secure access, data protection, segmentation, and endpoint visibility to enhance resilience and meet regulatory requirements.
- Develops security documentation such as configuration guides, standard procedures, and internal knowledge base articles. Maintains documentation to support consistent operations, training, and audit readiness.
- Performs all other duties and tasks as assigned.
All duties and responsibilities listed are subject to change.
MINIMUM QUALIFICATIONS
Education: Bachelor's DegreeExperience: Three (3) years of relevant experience
Preferred Qualifications:
Degree in Cybersecurity, Information Technology, Computer Science, or a related field.
GIAC certifications, such as:
GCIH – GIAC Certified Incident Handler
GSEC – GIAC Security Essentials Certification
GSTRT – GIAC Security Threat Intelligence
(ISC)² certifications, such as:
CISSP – Certified Information Systems Security Professional
SSCP – Systems Security Certified Practitioner
CompTIA cert
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s