Cybersecurity Operations Engineer

GranicusDenver, CO
$93,800 - $120,000Remote

About The Position

Granicus is seeking a Cybersecurity Operations Engineer to operate, monitor, and continuously improve the cybersecurity controls protecting a mission-critical SaaS product. Granicus provides purpose-built cloud technology and services that help government organizations deliver more accessible, effective, and trusted digital experiences for the communities they serve. As a global organization, Granicus supports customers and operations across North America, the United Kingdom, Europe, Australia, and New Zealand, delivering cloud platforms that power critical digital services for government agencies and public sector organizations worldwide. The Cybersecurity Operations Engineer will be one of two hands-on individual contributors responsible for preserving the confidentiality, integrity, and availability of a Granicus SaaS product hosted in Amazon Web Services (AWS) and subject to FedRAMP and Criminal Justice Information Services (CJIS) security requirements. The role will operate endpoint protection, centralized security logging and analytics, vulnerability management, and related cloud security controls; monitor the environment; triage and investigate security events; support incident response; execute operational activities for the Granicus data protection program; and contribute to other cybersecurity initiatives. The position reports to the Cybersecurity Operations Lead within the Global Cyber Defense organization led by the Senior Director, Global Cyber Defense. This role must be based in the United States and must possess or be able to obtain and maintain the personnel screening and access authorization required for CJIS-regulated environments.

Requirements

  • Strong knowledge of security operations and security engineering for cloud-hosted SaaS products, with practical understanding of AWS environments and the cloud shared-responsibility model.
  • Working knowledge of FedRAMP continuous monitoring, NIST SP 800-53 security controls, the CJIS Security Policy, and the operational expectations of regulated cloud environments.
  • Hands-on ability to operate endpoint detection and response, centralized logging and security analytics, vulnerability management, and cloud security monitoring capabilities.
  • Strong understanding of AWS identity, networking, compute, storage, logging, encryption, key management, and security-relevant configuration practices.
  • Ability to maintain reliable security telemetry pipelines, including log collection, parsing, normalization, enrichment, retention, access, and quality monitoring.
  • Ability to write and modify investigative queries, detections, and correlation logic and to analyze identity, endpoint, network, application, and cloud security events.
  • Practical incident response skills including scoping, evidence handling, containment, eradication, recovery, root-cause analysis, and corrective action management.
  • Knowledge of vulnerability management practices including asset discovery, scanning, validation, risk prioritization, remediation coordination, exception handling, and verification.
  • Knowledge of enterprise data protection practices including data discovery, classification, access governance, encryption, monitoring, retention, data loss prevention, and response to suspected misuse or exfiltration.
  • Experience using scripting, APIs, query languages, and workflow automation to improve security operations, evidence collection, reporting, and tool integration.
  • Ability to use AI-enabled capabilities responsibly, including human validation, prompt and data handling controls, quality measurement, explainability, and auditability.
  • Ability to maintain clear operational metrics, runbooks, case records, evidence, and technical documentation suitable for regulated and audited environments.
  • Strong analytical, troubleshooting, and decision-making skills, including the ability to remain effective during high-severity incidents.
  • Ability to translate cybersecurity and compliance requirements into practical technical actions and sustainable operating procedures.
  • Strong collaboration skills and the ability to work effectively across Security, Product, Engineering, Cloud, Compliance, Privacy, Legal, and business teams.
  • Strong written and verbal communication skills, including the ability to explain technical findings, security risk, and response actions to technical and non-technical stakeholders.
  • Ability to manage multiple priorities independently, recognize when escalation is required, and deliver reliable outcomes in a fast-paced and evolving cybersecurity environment.
  • 3+ years of experience in cybersecurity engineering, security operations, cloud security, incident response, or related roles.
  • Demonstrated hands-on experience operating security monitoring, endpoint protection, vulnerability management, and incident response capabilities in an AWS-hosted production cloud or SaaS environment.
  • Experience triaging and investigating security events and supporting incidents from initial detection through containment, recovery, and lessons learned.
  • Experience working with cloud and application logs, security analytics, detection queries, case management, and vulnerability remediation workflows.
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent professional experience.

Nice To Haves

  • Experience supporting a FedRAMP-authorized, CJIS-regulated, or similarly controlled environment is strongly preferred.
  • Experience supporting operational data protection activities and applying automation or AI-assisted capabilities to security workflows is preferred.
  • Relevant cybersecurity, cloud security, incident response, or security operations certifications are preferred.

Responsibilities

  • Perform day-to-day security operations and security engineering for the designated SaaS product and its supporting AWS environment.
  • Execute security controls and operating procedures that preserve the confidentiality, integrity, and availability of the product and its data.
  • Apply FedRAMP, NIST SP 800-53, the CJIS Security Policy, and Granicus security requirements in daily operational and technical activities.
  • Complete assigned continuous monitoring, control testing, audit evidence, corrective action, and authorization maintenance activities in partnership with Governance, Risk, and Compliance, Product, Cloud Engineering, Site Reliability Engineering, and system owners.
  • Identify control gaps, configuration deviations, and emerging technical risk; resolve issues within assigned authority and promptly escalate material concerns.
  • Operate and maintain endpoint detection and response, centralized security logging and analytics, vulnerability scanning and management, and related cloud security capabilities supporting the product.
  • Verify that in-scope assets are inventoried and monitored, security telemetry is collected and retained, agents and sensors remain healthy, and coverage gaps are corrected.
  • Onboard and maintain security log sources, including parsing, normalization, enrichment, alert routing, retention, access, and data quality.
  • Execute vulnerability scans, validate findings, prioritize risk using exploitability and asset context, coordinate remediation, track exceptions, and verify corrective actions.
  • Build and maintain dashboards and operational reporting for asset coverage, control health, vulnerability exposure, alert trends, response performance, compliance posture, and residual risk.
  • Maintain integrations between security capabilities and cloud, engineering, service management, and collaboration systems to improve data quality, response speed, and operational consistency.
  • Monitor security alerts and telemetry, triage events, manage cases, and ensure assigned work is handled consistently and within established response expectations.
  • Investigate identity, endpoint, network, application, and cloud activity; correlate evidence to determine event scope, impact, root cause, and required action.
  • Develop, test, and tune detections, correlation logic, and investigative queries for threats relevant to the product environment while reducing false positives.
  • Perform or support incident response activities including scoping, evidence preservation, containment, eradication, recovery, root-cause analysis, and corrective action tracking.
  • Execute incident response playbooks, escalation paths, notification procedures, exercises, and post-incident reviews suitable for FedRAMP- and CJIS-regulated operations.
  • Maintain complete, accurate, and auditable investigation records, incident timelines, evidence, decisions, and required reports; participate in after-hours response when required.
  • Work closely with the Cybersecurity Operations Lead and the other Cybersecurity Operations Engineer to provide dependable monitoring, investigation, and incident response coverage.
  • Follow and continuously improve runbooks, operating procedures, quality standards, service metrics, shift handoffs, and escalation practices.
  • Maintain cross-training and backup capability for the team's core responsibilities, take ownership of assigned work, and support teammates during periods of elevated demand.
  • Escalate complex, high-severity, or time-sensitive issues promptly and provide clear technical context, evidence, impact analysis, and recommended actions.
  • Contribute to a culture of technical excellence, sound judgment, collaboration, accountability, knowledge sharing, and continuous improvement.
  • Execute assigned operational activities for the Granicus enterprise data protection program under the direction of the Cybersecurity Operations Lead.
  • Support controls for data discovery, classification, handling, access, encryption, monitoring, retention, and secure disposal across relevant environments.
  • Monitor, triage, and investigate suspected data leakage, misuse, or policy violations in coordination with incident response, Privacy, Legal, and business processes.
  • Maintain data protection workflows, evidence, metrics, dashboards, exception records, and remediation tracking that demonstrate control coverage and effectiveness.
  • Partner with Privacy, Legal, Information Technology, Product, Engineering, and business stakeholders to implement protective controls, manage exceptions, and reduce data risk.
  • Use approved AI-assisted analysis and automation throughout monitoring, investigations, vulnerability management, data protection, compliance evidence, reporting, and engineering workflows.
  • Automate repetitive activities such as alert enrichment, case creation, evidence collection, asset reconciliation, vulnerability prioritization, notification, and status reporting.
  • Validate AI-generated insights and apply human-in-the-loop safeguards so sensitive data is handled in accordance with security, privacy, customer, and regulatory requirements.
  • Use scripting, APIs, query languages, and workflow orchestration to improve the speed, consistency, scalability, and auditability of security processes.
  • Propose, test, document, and measure improvements to detections, tooling, workflows, and controls based on operational outcomes, reliability, and controlled risk.
  • Partner with Product, Engineering, Cloud, Compliance, Privacy, and business teams supporting the designated SaaS product and data protection program.
  • Provide practical security input for architecture decisions, platform changes, releases, remediation plans, risk decisions, and customer assurance activities.
  • Communicate findings, incident status, priorities, tradeoffs, and program performance clearly to technical and non-technical stakeholders.
  • Support other cybersecurity projects and operational activities as assigned by the Cybersecurity Operations Lead or Senior Director, Global Cyber Defense.

Benefits

  • Flexible Time Off
  • Company-Wide Wellbeing Days
  • Work From Home Reimbursement
  • Multiple Health Plan Options
  • Employer HSA Contributions
  • Fitness Reimbursement Program
  • On-Demand Mental Health Support
  • Paid Parental Leave
  • Traditional & Roth 401(k)
  • Life & AD&D Insurance
  • Online Learning Platforms
  • Competitive Salary & Bonuses
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service