Comprehensive knowledge of cybersecurity engineering, security operations, cloud security, endpoint security, identity security, email security, data protection, and incident response principles; Strong working knowledge of Microsoft 365 security, compliance, identity, endpoint, device, email, and data protection administration; Thorough knowledge of SIEM technologies, log management, security analytics, detection development, alert tuning, and response automation concepts; Thorough knowledge of vulnerability management, risk-based remediation, configuration assessment, and security control validation; Knowledge of common attack techniques, threat vectors, malware behavior, identity compromise, phishing, and business email compromise; Knowledge of cybersecurity frameworks, audit, compliance, governance, and risk management practices applicable to local government environments; Skill in analyzing security events, correlating data from multiple sources, identifying root causes, and developing effective corrective actions; Skill in administering and integrating security platforms, cloud services, APIs, scripts, and automation tools; Strong written and verbal communication, interpersonal, customer service, documentation, and problem-solving skills; Ability to communicate technical security findings, risk, impact, and remediation guidance to technical and non-technical audiences; Ability to manage and prioritize multiple incidents, projects, remediation efforts, and competing deliverables; Ability to work on call as needed; Ability to work independently, exercise sound judgment, maintain confidentiality, learn new technologies, and establish effective working relationships. The position engineers, administers, and continuously improves cybersecurity capabilities with primary responsibility for Microsoft 365 security and compliance, security information and event management (SIEM), Intrusion Detection and Prevention Systems (IDS/IPS), vulnerability management, security monitoring, and incident response.