Base Career helps you apply smarter for this job.
Key skills for this role
Granicus is driven by the excitement of building, implementing, and maintaining technology that is transforming the Govtech industry by bringing governments and its constituents together. We are on a mission to support our customers with meeting the needs of their communities and implementing our technology in ways that are equitable and inclusive. Granicus has consistently appeared on the GovTech 100 list over the past 5 years and has been recognized as the best companies to work on BuiltIn.
Over the last 25 years, we have served 5,500 federal, state, and local government agencies and more than 300 million citizen subscribers power an unmatched Subscriber Network that use our digital solutions to make the world a better place. With comprehensive cloud-based solutions for communications, government website design, meeting and agenda management software, records management, and digital services, Granicus empowers stronger relationships between government and residents across the U.S., U.K., Australia, New Zealand, and Canada. By simplifying interactions with residents, while disseminating critical information, Granicus brings governments closer to the people they serve—driving meaningful change for communities around the globe.
Want to know more? See more of what we do here .
Granicus is seeking a Cybersecurity Operations Engineer to operate, monitor, and continuously improve the cybersecurity controls protecting a mission-critical SaaS product.
Granicus provides purpose-built cloud technology and services that help government organizations deliver more accessible, effective, and trusted digital experiences for the communities they serve.
As a global organization, Granicus supports customers and operations across North America, the United Kingdom, Europe, Australia, and New Zealand , delivering cloud platforms that power critical digital services for government agencies and public sector organizations worldwide.
The Cybersecurity Operations Engineer will be one of two hands-on individual contributors responsible for preserving the confidentiality, integrity, and availability of a Granicus SaaS product hosted in Amazon Web Services (AWS) and subject to FedRAMP and Criminal Justice Information Services (CJIS) security requirements. The role will operate endpoint protection, centralized security logging and analytics, vulnerability management, and related cloud security controls; monitor the environment; triage and investigate security events; support incident response; execute operational activities for the Granicus data protection program; and contribute to other cybersecurity initiatives. The position reports to the Cybersecurity Operations Lead within the Global Cyber Defense organization led by the Senior Director, Global Cyber Defense. This role must be based in the United States and must possess or be able to obtain and maintain the personnel screening and access authorization required for CJIS-regulated environments.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
, USA
, USA
, USA
, USA
, USA
, USA
, USA
, USA
Regulated SaaS Security Operations Perform day-to-day security operations and security engineering for the designated SaaS product and its supporting AWS environment. Execute security controls and operating procedures that preserve the confidentiality, integrity, and availability of the product and its data. Apply FedRAMP, NIST SP 800-53, the CJIS Security Policy, and Granicus security requirements in daily operational and technical activities. Complete assigned continuous monitoring, control testing, audit evidence, corrective action, and authorization maintenance activities in partnership with Governance, Risk, and Compliance, Product, Cloud Engineering, Site Reliability Engineering, and system owners. Identify control gaps, configuration deviations, and emerging technical risk; resolve issues within assigned authority and promptly escalate material concerns.
Perform day-to-day security operations and security engineering for the designated SaaS product and its supporting AWS environment.
Execute security controls and operating procedures that preserve the confidentiality, integrity, and availability of the product and its data.
Apply FedRAMP, NIST SP 800-53, the CJIS Security Policy, and Granicus security requirements in daily operational and technical activities.
Complete assigned continuous monitoring, control testing, audit evidence, corrective action, and authorization maintenance activities in partnership with Governance, Risk, and Compliance, Product, Cloud Engineering, Site Reliability Engineering, and system owners.
Identify control gaps, configuration deviations, and emerging technical risk; resolve issues within assigned authority and promptly escalate material concerns.
Security Platform and Control Operations Operate and maintain endpoint detection and response, centralized security logging and analytics, vulnerability scanning and management, and related cloud security capabilities supporting the product. Verify that in-scope assets are inventoried and monitored, security telemetry is collected and retained, agents and sensors remain healthy, and coverage gaps are corrected. Onboard and maintain security log sources, including parsing, normalization, enrichment, alert routing, retention, access, and data quality. Execute vulnerability scans, validate findings, prioritize risk using exploitability and asset context, coordinate remediation, track exceptions, and verify corrective actions. Build and maintain dashboards and operational reporting for asset coverage, control health, vulnerability exposure, alert trends, response performance, compliance posture, and residual risk. Maintain integrations between security capabilities and cloud, engineering, service management, and collaboration systems to improve data quality, response speed, and operational consistency.
Operate and maintain endpoint detection and response, centralized security logging and analytics, vulnerability scanning and management, and related cloud security capabilities supporting the product.
Verify that in-scope assets are inventoried and monitored, security telemetry is collected and retained, agents and sensors remain healthy, and coverage gaps are corrected.
Onboard and maintain security log sources, including parsing, normalization, enrichment, alert routing, retention, access, and data quality.
Execute vulnerability scans, validate findings, prioritize risk using exploitability and asset context, coordinate remediation, track exceptions, and verify corrective actions.
Build and maintain dashboards and operational reporting for asset coverage, control health, vulnerability exposure, alert trends, response performance, compliance posture, and residual risk.
Maintain integrations between security capabilities and cloud, engineering, service management, and collaboration systems to improve data quality, response speed, and operational consistency.
Monitoring, Detection, Investigation, and Incident Response Monitor security alerts and telemetry, triage events, manage cases, and ensure assigned work is handled consistently and within established response expectations. Investigate identity, endpoint, network, application, and cloud activity; correlate evidence to determine event scope, impact, root cause, and required action. Develop, test, and tune detections, correlation logic, and investigative queries for threats relevant to the product environment while reducing false positives. Perform or support incident response activities including scoping, evidence preservation, containment, eradication, recovery, root-cause analysis, and corrective action tracking. Execute incident response playbooks, escalation paths, notification procedures, exercises, and post-incident reviews suitable for FedRAMP- and CJIS-regulated operations. Maintain complete, accurate, and auditable investigation records, incident timelines, evidence, decisions, and required reports; participate in after-hours response when required.
Monitor security alerts and telemetry, triage events, manage cases, and ensure assigned work is handled consistently and within established response expectations.
Investigate identity, endpoint, network, application, and cloud activity; correlate evidence to determine event scope, impact, root cause, and required action.
Develop, test, and tune detections, correlation logic, and investigative queries for threats relevant to the product environment while reducing false positives.
Perform or support incident response activities including scoping, evidence preservation, containment, eradication, recovery, root-cause analysis, and corrective action tracking.
Execute incident response playbooks, escalation paths, notification procedures, exercises, and post-incident reviews suitable for FedRAMP- and CJIS-regulated operations.
Maintain complete, accurate, and auditable investigation records, incident timelines, evidence, decisions, and required reports; participate in after-hours response when required.
Operational Readiness and Team Collaboration Work closely with the Cybersecurity Operations Lead and the other Cybersecurity Operations Engineer to provide dependable monitoring, investigation, and incident response coverage. Follow and continuously improve runbooks, operating procedures, quality standards, service metrics, shift handoffs, and escalation practices. Maintain cross-training and backup capability for the team's core responsibilities, take ownership of assigned work, and support teammates during periods of elevated demand. Escalate complex, high-severity, or time-sensitive issues promptly and provide clear technical context, evidence, impact analysis, and recommended actions. Contribute to a culture of technical excellence, sound judgment, collaboration, accountability, knowledge sharing, and continuous improvement.
Work closely with the Cybersecurity Operations Lead and the other Cybersecurity Operations Engineer to provide dependable monitoring, investigation, and incident response coverage.
Follow and continuously improve runbooks, operating procedures, quality standards, service metrics, shift handoffs, and escalation practices.
Maintain cross-training and backup capability for the team's core responsibilities, take ownership of assigned work, and support teammates during periods of elevated demand.
Escalate complex, high-severity, or time-sensitive issues promptly and provide clear technical context, evidence, impact analysis, and recommended actions.
Contribute to a culture of technical excellence, sound judgment, collaboration, accountability, knowledge sharing, and continuous improvement.
Data Protection Program Operations Execute assigned operational activities for the Granicus enterprise data protection program under the direction of the Cybersecurity Operations Lead. Support controls for data discovery, classification, handling, access, encryption, monitoring, retention, and secure disposal across relevant environments. Monitor, triage, and investigate suspected data leakage, misuse, or policy violations in coordination with incident response, Privacy, Legal, and business processes. Maintain data protection workflows, evidence, metrics, dashboards, exception records, and remediation tracking that demonstrate control coverage and effectiveness. Partner with Privacy, Legal, Information Technology, Product, Engineering, and business stakeholders to implement protective controls, manage exceptions, and reduce data risk.
Execute assigned operational activities for the Granicus enterprise data protection program under the direction of the Cybersecurity Operations Lead.
Support controls for data discovery, classification, handling, access, encryption, monitoring, retention, and secure disposal across relevant environments.
Monitor, triage, and investigate suspected data leakage, misuse, or policy violations in coordination with incident response, Privacy, Legal, and business processes.
Maintain data protection workflows, evidence, metrics, dashboards, exception records, and remediation tracking that demonstrate control coverage and effectiveness.
Partner with Privacy, Legal, Information Technology, Product, Engineering, and business stakeholders to implement protective controls, manage exceptions, and reduce data risk.
AI, Automation, and Continuous Improvement Use approved AI-assisted analysis and automation throughout monitoring, investigations, vulnerability management, data protection, compliance evidence, reporting, and engineering workflows. Automate repetitive activities such as alert enrichment, case creation, evidence collection, asset reconciliation, vulnerability prioritization, notification, and status reporting. Validate AI-generated insights and apply human-in-the-loop safeguards so sensitive data is handled in accordance with security, privacy, customer, and regulatory requirements. Use scripting, APIs, query languages, and workflow orchestration to improve the speed, consistency, scalability, and auditability of security processes. Propose, test, document, and measure improvements to detections, tooling, workflows, and controls based on operational outcomes, reliability, and controlled risk.
Use approved AI-assisted analysis and automation throughout monitoring, investigations, vulnerability management, data protection, compliance evidence, reporting, and engineering workflows.
Automate repetitive activities such as alert enrichment, case creation, evidence collection, asset reconciliation, vulnerability prioritization, notification, and status reporting.
Validate AI-generated insights and apply human-in-the-loop safeguards so sensitive data is handled in accordance with security, privacy, customer, and regulatory requirements.
Use scripting, APIs, query languages, and workflow orchestration to improve the speed, consistency, scalability, and auditability of security processes.
Propose, test, document, and measure improvements to detections, tooling, workflows, and controls based on operational outcomes, reliability, and controlled risk.
Cross-Functional Collaboration and Cybersecurity Projects Partner with Product, Engineering, Cloud, Compliance, Privacy, and business teams supporting the designated SaaS product and data protection program. Provide practical security input for architecture decisions, platform changes, releases, remediation plans, risk decisions, and customer assurance activities. Communicate findings, incident status, priorities, tradeoffs, and program performance clearly to technical and non-technical stakeholders. Support other cybersecurity projects and operational activities as assigned by the Cybersecurity Operations Lead or Senior Director, Global Cyber Defense.
Partner with Product, Engineering, Cloud, Compliance, Privacy, and business teams supporting the designated SaaS product and data protection program.
Provide practical security input for architecture decisions, platform changes, releases, remediation plans, risk decisions, and customer assurance activities.
Communicate findings, incident status, priorities, tradeoffs, and program performance clearly to technical and non-technical stakeholders.
Support other cybersecurity projects and operational activities as assigned by the Cybersecurity Operations Lead or Senior Director, Global Cyber Defense.
3+ years of experience in cybersecurity engineering, security operations, cloud security, incident response, or related roles.
Demonstrated hands-on experience operating security monitoring, endpoint protection, vulnerability management, and incident response capabilities in an AWS-hosted production cloud or SaaS environment.
Experience triaging and investigating security events and supporting incidents from initial detection through containment, recovery, and lessons learned.
Experience working with cloud and application logs, security analytics, detection queries, case management, and vulnerability remediation workflows.
Experience supporting a FedRAMP-authorized, CJIS-regulated, or similarly controlled environment is strongly preferred.
Experience supporting operational data protection activities and applying automation or AI-assisted capabilities to security workflows is preferred.
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent professional experience.
Relevant cybersecurity, cloud security, incident response, or security operations certifications are preferred.
Don’t have all the skills/experience mentioned above? At Granicus, we are trying to build diverse, inclusive teams. We do not have degree requirements for most of our roles. If you don’t meet every requirement above but are excited to learn more, we encourage you to apply. We might just be able to find another role that could be a perfect fit!
We are a remote-first company with a globally distributed workforce across the United States, Canada, United Kingdom, India, Armenia, Australia, and New Zealand.
At Granicus, we are building a transparent, inclusive, and safe space for everyone who wants to be a part of our journey.
A few culture highlights include – Employee Resource Groups to encourage diverse voices
Coffee with Mark sessions – Our employees get to interact with our CEO on very important and sometimes difficult issues ranging from mental health to work-life balance and current affairs.
Microsoft Teams communities focused on wellness, art, furbabies, family, parenting, and more.
We bring in special guests from time to time to discuss issues that impact our employee population
We are proud to serve dynamic organizations around the globe that use our digital solutions to make the world a better place — quite literally. We have so many powerful success stories that illustrate how our solutions are impacting the world. See more of our impact here .
Flexibility & Balance
Flexible Time Off – Take the time you need to rest, recharge, and live your life.
Company-Wide Wellbeing Days – Paid days off to unplug and focus on your mental health.
Work From Home Reimbursement – Support a productive home office environment.
Multiple Health Plan Options – Including a 100% employer-paid plan.
Employer HSA Contributions – When enrolled in a High-Deductible Health Plan.
Fitness Reimbursement Program – Stay active, your way.
On-Demand Mental Health Support – Access to Headspace and other wellness tools.
Paid Parental Leave – For both birthing and non-birthing parents.
Traditional & Roth 401(k) – With a generous company match.
Life & AD&D Insurance – 100% employer-paid coverage for peace of mind.
Online Learning Platforms – Fuel your professional development.
Competitive Salary & Bonuses – Your contributions are valued and rewarded.
Private GovTech software and digital-services provider helping governments improve resident engagement, service delivery, and public-sector operations.
Visit company websiteJobs and hiring trendsUSD 93800-120000 yearly / year
Full-time
Mid · 3+ years experience
Remote
Apply faster on company sites with our extension.