Cybersecurity Red Team & Security Engineering Manager

Texas Health and Human Services Commission
  • Austin, TX
  • $8,488.33–$14,356 Per Year
6 days ago

Job Description

Join the Texas Health and Human Services Commission (HHSC) and be part of a team committed to creating a positive impact in the lives of fellow Texans. At HHSC, your contributions matter, and we support you at each stage of your life and work journey. Our comprehensive benefits package includes 100% paid employee health insurance for full-time eligible employees, a defined benefit pension plan, generous time off benefits, numerous opportunities for career advancement and more. Explore more details on the Benefits of Working at HHS webpage.

Functional Title: Cybersecurity Red Team & Security Engineering Manager

Job Title: Cybersecurity Analyst IV

Agency: Health & Human Services Comm

Department: CHIEF INFO SECURITY OFFICE

Posting Number: 20373

Closing Date: 10/24/2026

Posting Audience: Internal and External

Occupational Category: Computer and Mathematical

Salary Range: $8,488.33 - $14,356.00

Pay Frequency: Monthly

Salary Group: TEXAS-B-29

Shift: Day

Additional Shift: Days (First)

Telework:

Travel:

Regular/Temporary: Regular

Full Time/Part Time: Full time

FLSA Exempt/Non-Exempt: Exempt

Facility Location:

Job Location City: AUSTIN

Job Location Address: 701 W 51ST ST

Other Locations:

MOS Codes: 0605,0630,0631,0639,0670,0679,0681,1702,1705,1710,1720,1721,1799,2611,2659,8055,8858,14N,14NX,170A

170B,17A,17B,17C,17C0,17DX,17S,17SX,17X,181X,182X,183X,184X,1B4X1,1D7X1,1N4X1,255A,255N,255S,25B,25D

26A,26B,26Z,514A,5C0X1D,5C0X1N,5C0X1R,5C0X1S,5IX,681X,682X,683X,781X,782X,783X,784X,CTI,CTM,CTR,CWT

CYB10,CYB11,CYB12,CYB13,CYB14,IS,ISM,ISS,IT,ITS

Brief Job Description:

This position is open to U.S. Citizens and permanent residents.

This onsite role requires the selected candidate to work from an HHS office in Austin, Texas.

The Cybersecurity Analyst IV performs advanced managerial and cybersecurity leadership work with emphasis on security engineering, adversary emulation, penetration testing, breach attack simulation, security architecture validation, cybersecurity automation, and defensive capability enhancement. The role supports agency cybersecurity objectives by leading Red Team operations and enterprise security engineering functions that strengthen the organizations ability to prevent, detect, respond to, and recover from cybersecurity threats.

The Red Team & Security Engineering Manager is responsible for leading the agencys offensive security and cybersecurity engineering programs. This position provides strategic leadership and advanced technical expertise in adversary emulation, penetration testing, attack simulation, detection engineering, security automation, cloud security engineering, threat-informed defense, and security control effectiveness validation.

The Manager develops and maintains programs designed to evaluate the effectiveness of security controls, identify gaps in cybersecurity defenses, and enhance operational detection and response capabilities. This position serves as a critical leader in advancing the agencys cybersecurity maturity through the development of innovative security engineering solutions, continuous security testing, and collaborative security improvement initiatives.

This position performs highly advanced cybersecurity management and information security work. The Manager works under minimal supervision with extensive latitude for the use of initiative and independent judgment, reporting to the Deputy CISO. The Manager oversees security engineering and offensive security operations, establishes strategic priorities, develops program objectives, manages assigned personnel, and provides senior-level consultation regarding cybersecurity technologies, risks, and defensive capabilities.

The Manager partners closely with Cybersecurity Operations, Governance Risk & Compliance, Infrastructure Services, Cloud Operations, Application Development, Enterprise Architecture, Incident Response, and executive leadership to mature the overall security posture of the organization.

Essential Job Functions (EJFs):

Attends work on a regular and predictable schedule following agency leave policy and performs other duties as assigned.

Security Engineering Program Leadership - 30%

  • Directs and oversees enterprise cybersecurity engineering activities supporting agency security operations, monitoring, automation, and defensive technology platforms.
  • Establishes engineering strategies for improving threat detection, cloud security, endpoint protection, identity protection, security monitoring, and operational resilience.
  • Provides technical and strategic leadership for cybersecurity engineering initiatives, tool modernization efforts, and enterprise security architecture improvements.
  • Develops roadmaps and operational plans that align cybersecurity engineering efforts with agency objectives and risk management priorities.
  • Evaluates emerging technologies and security capabilities to improve enterprise cyber defense effectiveness.
  • Oversees maintenance and upgrades of the SecOps technology stack.

Red Team Operations & Adversary Emulation - 25%

  • Leads enterprise Red Team activities, penetration testing exercises, security assessments, breach attack simulations, exfiltration testing, and adversary emulation engagements.
  • Directs testing activities designed to evaluate the effectiveness of administrative, technical, and operational security controls.
  • Oversees assessments of cloud environments, applications, network infrastructure, identity platforms, and emerging technologies.
  • Coordinates Purple Team activities between offensive security personnel and cybersecurity operations teams to improve detection and response capabilities.
  • Develops recommendations and remediation strategies based on identified vulnerabilities, control weaknesses, and security gaps.

Security Architecture & Strategic Advisory - 15%

  • Provides senior-level consultation regarding security architecture, cloud security, application security, infrastructure protection, and cybersecurity modernization initiatives.
  • Participates in enterprise design reviews, major project reviews, and strategic technology initiatives.
  • Advises leadership regarding security capability gaps, emerging threats, technology risk, and cybersecurity investments.
  • Supports development of security standards, engineering requirements, and technical security baselines.

Detection Engineering & Defensive Improvement - 10%

  • Oversees development and improvement of detection use cases, threat analytics, monitoring strategies, and cybersecurity automation capabilities.
  • Ensures threat-informed defensive strategies are aligned with current adversary tactics, techniques, and procedures (TTPs).
  • Supports improvements to Security Operations Center visibility, telemetry coverage, and investigative capabilities.
  • Promotes the use of threat intelligence and MITRE ATT&CK methodologies to improve detection effectiveness and coverage.

Team Leadership & Personnel Management - 10%

  • Supervises cybersecurity engineers, Red Team personnel, and other assigned cybersecurity staff.
  • Establishes performance expectations, develops work assignments, and supports employee development and training initiatives.
  • Assists with recruiting, interviewing, onboarding, mentoring, and workforce development activities.
  • Promotes collaboration across cybersecurity teams and technical disciplines.

Program Oversight & Strategy - 10%

  • Develops operational metrics, performance measurements (KPIs), strategic initiatives, and program reporting.
  • Supports cybersecurity governance activities by ensuring engineering and testing programs align with agency objectives and regulatory requirements.
  • Assists with budgeting, procurement activities, project planning, and resource allocation.
  • Performs additional duties as assigned.

Knowledge, Skills and Abilities (KSAs):

Knowledge of:

  • Offensive security methodologies, penetration testing techniques, adversary emulation practices, and Red Team operations.
  • Enterprise security architecture, cloud security, application security, identity security, and network security technologies.
  • Security engineering principles, cybersecurity monitoring architectures, automation frameworks, and detection engineering methodologies.
  • Threat intelligence, threat hunting methodologies, MITRE ATT&CK framework, and modern adversary tactics and techniques.
  • Risk management concepts, security frameworks, and cybersecurity best practices.
  • Personnel management principles, project management methodologies, and organizational leadership practices.

Skill in:

  • Leading highly technical cybersecurity engineering and offensive security teams.
  • Adversary emulation, penetration testing, security validation, and security assessments.
  • Cybersecurity strategy development and program management.
  • Analyzing complex cybersecurity risks and developing remediation strategies.
  • Communicating technical concepts to executive leadership and non-technical stakeholders.
  • Planning, organizing, and directing large-scale cybersecurity initiatives.

Ability to:

  • Lead strategic cybersecurity programs and technical teams.
  • Translate complex technical findings into business-focused recommendations.
  • Establish priorities and allocate resources across multiple cybersecurity initiatives.
  • Build effective partnerships with technical, business, and executive stakeholders.
  • Drive continuous improvement across offensive security, security engineering, and security operations programs.
  • Manage multiple high-priority projects, investigations, and strategic initiatives simultaneously.

Registrations, Licensure Requirements or Certifications:

Prefer one or more of the following certifications:

  • Certified Information Systems Security Professional (CISSP)
  • Certified Cloud Security Professional (CCSP)
  • Certified Information Systems Manager (CISM)
  • GIAC Certified Security Operations Manager (GSOM)
  • GIAC Penetration Tester (GPEN)
  • GIAC Red Team Professional (GRTP)
  • GIAC Defensible Security Architecture (GDSA)
  • Offensive Security Certified Professional (OSCP)
  • Offensive Security Experienced Penetration Tester (OSEP)
  • Certified Ethical Hacker (CEH)
  • Practical Network Penetration Tester (PNPT)

Initial Screening Criteria:

  • Graduation from an accredited four-year college or university with major coursework in information technology security, computer information systems, computer science, management information systems, or a related field is strongly preferred. Education and experience may be substituted for one another on a year for year basis.
  • A minimum of 7+ years of experience in information technology, cybersecurity, information security, offensive security, security engineering, security operations, security architecture, or related disciplines.
  • A minimum of 3+ years of experience leading cybersecurity red teams preferred.
  • A minimum of 5+ years of experience with enterprise security technologies including SIEM, EDR/XDR, cloud security, identity security, email security, network security, vulnerability management, and security automation platforms.
  • Experience conducting or directly overseeing penetration testing, adversary emulation, breach attack simulation, threat modeling, Red Team operations, Purple Team exercises, or cybersecurity assessments is preferred.

Additional Information:

Any employment offer is contingent upon available budgeted funds. The offered salary will be determined in accordance with budgetary limits and the requirements of HHSC Human Resources Manual.

Selected candidates must be legally authorized to work in the U.S. without sponsorship.

Selected candidate must be willing to commute to the office on the required days.

#LI-IN1

Review our Tips for Success when applying for jobs at DFPS, DSHS and HHSC.

Active Duty, Military, Reservists, Guardsmen, and Veterans:

Military occupation(s) that relate to the initial selection criteria and registration or licensure requirements for this position may include, but not limited to those listed in this posting. All active-duty military, reservists, guardsmen, and veterans are encouraged to apply if qualified to fill this position. For more information please see the Texas State Auditor's Job Descriptions, Military Crosswalk and Military Crosswalk Guide at Texas State Auditors Office - Job Descriptions.

ADA Accommodations:

In compliance with the Americans with Disabilities Act (ADA), HHSC and DSHS agencies will provide reasonable accommodation during the hiring and selection process for qualified individuals with a disability. If you need assistance completing the on-line application, contact the HHS Employee Service Center at 1-888-894-4747. If you are contacted for an interview and need accommodation to participate in the interview process, please notify the person scheduling the interview.

Pre-Employment Checks and Work Eligibility:

Depending on the program area and position requirements, applicants selected for hire may be required to pass background and other due diligence checks.

HHSC uses E-Verify. You must bring your I-9 documentation with you on your first day of work. Download the I-9 Form

Telework Disclaimer:

This position may be eligible for telework. Please note, all HHS positions are subject to state and agency telework policies in addition to the discretion of the direct supervisor and business needs.

Numbers & Facts

LocationAustin, TX
Salary$8,488.33–$14,356 Per Year

Skills

  • Americans with Disabilities Act (ADA)unmatched
  • Analysis Skillsunmatched
  • Applications Securityunmatched
  • Automationunmatched
  • Best Practicesunmatched
  • Budgetingunmatched
  • CCSP - Cisco Certified Security Professionalunmatched
  • CEH - Certified Ethical Hackerunmatched
  • CISM - Certified Information Security Managerunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Cloud Applicationsunmatched
  • Cloud Computingunmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Continuous Improvementunmatched
  • Department of Health and Human Servicesunmatched
  • Email Securityunmatched
  • Emerging Technologyunmatched
  • Endpoint Securityunmatched
  • Engineering Managementunmatched
  • Enterprise Architectureunmatched
  • Enterprise Protectionunmatched
  • Establish Prioritiesunmatched
  • GIAC - Global Information Assurance Certificationunmatched
  • GPEN - GIAC Penetration Testerunmatched
  • Human Resourcesunmatched
  • Huntingunmatched
  • Incident Responseunmatched
  • Information Technology & Information Systemsunmatched
  • Information/Data Security (InfoSec)unmatched
  • Infrastructure as a Service (IaaS)unmatched
  • Internet Securityunmatched
  • Leadershipunmatched
  • Management of Information Systems/Technology (MIS)unmatched
  • Mathematicsunmatched
  • Mentoringunmatched
  • Network Administration/Managementunmatched
  • Network Securityunmatched
  • Network Testingunmatched
  • Onboardingunmatched
  • Operational Improvementunmatched
  • Operational Strategyunmatched
  • Operational Supportunmatched
  • Operations Managementunmatched
  • Operations Planningunmatched
  • Operations Security (OPSEC)unmatched
  • Penetration Testingunmatched
  • People Managementunmatched
  • Performance Metricsunmatched
  • Process Improvementunmatched
  • Project Planningunmatched
  • Project/Program Managementunmatched
  • Purchasing/Procurementunmatched
  • Quality Assurance Methodologyunmatched
  • Regulatory Requirementsunmatched
  • Resource Managementunmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Risk Managementunmatched
  • Security Analysisunmatched
  • Security Architectureunmatched
  • Security Attacksunmatched
  • Security Information and Event Management (SIEM)unmatched
  • Security Infrastructureunmatched
  • Security Monitoringunmatched
  • Simulationunmatched
  • Software Developmentunmatched
  • Software Engineeringunmatched
  • Staff Developmentunmatched
  • Standards Developmentunmatched
  • Strategic Planningunmatched
  • Team Lead/Managerunmatched
  • Team Playerunmatched
  • Technical Strategyunmatched
  • Telemetryunmatched
  • Test Designunmatched
  • Test Programunmatched
  • Testingunmatched
  • Threat Modelingunmatched
  • Training/Teachingunmatched
  • Use Casesunmatched
  • Validation Testingunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder