Jobs · Information Technology · Colorado

Cyber Security Engineer SME

GovCIO · Aurora, Colorado, United States · 1 wk ago
On-siteInformation Technology$160k/yrFull-time

About the Role

GovCIO is currently hiring for a Cybersecurity Engineer SME to support advanced Air Force Intelligence Community (AF IC) Risk Management Framework (RMF) modernization initiatives. The successful candidate will serve as a technical lead for cybersecurity engineering, RMF automation, and AI-enabled compliance capabilities supporting classified information systems. This position will be located at Peterson AFB, CO and will be an onsite position.

Responsibilities

  • Correlates threat data from various sources to establish the identity and modus operandi of hackers active in client's networks and posing a potential threat.
  • Provides the customer with assessments and reports facilitating situational awareness and understanding of current cyber threats and adversaries.
  • Develops cyber threat profiles based on geographic region, country, group, or individual actors.
  • Produces cyber threat assessments based on entity threat analysis.
  • May provide computer forensic and intrusion support to high technology investigations in the form of computer evidence seizure, computer forensic analysis, data recovery, and network assessments.
  • Researches and maintains proficiency in tools, techniques, countermeasures, and trends in computer network vulnerabilities, data hiding, network security, and encryption.
  • Collaborates with intrusion analysts to identify, report on, and coordinate remediation of cyber threats to the client.
  • Provides timely and actionable sanitized intelligence to cyber incident response professionals.
  • Leverages technical knowledge of computer systems and networks with cyber threat information to assess the client's security posture.
  • Conducts intelligence analysis to assess intrusion signatures, tactics, techniques, and procedures associated with preparation for and execution of cyber attacks.
  • Researches hackers, hacker techniques, vulnerabilities, exploits, and provides detailed briefings and intelligence reports to leadership.
  • Engineers cybersecurity solutions supporting DoD and Intelligence Community information systems.
  • Designs, implements, and documents security controls consistent with NIST SP 800-53 Rev. 5 and CNSSI 1253 overlays, as applicable.
  • Develops security architectures supporting Zero Trust, cloud, hybrid, and on-premises environments.
  • Integrates cybersecurity requirements throughout the System Development Life Cycle (SDLC).
  • Supports Authority to Operate (ATO), Continuous Authorization (cATO), and Continuous Monitoring (ConMon) initiatives.
  • Develops and maintains RMF authorization artifacts.
  • Engineers automated evidence collection and validation processes.
  • Develops reusable security control implementations and standardized control inheritance strategies.
  • Supports implementation of OSCAL-based RMF automation.
  • Designs and implements AI-assisted capabilities supporting RMF documentation, evidence management, and compliance analysis.
  • Develops Retrieval-Augmented Generation (RAG) workflows for cybersecurity documentation.
  • Implements Natural Language Processing (NLP) techniques to analyze RMF artifacts and identify documentation inconsistencies.
  • Develops machine learning and rule-based models.
  • Implements human-in-the-loop validation for all AI-generated outputs.
  • Applies Responsible AI principles and AI governance throughout solution development.
  • Develops automated RMF workflows.
  • Integrates cybersecurity controls into CI/CD pipelines.
  • Implements Security-as-Code and Policy-as-Code capabilities.
  • Develops dashboards supporting cybersecurity metrics, authorization status, and continuous monitoring.
  • Integrates automation with eMASS, Xacta, ServiceNow, Vuln Management platforms, and Enterprise asset inventories.
  • Engineers automated collection of cybersecurity evidence supporting continuous monitoring.
  • Integrates security tooling.
  • Develops automated compliance scoring and risk dashboards.
  • Provides technical recommendations supporting authorization decisions.
  • Supports modernization of enterprise RMF processes across AF IC environments.

Qualifications

  • High School with 10+ years (or commensurate experience)

Required Skills and Experience

  • Clearance Required: Top Secret/SCI
  • DoD 8140 IAT III certification required: CISSP, ISSEP, ISSAP, CGRC
  • 10 years of experience in one or more of the following: Cybersecurity Engineering, Risk Management Framework implementation, Security Architecture, DevSecOps, Continuous Monitoring, Security Automation
  • Minimum five years supporting DoD or Intelligence Community cybersecurity programs
  • Experience with eMASS, Xacta, NIST RMF, DoD RMF, AF IC cybersecurity processes, Classified information systems
  • Demonstrated experience with NIST SP 800-37 Rev. 2, NIST SP 800-53 Rev. 5, NIST SP 800-53A Rev. 5, NIST SP 800-137, NIST SP 800-30, FIPS 199 and 200, DoD RMF, CNSSI, ICD 50, OSCAL implementation and machine-readable RMF artifacts, Zero Trust Architecture, Continuous Authorization (cATO), Security engineering principles, DevSecOps, Security automation
  • Programming Experience developing automation using: Python, PowerShell, REST APIs, JSON/XML, GIT, CI/CD Platforms, integrating with enterprise APIs and cybersecurity platforms
  • Experience implementing AI-assisted cybersecurity capabilities using Large Language Models (LLMs), Retrieval-Augmented Generation (RAG), Natural Language Processing, Prompt engineering, Vector databases, Document intelligence, AI governance, Human-in-the-loop validation

Preferred Skills and Experience

  • Experience with the Space Force's network environment

Pay

Posted Salary Range: USD $160,000.00 - USD $200,000.00 /Yr.

Similar jobs