Cybersecurity Engineer– Administration Division – SF Municipal Transportation Agency (1044)
City and County of San Francisco · San Francisco, CA · 3 days ago
Information Technology$171k–$215k/yrFull-time
About the role
The Train Control Upgrade Project (TCUP) is a multi-year, multimillion dollar project aimed at replacing the existing train control system onboard vehicles and in the Muni Metro subway with a state-of-the-art radio-based technology. The role involves supporting the delivery of the information technology components, focusing on expanding network infrastructure, data architecture, wireless communication systems, servers, databases, and cybersecurity.
Responsibilities
- Serve as the lead cybersecurity architect for TCUP, defining the security posture for all networked, wireless, and backhaul train control systems.
- Develop and contribute to redundancy and failover strategies, ensuring network resiliency and availability while aligning with cybersecurity requirements.
- Define and document network policies, including access control, segmentation, QoS, and routing practices, ensuring alignment with cybersecurity principles.
- Assess wireless spectrum usage for security risks, interference vulnerabilities, and resiliency.
- Review and provide security oversight of network architecture, including routing, segmentation (VLANs), and multicast configurations.
- Support the design and configuration of network architecture to ensure support for secure routing, segmentation (VLANs), and multicast communications.
- Define security standards for hardware lifecycle management and support lifecycle planning decisions.
- Implement cybersecurity measures, such as firewalls, intrusion detection/prevention systems (IDS/IPS), and endpoint protection.
- Conduct periodic vulnerability assessments and ensure compliance with industry standards (e.g., NIST, CISA, ISO/IEC 27001).
- Validate cybersecurity controls in end-to-end communication systems supporting train control operations.
- Troubleshoot and resolve issues identified during testing phases.
- Develop and maintain technical documentation for network and cybersecurity architectures, configurations, and operational procedures.
- Ensure cybersecurity controls align with applicable railway safety and security standards and regulatory requirements.
- Define requirements for network and security monitoring and ensure integration with enterprise SOC/NOC tools.
Qualifications
- An associate degree in computer science, computer engineering, information systems, or a closely related field from an accredited college or university OR its equivalent in terms of total course credits/units [i.e., at least sixty (60) semester or ninety (90) quarter credits/units with a minimum of twenty (20) semester or thirty (30) quarter credits/units in one of the fields above or a closely-related field].
- Five (5) years of experience analyzing, installing, configuring, enhancing, and/or maintaining the components of a system or platform.
- One year of additional experience as described above may be substituted for the required degree.
- Completion of the 1010 Information Systems Trainee Program may be substituted for the required degree.
Desirable Qualifications
- 5+ years’ experience leading cybersecurity architecture for large, mission‑critical or safety‑critical systems.
- Knowledge of SIEM, SOAR, and/or SOC integrations for network and OT telemetry.
- 5-years’ experience securing LTE and 5G (3GPP) wireless communications for mission‑critical or operational technology environments.
- 5-years’ experience applying security principles to networks (e.g., BGP security, MPLS segmentation, multicast control).
- 5 years’ experience implementing and managing network security protocols, including encryption (e.g., IPSec, TLS), firewalls, IDS/IPS, and endpoint security.
- 5 years’ experience of cybersecurity frameworks (e.g., NIST Cybersecurity Framework, EN 50159:2010, IEC 62443) and best practices.
- 5 years’ defining, reviewing, and validating network and security test plans.
- Proficiency with tools for security validation, performance monitoring, and troubleshooting (e.g., SIEM platforms, EDR/XDR Wireshark, SolarWinds, NetScout).
- Familiarity with network equipment from major vendors (e.g. Palo Alto, Fortinet, Cisco, Juniper, Nokia, Ericsson) and radio system hardware (e.g., base stations, access points).
- 5-years’ experience working with system engineers, project managers, operations teams, and regulatory bodies to ensure alignment of system requirements and performance goals.
- 5-years’ experience designing and implementing secure system architectures using Zero Trust principles, including Identity and Access management (IAM), least privilege access, and secure system design practices across system lifecycle.
- 5-years’ experience conducting threat modeling and cybersecurity risk assessments for complex systems, with demonstrated ability to coordinate incident response activities and integrate security monitoring with enterprise SOC processes.
- 5-years’ experience securing transportation, rail, utilities, or other critical infrastructure environments.
- Ability to communicate progress and issues to stakeholders through regular status updates and technical reports.
- Experience collaborating with diverse stakeholders and fostering an inclusive environment that values different perspectives, backgrounds, and expertise to drive effective decision-making.