Cybersecurity Engineer SME
GovCIO · Laughlin AFB, TX · 1 wk ago
On-siteInformation Technology$160k/yrFull-time
GovCIO is hiring a Cybersecurity Engineer SME to support advanced Air Force Intelligence Community (AF IC) Risk Management Framework (RMF) modernization initiatives at Lackland AFB, TX. This is an onsite position focused on cybersecurity engineering, RMF automation, and AI-enabled compliance capabilities for classified information systems.
Responsibilities
- Correlate threat data from various sources to identify hackers active in client networks and assess potential threats.
- Provide assessments and reports to enhance situational awareness of current cyber threats and adversaries.
- Develop cyber threat profiles based on geographic region, country, group, or individual actors.
- Produce cyber threat assessments based on entity threat analysis.
- Provide computer forensic and intrusion support, including evidence seizure, forensic analysis, data recovery, and network assessments.
- Research and maintain proficiency in tools, techniques, countermeasures, and trends in computer network vulnerabilities, data hiding, and network security.
- Collaborate with intrusion analysts to identify, report, and coordinate remediation of cyber threats.
- Provide timely, actionable sanitized intelligence to cyber incident response professionals.
- Leverage technical knowledge of computer systems and networks with cyber threat information to assess security posture.
- Conduct intelligence analysis to assess intrusion signatures, tactics, techniques, and procedures associated with cyber attacks.
- Research hackers, hacker techniques, vulnerabilities, and exploits; provide detailed briefings and intelligence reports to leadership.
- Engineer and automate RMF processes to improve authorization efficiency and enhance continuous monitoring.
- Develop AI-assisted analysis capabilities for cybersecurity governance workflows.
- Support system owners, ISSMs, ISSOs, Authorizing Officials (AOs), and Security Control Assessors (SCAs) with automation and engineering solutions.
- Engineer cybersecurity solutions for DoD and Intelligence Community information systems.
- Design, implement, and document security controls consistent with NIST SP 800-53 Rev. 5 and CNSSI 1253 overlays.
- Develop security architectures supporting Zero Trust, cloud, hybrid, and on-premises environments.
- Integrate cybersecurity requirements throughout the System Development Life Cycle (SDLC).
- Support Authority to Operate (ATO), Continuous Authorization (cATO), and Continuous Monitoring (ConMon) initiatives.
- Develop and maintain RMF authorization artifacts.
- Engineer automated evidence collection and validation processes.
- Develop reusable security control implementations and standardized control inheritance strategies.
- Support implementation of OSCAL-based RMF automation.
- Design and implement AI-assisted capabilities for RMF documentation, evidence management, and compliance analysis.
- Develop Retrieval-Augmented Generation (RAG) workflows for cybersecurity documentation.
- Implement Natural Language Processing (NLP) techniques to analyze RMF artifacts and identify inconsistencies.
- Develop machine learning and rule-based models with human-in-the-loop validation for AI-generated outputs.
- Apply Responsible AI principles and AI governance throughout solution development.
- Develop automated RMF workflows and integrate cybersecurity controls into CI/CD pipelines.
- Implement Security-as-Code and Policy-as-Code capabilities.
- Develop dashboards for cybersecurity metrics, authorization status, and continuous monitoring.
- Integrate automation with eMASS, Xacta, ServiceNow, vulnerability management platforms, and enterprise asset inventories.
- Engineer automated collection of cybersecurity evidence supporting continuous monitoring.
- Provide technical recommendations supporting authorization decisions.
- Support modernization of enterprise RMF processes across AF IC environments.
Requirements
- High School diploma with 10+ years of relevant experience (or commensurate experience).
- Active Top Secret/SCI clearance required.
- DOD 8140 IAT III certification required: CISSP, ISSEP, ISSAP, or CGRC.
- 10 years of experience in one or more of the following: Cybersecurity Engineering, Risk Management Framework implementation, Security Architecture, DevSecOps, Continuous Monitoring, or Security Automation.
- Minimum five years supporting DoD or Intelligence Community cybersecurity programs.
- Experience with eMASS, Xacta, NIST RMF, DoD RMF, AF IC cybersecurity processes, and classified information systems.
- Demonstrated experience with NIST SP 800-37 Rev. 2, NIST SP 800-53 Rev. 5, NIST SP 800-53A Rev. 5, NIST SP 800-137, NIST SP 800-30, FIPS 199 and 200, DoD RMF, CNSSI, ICD 50, OSCAL, Zero Trust Architecture, Continuous Authorization (cATO), and security engineering principles.
Skills
- Programming experience developing automation using Python, PowerShell, REST APIs, JSON/XML, GIT, and CI/CD platforms.
- Experience integrating with enterprise APIs and cybersecurity platforms.
- Experience implementing AI-assisted cybersecurity capabilities using Large Language Models (LLMs), Retrieval-Augmented Generation (RAG), Natural Language Processing, prompt engineering, vector databases, document intelligence, AI governance, and human-in-the-loop validation.
Preferred Skills
- Experience with the Space Force's network environment.
Pay
Posted salary range: USD $160,000.00 - USD $200,000.00 per year.