Cyber Security Engineer SME
Job Description
GovCIO LLC is hiring a Cybersecurity Engineer SME to help modernize Air Force Intelligence Community (AF IC) Risk Management Framework (RMF) processes. This onsite role at Peterson AFB, CO focuses on engineering and automating RMF capabilities, improving authorization efficiency, and enhancing continuous monitoring to support classified information systems.
In this position, you will serve as a technical lead for cybersecurity engineering, RMF automation, and AI-enabled compliance capabilities that support system owners, ISSMs, ISSOs, Authorizing Officials (AOs), and Security Control Assessors (SCAs).
What You Will Do
- Correlate threat data from multiple sources to establish the identity and modus operandi of hackers operating in client networks.
- Provide assessments and reports that improve situational awareness and help teams understand current cyber threats and adversaries.
- Develop cyber threat profiles by geographic region, country, group, or individual actor.
- Produce cyber threat assessments based on entity threat analysis.
- Support high technology investigations with computer forensics and intrusion support, including evidence seizure, forensic analysis, data recovery, and network assessments.
- Research and maintain proficiency in tools, techniques, countermeasures, and trends related to computer network vulnerabilities, data hiding, and security and encryption.
- Collaborate with intrusion analysts to identify, report, and coordinate remediation of cyber threats.
- Deliver timely, actionable sanitized intelligence to cyber incident response professionals.
- Use knowledge of computer systems and networks, combined with threat information, to assess the client’s security posture.
- Conduct intelligence analysis to assess intrusion signatures and tactics, techniques, and procedures associated with cyber attack preparation and execution.
- Research threat actors and techniques, and brief leadership with detailed intelligence reports.
- Engineer cybersecurity solutions supporting DoD and Intelligence Community information systems.
- Design, implement, and document security controls aligned with NIST SP 800-53 Rev. 5 and CNSSI 1253 overlays, as applicable.
- Support security architectures for Zero Trust, cloud, hybrid, and on-premises environments, and integrate cybersecurity requirements throughout the SDLC.
- Support ATO, cATO, and ConMon initiatives, including development and maintenance of RMF authorization artifacts.
- Engineer automated evidence collection and validation, reusable control implementations, and standardized control inheritance strategies.
- Support OSCAL-based RMF automation and design AI-assisted capabilities for RMF documentation, evidence management, and compliance analysis.
- Develop RAG workflows for cybersecurity documentation and apply NLP to analyze RMF artifacts and identify documentation inconsistencies.
- Develop machine learning and rule-based models, and implement human-in-the-loop validation for all AI-generated outputs, applying Responsible AI principles and AI governance.
- Build automated RMF workflows, integrate cybersecurity controls into CI/CD pipelines, and implement Security-as-Code and Policy-as-Code.
- Create dashboards for cybersecurity metrics, authorization status, and continuous monitoring.
- Integrate automation with eMASS, Xacta, ServiceNow, and Vuln Management platforms, plus enterprise asset inventories.
- Engineer automated collection of cybersecurity evidence supporting continuous monitoring and integrate security tooling.
- Develop automated compliance scoring and risk dashboards and provide technical recommendations supporting authorization decisions.
- Support modernization of enterprise RMF processes across AF IC environments.
Note: This position supports engineering and automating RMF processes to improve authorization efficiency. It does not perform independent security control assessments to preserve RMF assessment independence.
Required Qualifications
- Clearance Required: Top Secret/SCI
- DoD 8140 IAT III: Certification required: CISSP, ISSEP, ISSAP, or CGRC
- Minimum experience: 5 years supporting DoD or Intelligence Community cybersecurity programs
- Experience with eMASS, Xacta, NIST RMF, DoD RMF, AF IC cybersecurity processes, and classified information systems
- Demonstrated experience with NIST SP 800-37 Rev. 2, NIST SP 800-53 Rev. 5, NIST SP 800-53A Rev. 5, NIST SP 800-137, NIST SP 800-30, FIPS 199 and FIPS 200, DoD RMF, CNSSI, ICD 50, OSCAL implementation and machine-readable RMF artifacts, Zero Trust architecture, cATO, security engineering principles, DevSecOps, and security automation
- Programming experience developing automation using: Python, PowerShell, REST APIs, JSON/XML, GIT, CI/CD platforms, and integrating with enterprise APIs and cybersecurity platforms
- AI-assisted cybersecurity experience using LLMs, RAG, NLP, prompt engineering, vector databases, document intelligence, AI governance, and human-in-the-loop validation
Preferred Qualifications
- Experience with the Space Force’s network environment
Location and Salary
- Location: Peterson AFB, CO (onsite)
- Salary Range: USD 160,000 - 200,000 per year