Cybersecurity Engineer SME
Job Description
GovCIO LLC is hiring a Cybersecurity Engineer SME to support Air Force Intelligence Community (AF IC) Risk Management Framework (RMF) modernization efforts at Lackland AFB, TX (onsite). In this role, you will lead cybersecurity engineering work focused on RMF automation and AI-enabled compliance capabilities for classified information systems, helping improve authorization efficiency and continuous monitoring.
This position operates as an engineering and modernization partner to stakeholders involved in cybersecurity governance, including system owners, ISSMs, ISSOs, Authorizing Officials (AOs), and Security Control Assessors (SCAs). The work centers on engineering and automating RMF processes and integrating technical analysis into governance workflows, while maintaining assessment independence by not performing independent security control assessments.
Key Responsibilities
- Correlate threat data from multiple sources to identify hacker identities and modus operandi targeting client networks.
- Provide assessments and reporting that improve situational awareness and understanding of current cyber threats and adversaries.
- Develop cyber threat profiles based on geographic region, country, group, or individual actors.
- Produce cyber threat assessments using entity threat analysis.
- May support computer forensics and intrusion activities for high technology investigations, including evidence seizure, forensic analysis, data recovery, and network assessments.
- Research and maintain proficiency in tools, techniques, countermeasures, and trends related to computer network vulnerabilities, data hiding, and network security and encryption.
- Collaborate with intrusion analysts to identify, report on, and coordinate remediation of cyberthreats.
- Deliver timely and actionable sanitized intelligence to cyber incident response professionals.
- Use knowledge of computer systems and networks along with cyber threat information to assess the client’s security posture.
- Conduct intelligence analysis of intrusion signatures and tactics, techniques, and procedures tied to preparation for and execution of cyber attacks.
- Research hackers, hacker techniques, vulnerabilities, and exploits, and provide detailed briefings and intelligence reports to leadership.
- Engineer cybersecurity solutions supporting DoD and Intelligence Community information systems.
- Design, implement, and document security controls aligned with NIST SP 800-53 Rev. 5 and applicable CNSSI 1253 overlays.
- Develop security architectures supporting Zero Trust, cloud, hybrid, and on-premises environments.
- Integrate cybersecurity requirements throughout the System Development Life Cycle (SDLC).
- Support Authority to Operate (ATO), Continuous Authorization (cATO), and Continuous Monitoring (ConMon) initiatives.
- Develop and maintain RMF authorization artifacts.
- Engineer automated evidence collection and validation processes.
- Develop reusable security control implementations and standardized control inheritance strategies.
- Support implementation of OSCAL-based RMF automation.
- Design and implement AI-assisted capabilities for RMF documentation, evidence management, and compliance analysis.
- Develop Retrieval-Augmented Generation (RAG) workflows for cybersecurity documentation.
- Implement NLP techniques to analyze RMF artifacts and identify documentation inconsistencies.
- Develop machine learning and rule-based models, including human-in-the-loop validation for AI-generated outputs.
- Apply Responsible AI principles and AI governance throughout solution development.
- Develop automated RMF workflows and integrate cybersecurity controls into CI/CD pipelines.
- Implement Security-as-Code and Policy-as-Code capabilities.
- Develop dashboards supporting cybersecurity metrics, authorization status, and continuous monitoring.
- Integrate automation with eMASS, Xacta, ServiceNow, vulnerability management platforms, and enterprise asset inventories.
- Engineer automated collection of cybersecurity evidence supporting continuous monitoring, including security tooling integration.
- Develop automated compliance scoring and risk dashboards and provide technical recommendations supporting authorization decisions.
- Support modernization of enterprise RMF processes across AF IC environments.
Requirements
- Clearance Required: Top Secret/SCI
- DOD 8140 IAT III certification required: CISSP, ISSEP, ISSAP, or CGRC
- Experience: 10 years in one or more of: Cybersecurity Engineering, RMF implementation, Security Architecture, DevSecOps, Continuous Monitoring, Security Automation
- Minimum experience: five years supporting DoD or Intelligence Community cybersecurity programs
- Experience with eMASS, Xacta, NIST RMF, DoD RMF, AF IC cybersecurity processes, and classified information systems
- Demonstrated experience with NIST and related frameworks and standards including: NIST SP 800-37 Rev. 2, NIST SP 800-53 Rev. 5, NIST SP 800-53A Rev. 5, NIST SP 800-137, NIST SP 800-30, FIPS 199 and 200, DoD RMF, CNSSI, ICD 50, and OSCAL implementation and machine-readable RMF artifacts
- Experience with Zero Trust Architecture, Continuous Authorization (cATO), security engineering principles, DevSecOps, and security automation
- Programming experience: Python, PowerShell, REST APIs, JSON/XML, GIT, CI/CD platforms, and integrating with enterprise APIs and cybersecurity platforms
- AI-assisted cybersecurity experience: Large Language Models (LLMs), RAG, Natural Language Processing, prompt engineering, vector databases, document intelligence, AI governance, and human-in-the-loop validation
Technologies
- CISSP, ISSEP, ISSAP, CGRC
- NIST SP 800-37 Rev. 2, NIST SP 800-53 Rev. 5, NIST SP 800-53A Rev. 5, NIST SP 800-137, NIST SP 800-30
- FIPS 199, FIPS 200
- DoD RMF, CNSSI, ICD 50, OSCAL
- Zero Trust Architecture, Continuous Authorization (cATO), DevSecOps, Continuous Monitoring (ConMon), SDLC
- eMASS, Xacta, ServiceNow, Vuln Management, Enterprise asset inventories
- Python, PowerShell, REST APIs, JSON/XML, GIT, CI/CD Platforms
- Large Language Models (LLMs), Retrieval-Augmented Generation (RAG), Natural Language Processing, prompt engineering, vector databases, document intelligence
- Human-in-the-loop validation, machine learning, rule-based models, AI governance
- Security-as-Code, Policy-as-Code
Preferred Skills and Experience
- Experience with the Space Force’s network environment
Role Details
- Location: Lackland AFB, TX (onsite)
- Salary: USD 160,000 - 200,000 per year
- Minimum experience: 5 years
- Education: High School
- Clearance: Top Secret/SCI