Sr IT Security Engineer

GovCIO

San Antonio (TX)

On-site

USD 140,000 - 160,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

GovCIO is seeking an IT Security Engineer Senior to support the 16AF/AF IC zero trust initiative at Joint Base San Antonio, Lackland. This onsite role requires leading RMF activities, developing and tailoring security controls, and advancing Zero Trust across classified and unclassified environments.

The candidate will work with Air Force and IC stakeholders, maintain SSCs and ISA packages, and communicate risk to technical and senior audiences. TS/SCI clearance is required.

Qualifications

  • Active TS/SCI clearance required.
  • Minimum high school diploma with 9+ years in cybersecurity or related field.
  • 8+ years information security or cybersecurity engineering experience, preferably in federal/DoD/IC.
  • Must have a DoD 8570 IAT III certification.
  • Strong knowledge of RMF, NIST SPs, and IC cybersecurity guidance.
  • Experience with cloud security, zero trust, and infiltration risk assessments.
  • Proficiency with RMF artifacts: SSPs, POA&Ms, security assessments, authorization packages.
  • Ability to communicate risks to technical and senior leadership.

Responsibilities

  • Lead RMF activities across system categorization, control selection, implementation, assessment, authorization, and continuous monitoring.
  • Develop, tailor, document, and validate security controls using NIST/DoD/IC requirements.
  • Prepare and maintain System Security Plans, Security Assessment Reports, POA&Ms, risk assessments, and authorization packages.
  • Advise program managers, system owners, ISSOs/ISSMs, engineers, and Authorizing Officials on cybersecurity risks and remediation.
  • Assess cloud architectures for security/compliance with data protection and boundary requirements.
  • Support Zero Trust implementation including identity-centric access control and least privilege.
  • Conduct security control assessments, vulnerability reviews, and monitoring activities; coordinate remediation and risk closure.
  • Support security architecture reviews, system design assessments, and mission-impact analyses.
  • Develop cybersecurity documentation, briefings, risk reports, and executive recommendations.

Skills

RMF activities
NIST standards
Zero Trust
Cloud security
Communication skills
Security assessment
Authorization packages

Education

Active DoD 8570 IAT III certification
High school diploma with 9+ years of cybersecurity experience

Tools

SIEM
eMASS
ServiceNow GRC
Archer
Tenable
ACAS
Splunk
Microsoft Sentinel

Job description

GovCIO is currently hiring for an IT Security Engineer Senior to support the 16AF/AF IC zero trust initiative. This position will be located at Joint Base San Antonio, Lackland and will be an onsite position.

Responsibilities

This position will support Air Force Intelligence Community mission systems in the implementation, assessment, and continuous monitoring of cybersecurity requirements. The engineer will lead Risk Management Framework activities, develop and tailor security controls, strengthen cloud security architectures, and advance Zero Trust capabilities across classified and unclassified environments. The role requires strong knowledge of federal, DoD, Air Force, and Intelligence Community cybersecurity policies and the ability to translate them into practical engineering and compliance outcomes.

  • Lead and support RMF activities, including system categorization, control selection, implementation, assessment, authorization, and continuous monitoring.
  • Develop, tailor, document, and validate security controls and implementation statements using NIST, DoD, Air Force, and Intelligence Community requirements.
  • Prepare and maintain System Security Plans, Security Assessment Reports, Plans of Action and Milestones, risk assessments, and authorization packages.
  • Advise program managers, system owners, ISSOs, ISSMs, engineers, and Authorizing Officials on cybersecurity risks and remediation strategies.
  • Assess cloud architectures and services for compliance with security, privacy, identity, logging, encryption, data protection, and boundary requirements.
  • Support Zero Trust implementation, including identity-centric access control, least privilege, device trust, segmentation, continuous verification, and data-centric security.
  • Conduct security control assessments, vulnerability reviews, configuration assessments, and continuous monitoring activities.
  • Coordinate remediation of findings and track risks through closure or formal risk acceptance.
  • Support security architecture reviews, system design assessments, and mission-impact analyses.
  • Develop cybersecurity documentation, briefings, risk reports, and executive-level recommendations.
Qualifications

Required Skills and Experience

Clearance: TS/SCI

High school diploma with 9+ years’ experience in cybersecurity, computer science, information systems, engineering, or a related discipline.

  • Eight or more years of information security or cybersecurity engineering experience, including significant federal, DoD, Air Force, or Intelligence Community work.
  • Must possess and maintain active certification that meets DOD 8570 IAT III in lieu of DoD 8140 job code 633 System Security Engineer.
  • Understanding of systems security design and engineering principles.
  • Knowledge of cybersecurity and zero trust reference architectures.
  • Strong understanding of SIEM systems.
  • Strong understanding of security for cloud-based platforms and applications.
  • Excellent communication skills (spoken and written).
  • Experience creating security workflows and diagrams based on system architecture.
  • Understanding of Model Based Systems Engineering and the correlation to cybersecurity.
  • Demonstrated experience executing RMF activities for moderate- or high-impact systems.
  • Strong working knowledge of NIST SP 800-37, NIST SP 800-53, NIST SP 800-53A, and applicable DoD or Intelligence Community cybersecurity guidance.
  • Experience developing, tailoring, implementing, and assessing security controls.
  • Experience preparing authorization packages and working with system owners, ISSOs, ISSMs, security assessors, and Authorizing Officials.
  • Practical knowledge of cloud security architectures, including identity and access management, encryption, logging, network security, configuration management, and secure service deployment.
  • Knowledge of Zero Trust principles and architectures, including identity, device, application, network, and data protection.
  • Ability to analyze technical and operational risks and communicate findings clearly to technical and executive audiences.

Preferred Skills and Experience

  • Experience supporting Air Force, Space Force, DoD, and/or Intelligence Community systems and mission applications.
  • Experience with classified environments, cross-domain solutions, high-side/low-side architectures, and compartmented or mission-partitioned systems.
  • Experience with FedRAMP, DoD Cloud Computing Security Requirements Guide, IL4/IL5/IL6 environments, or comparable cloud authorization processes.
  • Experience implementing Zero Trust using identity governance, privileged access management, micro segmentation, endpoint detection and response, security analytics, and continuous diagnostics.
  • Familiarity with CNSSI 1253, ICD 503, DoD RMF guidance, Air Force cybersecurity policy, and applicable Intelligence Community directives.
  • Experience with cloud platforms such as AWS, Microsoft Azure, or Google Cloud.
  • Experience with GRC and security tools such as eMASS, ServiceNow GRC, Archer, Tenable, ACAS, SCAP, Splunk, Microsoft Sentinel, or comparable platforms.
  • Experience performing security architecture reviews, threat modeling, attack-surface analysis, and control inheritance analysis.
  • Experience leading technical teams, mentoring junior security personnel, or briefing senior government stakeholders.
Posted Salary Range

USD $140,000.00 - USD $160,000.00 /Yr.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Security Engineer
Cyber Security Engineer

GovCIO • San Antonio (TX)

Hybrid
USD 180,000 - 200,000
Senior Zero-Trust Security Engineer - Onsite
Senior Zero-Trust Security Engineer - Onsite

GovCIO • San Antonio (TX)

On-site
USD 140,000 - 160,000
Systems Engineer
Systems Engineer

GovCIO • Hampton (VA)

On-site
USD 130,000 - 140,000
Zero Trust Cybersecurity Engineer (Onsite, TS/SCI)
Zero Trust Cybersecurity Engineer (Onsite, TS/SCI)

GovCIO • Hampton (VA)

On-site
USD 180,000 - 200,000
Employee Assistance Program (EAP)
Corporate Discounts
Learning & Development platform
+5
Cybersecurity Engineer SME
Cybersecurity Engineer SME

GovCIO • San Antonio (TX)

On-site
USD 160,000 - 200,000
Cybersecurity Engineer SME
Cybersecurity Engineer SME

GovCIO • Town of Texas (WI)

On-site
USD 160,000 - 200,000
Zero Trust Cybersecurity Engineer – Onsite, TS/SCI
Zero Trust Cybersecurity Engineer – Onsite, TS/SCI

GovCIO • San Antonio (TX)

Hybrid
USD 180,000 - 200,000
Network Engineer
Network Engineer

GovCIO • Hampton (VA)

On-site
USD 130,000 - 140,000
Cybersecurity Engineer SME
Cybersecurity Engineer SME

GovCIO • Del Rio (TX)

On-site
USD 160,000 - 200,000
Cyber Security Engineer
Cyber Security Engineer

GovCIO • Hampton (VA)

On-site
USD 180,000 - 200,000
Employee Assistance Program (EAP)
Corporate Discounts
Learning & Development platform
+5