Cyber Security Engineer SME
Job Description
Onsite at Peterson AFB, CO, this SME role supports AF IC Risk Management Framework (RMF) modernization for classified information systems.
Responsibilities
- Correlate threat data from multiple sources to identify hackers’ identity and modus operandi within client networks.
- Produce assessments and reporting that improve situational awareness and understanding of current cyber threats and adversaries.
- Develop cyber threat profiles by geographic region, country, group, or individual actor.
- Create cyber threat assessments using entity threat analysis.
- Provide computer forensic and intrusion support for high-technology investigations, including evidence seizure, forensic analysis, data recovery, and network assessments.
- Maintain proficiency in tools, techniques, countermeasures, and trends for computer network vulnerabilities, data hiding, and network security and encryption.
- Collaborate with intrusion analysts to identify, report on, and coordinate remediation of cyber threats.
- Deliver timely, actionable sanitized intelligence to cyber incident response professionals.
- Use knowledge of computer systems and networks plus threat information to assess the client’s security posture.
- Conduct intelligence analysis to evaluate intrusion signatures and tactics, techniques, and procedures for cyber attack preparation and execution.
- Research threat actors, techniques, vulnerabilities, and exploits; brief leadership and provide detailed intelligence reports.
- Engineer cybersecurity solutions for DoD and Intelligence Community information systems.
- Design, implement, and document security controls aligned with NIST SP 800-53 Rev. 5 and CNSSI 1253 overlays, as applicable.
- Design security architectures for Zero Trust, cloud, hybrid, and on-premises environments.
- Integrate cybersecurity requirements throughout the SDLC.
- Support Authority to Operate (ATO), Continuous Authorization (cATO), and Continuous Monitoring (ConMon).
- Develop and maintain RMF authorization artifacts.
- Engineer automated evidence collection and validation processes.
- Develop reusable security control implementations and standardized control inheritance strategies.
- Support OSCAL-based RMF automation.
- Design and implement AI-assisted capabilities for RMF documentation, evidence management, and compliance analysis.
- Develop Retrieval-Augmented Generation (RAG) workflows for cybersecurity documentation.
- Apply NLP techniques to analyze RMF artifacts and identify documentation inconsistencies.
- Develop machine learning and rule-based models.
- Implement human-in-the-loop validation for all AI-generated outputs.
- Apply Responsible AI principles and AI governance during solution development.
- Develop automated RMF workflows and integrate cybersecurity controls into CI/CD pipelines.
- Implement Security-as-Code and Policy-as-Code capabilities.
- Create dashboards for cybersecurity metrics, authorization status, and continuous monitoring.
- Integrate automation with eMASS, Xacta, ServiceNow, vulnerability management platforms, and enterprise asset inventories.
- Engineer automated cybersecurity evidence collection supporting continuous monitoring and integrate security tooling.
- Develop automated compliance scoring and risk dashboards.
- Provide technical recommendations supporting authorization decisions.
- Support modernization of enterprise RMF processes across AF IC environments.
- Support system owners, ISSMs, ISSOs, Authorizing Officials (AOs), and Security Control Assessors (SCAs) by developing automation capabilities and engineering solutions.
- Note: This position does not perform independent security control assessments to preserve RMF assessment independence.
Requirements
- Clearance: Top Secret/SCI
- DoD 8140 IAT III certification required: CISSP, ISSEP, ISSAP, or CGRC
- Experience: 10 years in one or more of: Cybersecurity Engineering, RMF implementation, Security Architecture, DevSecOps, Continuous Monitoring, Security Automation
- Minimum DoD/IC experience: 5 years supporting DoD or Intelligence Community cybersecurity programs
- RMF and environment experience: eMASS, Xacta, NIST RMF, DoD RMF, AF IC cybersecurity processes, and classified information systems
- Frameworks and standards experience: NIST SP 800-37 Rev. 2, NIST SP 800-53 Rev. 5, NIST SP 800-53A Rev. 5, NIST SP 800-137, NIST SP 800-30, FIPS 199 and 200, DoD RMF, CNSSI, ICD 50, OSCAL implementation and machine-readable RMF artifacts, Zero Trust Architecture, cATO, security engineering principles, DevSecOps, and security automation
- Programming for automation: Python, PowerShell, REST APIs, JSON/XML, GIT, CI/CD Platforms, plus integration with enterprise APIs and cybersecurity platforms
- AI-assisted cybersecurity experience: Large Language Models (LLMs), RAG, NLP, prompt engineering, vector databases, document intelligence, AI governance, and human-in-the-loop validation
- Education/qualification: High School with 10+ years (or commensurate experience)
Preferred Skills
- Experience with the Space Force’s network environment
Technologies
- CISSP, ISSEP, ISSAP, CGRC
- NIST SP 800-53 Rev. 5, CNSSI 1253
- Zero Trust Architecture, SDLC, OSCAL
- eMASS, Xacta, ServiceNow, vulnerability management platforms, enterprise asset inventories
- NIST SP 800-37 Rev. 2, NIST SP 800-53A Rev. 5, NIST SP 800-137, NIST SP 800-30
- FIPS 199, FIPS 200
- DoD RMF, ICD 50
- Python, PowerShell, REST APIs, JSON/XML, GIT, CI/CD Platforms
- Large Language Models (LLMs), RAG, NLP, prompt engineering, vector databases, document intelligence
Position Details
- Location: Peterson AFB, CO (onsite)
- Salary range: USD 160,000 - 200,000 per year