EngineerJobs.io
← Back to all jobs

Job Description

Govcio LLC is seeking a Sr IT Security Engineer to support the 16AF/AF IC Zero Trust initiative at Joint Base San Antonio, Lackland. This onsite role focuses on strengthening security controls, leading RMF activities, and advancing Zero Trust across both classified and unclassified environments.

Location and Work Setting

  • Location: San Antonio, TX
  • Work model: Onsite

Compensation

  • Estimated salary range: USD 140,000 - 160,000 per year

Key Responsibilities

  • Lead and support RMF activities, including system categorization, control selection, implementation, assessment, authorization, and continuous monitoring.
  • Develop, tailor, document, and validate security controls and implementation statements aligned to NIST, DoD, Air Force, and Intelligence Community requirements.
  • Prepare and maintain System Security Plans, Security Assessment Reports, Plans of Action and Milestones, risk assessments, and authorization packages.
  • Advise program managers, system owners, ISSOs, ISSMs, engineers, and Authorizing Officials on cybersecurity risks and remediation strategies.
  • Assess cloud architectures and services for compliance across security, privacy, identity, logging, encryption, data protection, and boundary requirements.
  • Support Zero Trust implementation, including identity-centric access control, least privilege, device trust, segmentation, continuous verification, and data-centric security.
  • Conduct security control assessments, vulnerability reviews, configuration assessments, and continuous monitoring activities.
  • Coordinate remediation of findings and track risks through closure or formal risk acceptance.
  • Support security architecture reviews, system design assessments, and mission-impact analyses.
  • Create cybersecurity documentation, briefings, risk reports, and executive-level recommendations.

Required Qualifications

  • Clearance: TS/SCI
  • Education: High school diploma
  • Experience: 9+ years in cybersecurity, computer science, information systems, engineering, or a related discipline; and 8+ years in information security or cybersecurity engineering with significant federal, DoD, Air Force, or Intelligence Community work.
  • Maintain an active certification that meets DoD 8570 IAT III in lieu of DoD 8140 job code 633 System Security Engineer.
  • Understanding of systems security design and engineering principles.
  • Knowledge of cybersecurity and Zero Trust reference architectures.
  • Strong understanding of SIEM systems.
  • Strong understanding of security for cloud-based platforms and applications.
  • Excellent spoken and written communication skills.
  • Experience creating security workflows and diagrams based on system architecture.
  • Understanding of Model Based Systems Engineering and its correlation to cybersecurity.
  • Demonstrated experience executing RMF activities for moderate- or high-impact systems.
  • Strong working knowledge of NIST SP 800-37, NIST SP 800-53, NIST SP 800-53A, and applicable DoD or Intelligence Community cybersecurity guidance.
  • Experience developing, tailoring, implementing, and assessing security controls.
  • Experience preparing authorization packages and working with system owners, ISSOs, ISSMs, security assessors, and Authorizing Officials.
  • Practical knowledge of cloud security architectures, including identity and access management, encryption, logging, network security, configuration management, and secure service deployment.
  • Knowledge of Zero Trust principles and architectures, including identity, device, application, network, and data protection.
  • Ability to analyze technical and operational risks and communicate findings to both technical and executive audiences.

Technologies and Standards

  • NIST SP 800-37
  • NIST SP 800-53
  • NIST SP 800-53A
  • DoD 8570 IAT III
  • DoD 8140 job code 633 System Security Engineer
  • SIEM systems

Preferred Skills and Experience

  • Experience supporting Air Force, Space Force, DoD, and/or Intelligence Community systems and mission applications.
  • Experience with classified environments, cross-domain solutions, high-side/low-side architectures, and compartmented or mission-partitioned systems.
  • Experience with FedRAMP, DoD Cloud Computing Security Requirements Guide, IL4/IL5/IL6 environments, or comparable cloud authorization processes.
  • Experience implementing Zero Trust using identity governance, privileged access management, micro segmentation, endpoint detection and response, security analytics, and continuous diagnostics.
  • Familiarity with CNSSI 1253, ICD 503, DoD RMF guidance, Air Force cybersecurity policy, and applicable Intelligence Community directives.
  • Experience with cloud platforms such as AWS, Microsoft Azure, or Google Cloud.
  • Experience with GRC and security tools such as eMASS, ServiceNow GRC, Archer, Tenable, ACAS, SCAP, Splunk, Microsoft Sentinel, or comparable platforms.
  • Experience performing security architecture reviews, threat modeling, attack-surface analysis, and control inheritance analysis.
  • Experience leading technical teams, mentoring junior security personnel, or briefing senior government stakeholders.

Similar Jobs