> Markdown version of [/jobs/ext/1758473-oit-s-senior-cyber-security-engineer](https://www.wearedevelopers.com/jobs/ext/1758473-oit-s-senior-cyber-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # OIT's Senior Cyber Security Engineer - **Company:** Governor's Office Of Information Technology - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $110,000.0 - $125,000.0 - **Contract:** Temporary contract - **Skills:** Cyber Security, Secure Coding, Systems Architecture, Information Technology, Servicenow - **Published:** July 31, 2026 - **Apply:** https://www.dice.com/job-detail/2f604efb-b4b4-4018-989b-0fa4506f4159 ## About the Role A wide salary range is posted for this position and any job offer is based upon a salary analysis to comply with the Colorado Equal Pay for Equal Work Act. The salary analysis considers relevant experience, education, certifications, and state seniority as compared to others doing substantially similar work. While most salary offers are made within the posted range, occasionally an offer is made below or above the posted range based upon this salary analysis. This is a skills-based job announcement. The required minimum qualifications and/or education (if substituting for the proven experience, knowledge, and skills), are as follows: Minimum Qualifications: * At Least five (5) years of experience in a security engineering, secure code reviews, systems administration, or compliance advisory role in a variety of technical environments, including on-premise, cloud, and hybrid. * Experience supporting audit or compliance programs (e.g., NIST 800-53 CJIS, IRS, HIPAA, SSA, SOC 2, or similar). Substitutions: * Additional appropriate education will substitute for the required experience on a year-for-year basis, but cannot completely substitute for these qualifications. * Training or Certification related to the work assigned to the position will be assigned credit towards substitution for experience and/or education, but cannot completely substitute for these qualifications. * If the minimum qualifications include a degree requirement, additional appropriate paid or unpaid experience will substitute for the required education on a year-for-year basis., * Professional security certification. * Exposure to Governance Risk and Compliance (GRC) tooling, such as ServiceNow GRC, Archer, or similar platforms. * Project management experience. ## Description Type of Announcement: This announcement is not governed by the selection processes of the classified personnel system. Applications will be considered from residents and non-residents of Colorado. How To Apply: Please submit an online application for this position at Reach out to the Department Contact to apply using a paper application, including any supplemental questions. Failure to submit a complete and timely application may result in the rejection of your application. Applicants are responsible for ensuring that application materials are received by the appropriate Human Resources office before the closing date and time listed. Department Information Together, we innovate for a stronger Colorado The work of employees at the Governor's Office of Information Technology (OIT) is challenging and diverse because the needs of agencies, customers and Coloradans constantly evolve. But our focus never changes: improve the lives of all Coloradans through innovation and collaboration. We're building one of the nation's leading government IT organizations by reimagining how we support agencies, building first-of-their-kind applications, and creating an inclusive, collaborative culture, together. Join us in the important work of providing equitable access to services., Do you have demonstrated expertise in core security principles, such as robust access controls, cryptographic methods, and secure system architecture, with the ability to interpret and implement these effectively? Are you able to translate complex security requirements into practical technical guidance to securely implement controls within diverse technical environments? As OIT's Senior Cyber Security Engineer, you will be a subject matter expert who develops and implements security strategies, ensuring alignment with project goals and operational continuity. In this role, you will collaborate with technical system administrators and engineers, business continuity specialists, compliance analysts, and others to identify improvements and integrate new technologies. One of your key functions will be as a technical liaison between diverse stakeholder groups in complex technical environments. In this role, you will validate security control implementations, provide technical advisory support, and suggest and evaluate security tooling. You will also play a critical part in strengthening the agency's compliance by translating security controls into practical technical guidance., * Collaborating with compliance analysts and technical SMEs to validate system-level control implementations to support audit remediation and planning * Developing processes and evaluating tooling to improve audit workflow automation and evidence management * Interpreting security policies, standards, and frameworks (e.g., NIST 800-53, CJIS, IRS Publication 1075), mapping requirements to technical implementations, and validating adherence. * Providing guidance on secure product implementation practices and helping define minimum security and compliance baselines for new systems and services. * Developing and collaborating on readiness assessments and audit simulations by evaluating technical control implementations. * Identifying opportunities for improvement by leveraging current systems' strengths and investigating new technologies and methodologies. * Draft policies and standard operating procedures pertaining to risk management and audits. * Manage projects and work with stakeholders to accomplish tasks on schedule., OIT employees must comply with any screening procedures in place at state agency locations where they might perform work. A pre-employment background check will be conducted as part of the selection process. Post-employment background checks will be required for specific agencies as business needs dictate, which may include a polygraph exam, fingerprint-based criminal history search, reference checks, and a drug test. This position may require travel within the specified geographic area, and to locations across the state as needed. This position may require on-call duties as needed by the position. Supplemental Information If this posting indicates "remote from anywhere in CO" in the title, periodic reporting to the primary state work location designated for the position is required. All remote work must be performed in Colorado. While candidates from out of state will be considered for this role, the candidate selected for the position must relocate and reside in Colorado on the first day of their new position. A reasonable timeframe for relocation will be established on an individual basis, while considering business needs, and determining a start date. We know it's important to support each other, and that means having a healthy balance of work and personal time. Visit our benefits to learn more about some of our great offerings that allow us all to have fulfilling lives. Visit our How to Apply webpage to learn more about our application process and what to expect after you apply. The State of Colorado strives to create a Colorado for All by building and maintaining workplaces that value and respect all Coloradans through a commitment to equal opportunity and hiring based on merit and fitness. The State is resolute in non-discriminatory practices in everything we do, including hiring, employment, and advancement opportunities. The Governor's Office of Information Technology is committed to the full inclusion of all qualified individuals. As part of this commitment, our agency will assist individuals who have a disability with any reasonable accommodation requests related to employment, including completing the application process, interviewing, completing any pre-employment testing, participating in the employee selection process, and/or to perform essential job functions where the requested accommodation does not impose an undue hardship. If you have a disability and require reasonable accommodation to ensure you have a positive experience applying or interviewing for this position, please direct your inquiries to our ADA Coordinator at or call ., The role requires acting as a technical liaison between compliance teams and technical stakeholders. Explain your approach to fostering collaboration and effectively communicating highly technical security concepts to non-technical audiences, particularly in the context of audit control implementation or new technology integrations. 04 Describe your experience translating complex security requirements (e.g., those from IRS Publication 1075, CMS MARS-E, or similar) into actionable technical controls and implementation guidance for technical teams. Provide a specific example of a challenge you faced and how you addressed it. 05 Describe your experience in designing, implementing, and operationalizing security tooling and controls across diverse technical environments (on-premise, cloud, and hybrid). Provide an example of how you've identified opportunities for improvement or integrated new technologies to strengthen an agency's security posture. 06 What experience do you have drafting policies and standard operating procedures about risk management and audits? 07 ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) - [How GitHub secures open source](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) ## Related Articles - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [IT Salaries in Germany](https://www.wearedevelopers.com/magazine/287-it-salaries-in-germany) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [IT Salaries in Austria](https://www.wearedevelopers.com/magazine/286-it-salaries-in-austria) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)