> Markdown version of [/jobs/ext/2155420-cyber-security-engineer-sme](https://www.wearedevelopers.com/jobs/ext/2155420-cyber-security-engineer-sme). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Engineer SME - **Company:** GovCIO - **Location:** Colorado Springs, CO, United States - **Experience:** Expert - **Salary:** $200,000.0 - **Contract:** Permanent contract - **Skills:** Xacta, Application Programming Interfaces (APIs), Artificial Intelligence, Cyber Security, Information Systems, Computer Programming, Computer Networks, Computer Forensics, Data Recovery, Federal Information Processing Standards (FIPS), Intelligence Analysis, Information Systems Security Architecture Professional, Information Systems Security Engineering Professional, JSON, Python (Programming Language), Network Security, Machine Learning, Natural Language Processing, Windows PowerShell, Systems Development Life Cycle, Zero Trust Network Access, Systems Integration, Extensible Markup Language (XML), Policy as Code, Large Language Models, Prompt Engineering, Generative AI, Cyber Threat Analysis, Git, Cybercrime, Restful APIs, Devsecops, Security Orchestration, Automation & Response, Servicenow - **Published:** August 20, 2026 - **Apply:** https://www.juju.com/job/00000000gnxinr ## About the Role High School with 10+ years (or commensurate experience), + Clearance Required: Top Secret/SCI + DOD 8140 IAT III certification required: CISSP, ISSEP, ISSAP, CGRC. + 10 years of experience in one or more of the following: Cybersecurity Engineering, Risk Management Framework implementation, Security Architecture, DevSecOps, Continuous Monitoring, Security Automation. + Minimum five years supporting DoD or Intelligence Community cybersecurity programs. + Experience with eMASS, Xacta, NIST RMF, DoD RMF, AF IC cybersecurity processes, Classified information systems. + Demonstrated experience with NIST SP 800-37 Rev. 2, NIST SP 800-53 Rev. 5. NIST SP 800-53A Rev. 5, NIST SP 800-137, NIST SP 800-30, FIPS 199 and 200, DoD RMF, CNSSI, ICD 50, OSCAL implementation and machine-readable RMF artifacts, Zero Trust Architecture, Continuous Authorization (cATO), Security engineering principles, DevSecOps, Security automation. + Programming Experience developing automation using: Python, PowerShell, REST APIs, JSON/XML, GIT, CI/CD Platforms, integrating with enterprise APIs and cybersecurity platforms + Experience implementing AI-assisted cybersecurity capabilities using Large Language Models (LLMs), Retrieval-Augmented Generation (RAG), Natural Language Processing, Prompt engineering, Vector databases, Document intelligence, AI governance, Human-in-the-loop validation. Preferred Skills and Experience + Experience with the Space Force's network environment. ## Description GovCIO is currently hiring for Cybersecurity Engineer SME to support advanced Air Force Intelligence Community (AF IC) Risk Management Framework (RMF) modernization initiatives. The successful candidate will serve as a technical lead for cybersecurity engineering, RMF automation, and AI-enabled compliance capabilities supporting classified information systems. This position will be located at Peterson AFB, CO and will be an onsite position. Responsibilities Correlates threat data from various sources to establish the identity and modus operandi of hackers active in client's networks and posing a potential threat. Provides the customer with assessments and reports facilitating situational awareness and understanding of current cyber threats and adversaries. Develops cyber threat profiles based on geographic region, country, group, or individual actors. Produces cyber threat assessments based on entity threat analysis. May provide computer forensic and intrusion support to high technology investigations in the form of computer evidence seizure, computer forensic analysis, data recovery, and network assessments. Researches and maintains proficiency in tools, techniques, countermeasures, and trends in computer network vulnerabilities, data hiding and network security and encryption. + Collaborates with intrusion analysts to identify, report on, and coordinate remediation of cyberthreats to the client. + Provides timely and actionable sanitized intelligence to cyber incident response professionals. + Leverages technical knowledge of computer systems and networks with cyber threat information to assess the client's security posture. + Conducts intelligence analysis to assess intrusion signatures, tactics, techniques and procedures associated with preparation for and execution of cyber attacks. + Researches hackers, hacker techniques, vulnerabilities, exploits, and provides detailed briefings and intelligence reports to leadership. This position focuses on engineering and automating RMF processes, improving authorization efficiency, enhancing continuous monitoring, and integrating AI-assisted analysis into cybersecurity governance workflows. The position supports system owners, ISSMs, ISSOs, Authorizing Officials (AOs), and Security Control Assessors (SCAs) by developing automation capabilities and engineering solutions. The position does not perform independent security control assessments to preserve RMF assessment independence. Primary Responsibilities + Engineer cybersecurity solutions supporting DoD and Intelligence Community information systems. + Design, implement, and document security controls consistent with NIST SP 800-53 Rev. 5 and CNSSI 1253 overlays, as applicable. + Develop security architectures supporting Zero Trust, cloud, hybrid, and on-premises environments. + Integrate cybersecurity requirements throughout the System Development Life Cycle (SDLC). + Support Authority to Operate (ATO), Continuous Authorization (cATO), and Continuous Monitoring (ConMon) initiatives. + Develop and maintain RMF authorization artifacts\ + Engineer automated evidence collection and validation processes. + Develop reusable security control implementations and standardized control inheritance strategies. + Support implementation of OSCAL-based RMF automation. + Design and implement AI-assisted capabilities supporting RMF documentation, evidence management, and compliance analysis. + Develop Retrieval-Augmented Generation (RAG) workflows for cybersecurity documentation. + Implement Natural Language Processing (NLP) techniques to analyze RMF artifacts and identify documentation inconsistencies. + Develop machine learning and rule-based models. + Implement human-in-the-loop validation for all AI-generated outputs. + Apply Responsible AI principles and AI governance throughout solution development. + Develop automated RMF workflows. + Integrate cybersecurity controls into CI/CD pipelines. + Implement Security-as-Code and Policy-as-Code capabilities. + Develop dashboards supporting cybersecurity metrics, authorization status, and continuous monitoring. + Integrate automation with eMASS, Xacta, ServiceNow, Vuln Management platforms, and Enterprise asset inventories + Engineer automated collection of cybersecurity evidence supporting continuous monitoring. + Integrate security tooling. + Develop automated compliance scoring and risk dashboards. + Provide technical recommendations supporting authorization decisions. + Support modernization of enterprise RMF processes across AF IC environments. ## Related Videos - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Introducing JSON Structure](https://www.wearedevelopers.com/videos/100219-introducing-json-structure) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)