> Markdown version of [/jobs/ext/613875-senior-security-engineer-risk-remote](https://www.wearedevelopers.com/jobs/ext/613875-senior-security-engineer-risk-remote). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer (Risk) (Remote... - **Company:** The State Of Colorado - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $109,000.0 - $124,000.0 - **Contract:** Permanent contract - **Skills:** Security Information and Event Management, Data Analytics, Hardware Infrastructure - **Published:** June 19, 2026 - **Apply:** https://www.juju.com/job/00000000g9cab8 ## About the Role A wide salary range is posted for this position and any job offer is based upon a salary analysis to comply with the Colorado Equal Pay for Equal Work Act. The salary analysis considers relevant experience, education, certifications, and state seniority as compared to others doing substantially similar work. While all offers are compliant with the Colorado Equal Pay for Equal Work Act, there is no guarantee an offer will be at the top of the posted range based on the salary analysis. This is a skills-based job announcement. The required minimum qualifications and/or education (if substituting for the proven experience, knowledge, and skills), are as follows, + At least five (5) years of professional experience in security engineering, technical risk management, or high-level systems administration with a focus on security. + Demonstrated experience in technical and people leadership capacity, such as serving as a team lead, managing project workstreams, or providing high-level technical guidance to other technical staff, with the skillset to build relationships across service delivery organizations. + Proven experience in the full risk lifecycle, including performing risk assessments, identifying threats, and developing successful remediation strategies. Substitutions: + Additional appropriate education will substitute for the required experience on a year-for-year basis, but cannot completely substitute for these qualifications. + Training or Certification (CRISC, CISSP, CISA) related to the work assigned to the position will be assigned credit towards substitution for experience and/or education, but cannot completely substitute for these qualifications. Preferred Qualifications: + Proven expertise applying security and compliance frameworks (NIST 800-53, NIST RMF 800-37/39/30, NIST CSF, CJIS, IRS Pub 1075) to conduct risk assessments, evaluate control effectiveness, and deliver engineering-level guidance for enterprise risk mitigation. + Experience validating security controls in a variety of environments, including on-premise infrastructure and modern cloud architectures. + Hands-on experience implementing or operationalizing a GRC/IRM platform to automate risk workflows, track control status, and support audit readiness. + Previous experience working within or building a high-volume Third-Party Risk Management program. + Ability to translate risk metrics into clear visualizations and executive-level reporting using SIEM or data analytics platforms. + Ability to "hit the ground running" to meet aggressive roadmap goals while maintaining a focus on team-wide technical excellence. ## Description As the Senior Security Engineer (Risk) , you will serve as a technical leader and subject matter expert dedicated to the identification, quantification, and mitigation of technical risk across the organization. This role requires a seasoned professional with demonstrated leadership experience who can provide technical guidance to diverse stakeholders and offer strategic direction during complex security evaluations. A primary function of this role is performing comprehensive technical risk assessments on diverse systems and services to ensure they align with the state's security posture. You will be a key contributor in driving the maturity of a Third-Party Risk Management (TPRM) program designed to scale significantly, performing assessments for a high volume of vendors with efficiency and precision. You will act as a senior technical liaison between engineers, business users, and executive leadership, translating complex technical vulnerabilities into actionable risk narratives. Your work will directly support the risk management strategic roadmap, ensuring state technology remains resilient through consistent, expert-level evaluation. While this role does not involve hands-on infrastructure or engineering deployment, it requires deep technical literacy to evaluate security documentation and direct experience configuring and operationalizing risk management tooling. Key Job Responsibilities: + Act as a key security advisor and collaborator for teams across the organization. You will partner with Service Delivery teams to provide technical guidance on risk mitigation. You will serve as an escalation point for cross-team alignment on enterprise remediation strategies. + Execute deep-dive technical risk assessments for high-profile state systems. You will evaluate control implementations across a variety of environments, including on-premise, cloud, and hybrid, identifying critical gaps and developing technical remediation plans. + Serve as a key member in designing and maturing a TPRM program capable of handling an enterprise volume of vendors. You will establish and support a scalable solution with automated workflows and collaborate cross-functionally to scale the program's reach . + Support the execution and refinement of the risk management strategic roadmap. You will be responsible for driving milestones related to risk assessments, vendor risk management, continuous monitoring, TPRM program governance, and expanding risk services to state agencies and local government partners. + Support the transition from manual workflows to automated processes and platforms. You will provide the technical expertise needed to ensure the platform delivers real-time, asset-level risk visibility for leadership. + Partner with internal OIT teams to build TPRM dashboards that improve visibility for program governance and enterprise risk. You will contribute actionable insights that help leadership prioritize resources based on data-driven risk findings. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Generative UIs and AI Assistants for Your Angular Applications](https://www.wearedevelopers.com/videos/100074-generative-uis-and-ai-assistants-for-your-angular-applications) - [WeAreDevelopers LIVE - "Fun and games - and all that comes with it", Back to BASIC & more](https://www.wearedevelopers.com/videos/1719-wearedevelopers-live-fun-and-games-and-all-that-comes-with-it-back-to-basic-more) - [PySpark - Combining Machine Learning & Big Data](https://www.wearedevelopers.com/videos/44-pyspark-combining-machine-learning-big-data) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Remote Jobs](https://www.wearedevelopers.com/magazine/255-best-paying-remote-jobs) - [How Much Does a Software Engineer Make? Realistic Software Engineering Salaries](https://www.wearedevelopers.com/magazine/425-how-much-does-a-software-engineer-make-realistic-software-engineering-salaries) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)