Cybersecurity Engineer

San Francisco Municipal Transportation Agency
San Francisco, United States of America
2 days ago

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Working hours
Shift work
Languages
English
Experience level
Junior
Compensation
$ 244K

Job location

San Francisco, United States of America

Tech stack

LTE (Telecommunication)
Border Gateway Protocol
Computer Security
Information Systems
Computer Networks
Databases
System Configuration
Data Architecture
Data Integration
Cryptographic Protocols
Network Topologies
Identity and Access Management
Networking Hardware
Internet Protocol Security (IP SEC)
Intrusion Detection and Prevention
Intrusion Detection Systems
Multi-protocol Systems
Multicasting
Network Architecture
Zero Trust Network Access
Security Information and Event Management
Software Requirements Analysis
Systems Architecture
Wireshark
Virtual Local Area Networks
Wireless Access Point
Wireless Networks
Safety Critical Systems
Firewalls (Computer Science)
Juniper
NetScout
Information Technology
SolarWinds (Software)
Palo Alto Networks
Performance Monitor
Fortinet
Network Server
Cisco networks
Vulnerability Analysis

Job description

The San Francisco Municipal Transportation Agency (SFMTA) is a department of the City and County of San Francisco responsible for the management of all ground transportation in the City. The SFMTA has oversight over the Municipal Railway public transit (Transit Division or "Muni"), as well as bicycling, paratransit, parking, traffic, walking, and taxis. SFMTA is currently in the process of implementing an upgrade of the technology used to manage light rail operations on the surface and in the subway.

The Train Control Upgrade Project (TCUP) is a multi-year, multimillion dollar project with the goal of replacing the existing train control system onboard vehicles and in the Muni Metro subway with a state-of-the-art radio-based technology. TCUP will expand supervision of trains by the train control system from the subway to the entire surface Muni light rail system. The TCUP vendor contract and installation work will be managed by a project management team within the Transit Division ("Muni").

Information Technology is at the core of TCUP. SFMTA's Technology Solutions and Integration (TSI) team will be delivering the technology scope for TCUP. The role will be supporting delivery of the information technology components.

Success requires significant investments in expanded network infrastructure, data architecture, wireless communication systems, servers, databases, and cybersecurity. Project systems will need data integration with existing enterprise and intelligent transportation systems. Changes need to be baselined, documented, designed, implemented, and tested.

This is an opportunity to work with stakeholders and business units across the SFMTA and take a pivotal step in your career. Your work will impact the lives of all users of our transportation services and infrastructure., Under the direction of the TCUP Technology Project Manager, the Cybersecurity Engineer works with the team responsible for delivering the network topology, policies, wireless infrastructure, fiber infrastructure, network equipment, security, installation, and testing for the new CBTC system. The Cybersecurity Engineer ensures that communication systems supporting CBTC operations are designed, implemented, and maintained to meet security, resiliency, and regulatory requirements., * Serve as the lead cybersecurity architect for TCUP, defining the security posture for all networked, wireless, and backhaul train control systems.

  • Develop and contribute to redundancy and failover strategies, ensuring network resiliency and availability while aligning with cybersecurity requirements.
  • Define and document network policies, including access control, segmentation, QoS, and routing practices, ensuring alignment with cybersecurity principles.
  • Assess wireless spectrum usage for security risks, interference vulnerabilities, and resiliency.
  • Review and provide security oversight of network architecture, including routing, segmentation (VLANs), and multicast configurations.
  • Support the design and configuration of network architecture to ensure support for secure routing, segmentation (VLANs), and multicast communications.
  • Define security standards for hardware lifecycle management and support lifecycle planning decisions.
  • Implement cybersecurity measures, such as firewalls, intrusion detection/prevention systems (IDS/IPS), and endpoint protection.
  • Conduct periodic vulnerability assessments and ensure compliance with industry standards (e.g., NIST, CISA, ISO/IEC 27001).
  • Validate cybersecurity controls in end-to-end communication systems supporting train control operations.
  • Troubleshoot and resolve issues identified during testing phases.
  • Develop and maintain technical documentation for network and cybersecurity architectures, configurations, and operational procedures.
  • Ensure cybersecurity controls align with applicable railway safety and security standards and regulatory requirements.
  • Define requirements for network and security monitoring and ensure integration with enterprise SOC/NOC tools.
  • Performs other related duties as assigned.

Requirements

Education: An associate degree in computer science, computer engineering, information systems, or a closely related field from an accredited college or university OR its equivalent in terms of total course credits/units [i.e., at least sixty (60) semester or ninety (90) quarter credits/units with a minimum of twenty (20) semester or thirty (30) quarter credits/units in one of the fields above or a closely-related field].

Experience: Five (5) years of experience analyzing, installing, configuring, enhancing, and/or maintaining the components of a system or platform.

Substitution: One year of additional experience as described above may be substituted for the required degree.

Completion of the 1010 Information Systems Trainee Program may be substituted for the required degree.

Notes:

  1. Applicants must meet the minimum qualifications by the final filing date unless otherwise noted.

  2. One (1) year full-time experience is equivalent to 2000 hours. (2000 hours of qualifying work experience is based on a 40-hour work week). Any overtime hours that you work above forty (40) hours per week are not included in the calculation to determine full-time experience., The stated desirable qualifications may be used to identify candidates advancing to the interview process and/or to identify job finalist(s) at the end of the selection process when referred for hiring.

  • 5+ years' experience leading cybersecurity architecture for large, mission-critical or safety-critical systems.
  • Knowledge of SIEM, SOAR, and/or SOC integrations for network and OT telemetry.
  • 5-years' experience securing LTE and 5G (3GPP) wireless communications for mission-critical or operational technology environments.
  • 5-years' experience applying security principles to networks (e.g., BGP security, MPLS segmentation, multicast control).
  • 5 years' experience implementing and managing network security protocols, including encryption (e.g., IPSec, TLS), firewalls, IDS/IPS, and endpoint security.
  • 5 years' experience of cybersecurity frameworks (e.g., NIST Cybersecurity Framework, EN 50159:2010, IEC 62443) and best practices.
  • 5 years' defining, reviewing, and validating network and security test plans.
  • Proficiency with tools for security validation, performance monitoring, and troubleshooting (e.g., SIEM platforms, EDR/XDR Wireshark, SolarWinds, NetScout).
  • Familiarity with network equipment from major vendors (e.g. Palo Alto, Fortinet, Cisco, Juniper, Nokia, Ericsson) and radio system hardware (e.g., base stations, access points).
  • 5-years' experience working with system engineers, project managers, operations teams, and regulatory bodies to ensure alignment of system requirements and performance goals.
  • 5-years' experience designing and implementing secure system architectures using Zero Trust principles, including Identity and Access management (IAM), least privilege access, and secure system design practices across system lifecycle.
  • 5-years' experience conducting threat modeling and cybersecurity risk assessments for complex systems, with demonstrated ability to coordinate incident response activities and integrate security monitoring with enterprise SOC processes.
  • 5-years' experience securing transportation, rail, utilities, or other critical infrastructure environments.
  • Ability to communicate progress and issues to stakeholders through regular status updates and technical reports.
  • Experience collaborating with diverse stakeholders and fostering an inclusive environment that values different perspectives, backgrounds, and expertise to drive effective decision-making.

Apply for this position