Cyber Security Engineer

  • GovCIO LLC
  • Colorado Springs, Colorado
  • 08/25/2026
Full time Information Technology Telecommunications Testing Cyber Security

Job Description

GovCIO LLC seeks a Cyber Security Engineer SME to secure mission-critical federal IT systems. You'll design and harden secure network, cloud, and application architectures; lead vulnerability management, penetration testing, and incident response; and implement tools such as SIEM, IDS/IPS, and endpoint protection. Partnering with cross-functional teams, you'll embed security into agile delivery, support ATO and federal compliance (NIST/FISMA), and mentor engineers. Join a mission-driven, collaborative, and fast-paced culture modernizing government technology and protecting high-impact national programs.

Responsibilities

  • Design, implement, and maintain secure network, cloud, and application architectures for federal clients
  • Conduct security assessments, penetration testing, and vulnerability management across complex environments
  • Develop and enforce security policies, standards, and best practices aligned to federal frameworks (e.g., NIST, FISMA)
  • Configure and manage security tools such as SIEM, IDS/IPS, endpoint protection, and identity/access management
  • Lead incident response, forensic analysis, and root-cause investigations for security events
  • Collaborate with engineers, developers, and government stakeholders to embed security into solutions and SDLCPrepare security documentation, ATO support materials, and technical reports for audits and compliance
  • Provide SME guidance, mentoring, and training to project teams and junior security engineers
  • Continuously monitor emerging threats and recommend improvements to security posture
  • Support architecture reviews, change control, and risk assessments for high-impact government systems

Required Skills

  • Cybersecurity architecture
  • Network security
  • Cloud security (AWS/Azure/GCP)
  • SIEM configuration and management
  • IDS/IPS and endpoint protection
  • Penetration testing and ethical hacking
  • Vulnerability assessment and remediation
  • Incident response and digital forensics
  • NIST/FISMA/RMF compliance
  • Identity and access management (IAM)