Senior Cyber Security Engineer (Remote From Anywhere In Colorado)

State of Colorado

$110K — $125K *
US-AnywhereRemote in Colorado, US
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in security engineering, secure code reviews, systems administration, or compliance advisory roles across diverse environments.
  • Experience with audit or compliance programs such as NIST 800-53, CJIS, or HIPAA.
  • Professional security certification preferred, enhancing credibility in the field.
  • Exposure to Governance Risk and Compliance (GRC) tools like ServiceNow GRC or Archer is beneficial.
  • Solid project management experience is advantageous.

Responsibilities

  • Collaborate with compliance analysts and SMEs to validate security controls supporting audit efforts.
  • Develop processes to automate audit workflows and manage compliance evidence efficiently.
  • Interpret security policies and standards, mapping them to technical implementations while ensuring adherence.
  • Provide guidance on secure product implementation and define security baselines for new systems.
  • Conduct readiness assessments and audit simulations to evaluate technical controls.
  • Identify improvement opportunities leveraging existing systems and explore new technologies.
  • Draft policies and procedures related to risk management and audits.

Benefits

  • Eligible for state employee benefits, including health care and retirement plans.
  • Flexible remote work policy allowing employees to work from anywhere in Colorado.
  • Opportunities for professional development and training in the field of cybersecurity.
  • Supportive work environment promoting work-life balance.
  • Possibility for position extension based on funding and needs.
Full Job Description
Salary: $110,000.00 - $125,000.00 Annually
Location : Statewide, CO
Job Type: Full Time
Job Number: EGB93815
Department: Governor's Office of Information Technology
Opening Date: 07/27/2026
Closing Date: 8/9/2026 11:59 PM Mountain
FLSA: Determined by Position
Primary Physical Work Address: (Remote From Anywhere In CO)
FLSA Status: Exempt; position is not eligible for overtime compensation.
Department Contact Information:
Type of Announcement: This announcement is not governed by the selection processes of the classified personnel system. Applications will be considered from residents and non-residents of Colorado.
How To Apply: Please submit an online application for this position at https://www.governmentjobs.com/careers/colorado. Reach out to the Department Contact to apply using a paper application, including any supplemental questions. Failure to submit a complete and timely application may result in the rejection of your application. Applicants are responsible for ensuring that application materials are received by the appropriate Human Resources office before the closing date and time listed.

Description of Job
TERM LIMITED POSITION: This position is term limited with an anticipated end date of approximately one year from the date of hire. This position is eligible for State employee benefits and may be extended as the situation warrants. This video explains the many benefits of working at the State of Colorado on a term limited basis

IMPORTANT NOTE: Please review your application to ensure completion. For the most equitable applicant experience, OIT's hiring team considers only the contents of your application to review your qualifications. Please do not include any attachments (such as resume or cover letter) with your application as these items are not used by OIT's hiring team.
Do you have demonstrated expertise in core security principles, such as robust access controls, cryptographic methods, and secure system architecture, with the ability to interpret and implement these effectively? Are you able to translate complex security requirements into practical technical guidance to securely implement controls within diverse technical environments?
As OIT's Senior Cyber Security Engineer, you will be a subject matter expert who develops and implements security strategies, ensuring alignment with project goals and operational continuity. In this role, you will collaborate with technical system administrators and engineers, business continuity specialists, compliance analysts, and others to identify improvements and integrate new technologies. One of your key functions will be as a technical liaison between diverse stakeholder groups in complex technical environments. In this role, you will validate security control implementations, provide technical advisory support, and suggest and evaluate security tooling. You will also play a critical part in strengthening the agency's compliance by translating security controls into practical technical guidance.
Key Job Responsibilities:

  • Collaborating with compliance analysts and technical SMEs to validate system-level control implementations to support audit remediation and planning
  • Developing processes and evaluating tooling to improve audit workflow automation and evidence management
  • Interpreting security policies, standards, and frameworks (e.g., NIST 800-53, CJIS, IRS Publication 1075), mapping requirements to technical implementations, and validating adherence.
  • Providing guidance on secure product implementation practices and helping define minimum security and compliance baselines for new systems and services.
  • Developing and collaborating on readiness assessments and audit simulations by evaluating technical control implementations.
  • Identifying opportunities for improvement by leveraging current systems' strengths and investigating new technologies and methodologies.
  • Draft policies and standard operating procedures pertaining to risk management and audits.
  • Manage projects and work with stakeholders to accomplish tasks on schedule.


Minimum Qualifications, Substitutions, Conditions of Employment & Appeal Rights
A wide salary range is posted for this position and any job offer is based upon a salary analysis to comply with the Colorado Equal Pay for Equal Work Act. The salary analysis considers relevant experience, education, certifications, and state seniority as compared to others doing substantially similar work. While most salary offers are made within the posted range, occasionally an offer is made below or above the posted range based upon this salary analysis.

This is a skills-based job announcement. The required minimum qualifications and/or education (if substituting for the proven experience, knowledge, and skills), are as follows:
Minimum Qualifications:

  • At Least five (5) years of experience in a security engineering, secure code reviews, systems administration, or compliance advisory role in a variety of technical environments, including on-premise, cloud, and hybrid.
  • Experience supporting audit or compliance programs (e.g., NIST 800-53 CJIS, IRS, HIPAA, SSA, SOC 2, or similar).

Substitutions:

  • Additional appropriate education will substitute for the required experience on a year-for-year basis, but cannot completely substitute for these qualifications.
  • Training or Certification related to the work assigned to the position will be assigned credit towards substitution for experience and/or education, but cannot completely substitute for these qualifications.
  • If the minimum qualifications include a degree requirement, additional appropriate paid or unpaid experience will substitute for the required education on a year-for-year basis.

Preferred Qualifications:

  • Professional security certification.
  • Exposure to Governance Risk and Compliance (GRC) tooling, such as ServiceNow GRC, Archer, or similar platforms.
  • Project management experience.


Conditions of Employment:
OIT employees must comply with any screening procedures in place at state agency locations where they might perform work.

A pre-employment background check will be conducted as part of the selection process. Post-employment background checks will be required for specific agencies as business needs dictate, which may include a polygraph exam, fingerprint-based criminal history search, reference checks, and a drug test.

This position may require travel within the specified geographic area, and to locations across the state as needed.

This position may require on-call duties as needed by the position.
Supplemental Information
If this posting indicates "remote from anywhere in CO" in the title, periodic reporting to the primary state work location designated for the position is required. All remote work must be performed in Colorado.

While candidates from out of state will be considered for this role, the candidate selected for the position must relocate and reside in Colorado on the first day of their new position. A reasonable timeframe for relocation will be established on an individual basis, while considering business needs, and determining a start date.
We know it's important to support each other, and that means having a healthy balance of work and personal time. Visit our benefits to learn more about some of our great offerings that allow us all to have fulfilling lives.

Visit our How to Apply webpage to learn more about our application process and what to expect after you apply.
This posting may be used to fill multiple vacancies based upon business need.
Please note that each agency's contact information is different; therefore, we encourage all applicants to view the full, official job announcement which includes contact information and class title. Select the job you wish to view, then click on the "Print" icon.
01

TERM LIMITED POSITION:
This position is term limited with an anticipated end date of one year from the time of hire. The position may be extended if additional funds permit it. This position is eligible for State employee benefits. Do you wish to proceed with the selection process?
  • Yes
  • No

02

Please detail how your skills and experience align with the requirements of this position.
03

The role requires acting as a technical liaison between compliance teams and technical stakeholders. Explain your approach to fostering collaboration and effectively communicating highly technical security concepts to non-technical audiences, particularly in the context of audit control implementation or new technology integrations.
04

Describe your experience translating complex security requirements (e.g., those from IRS Publication 1075, CMS MARS-E, or similar) into actionable technical controls and implementation guidance for technical teams. Provide a specific example of a challenge you faced and how you addressed it.
05

Describe your experience in designing, implementing, and operationalizing security tooling and controls across diverse technical environments (on-premise, cloud, and hybrid). Provide an example of how you've identified opportunities for improvement or integrated new technologies to strengthen an agency's security posture.
06

What experience do you have drafting policies and standard operating procedures about risk management and audits?
07

Please describe how you learned of this job opening.
08

The Governor's Office of Information Technology (OIT) complies with Colorado's Equal Pay for Equal Work Act. While a wide salary range is posted, specific criteria (experience, education, state seniority, etc.) will be used to determine any salary offer. While most salary offers are made within the posted range, occasionally an offer is made below or above the posted range based upon this salary analysis. It is this salary analysis, rather than any negotiation process, that determines any salary offer. Please acknowledge your understanding of this process and the posted salary range for this position.
  • Yes, I understand the above statement.

09

All remote work must be performed from within the State of Colorado. If you live out of state and are selected for this position you must relocate to Colorado before commencing employment. There is no form of relocation assistance, financial or otherwise, available for any position. Do you wish to proceed with your submission?
  • Yes, I understand the above statement.

10

Do you currently reside in the state of Colorado?
  • Yes
  • No

11

If any of the State of Colorado positions listed in your employment history were performed as a contract employee, you MUST list the position/s, State Agency, and the name of the contracting company by whom you were paid during the contract position. If this does not apply, please type "N/A".
12

Do you currently require employer sponsorship for a Visa, employer-provided documentation to maintain your Visa, or employer participation in a program for the purposes of immigration status?
  • Yes
  • No

13

In the future, will you require employer sponsorship for a Visa, employer-provided documentation to maintain your Visa, or employer participation in a program for the purposes of immigration status?
  • Yes
  • No

Required Question

Similar Jobs

More Jobs at State of Colorado

More Information Technology Jobs

Find similar Senior Cyber Security Engineer (Remote From Anywhere In Colorado) jobs: