Cybersecurity Engineer– Administration Division – SF Municipal Transportation Agency (1044)
About this role
<p>The San Francisco Municipal Transportation Agency (SFMTA) is a department of the City and County of San Francisco responsible for the management of all ground transportation in the City. The SFMTA has oversight over the Municipal Railway public transit (Transit Division or “Muni”), as well as bicycling, paratransit, parking, traffic, walking, and taxis. SFMTA is currently in the process of implementing an upgrade of the technology used to manage light rail operations on the surface and in the subway.</p><p>The Train Control Upgrade Project (TCUP) is a multi-year, multimillion dollar project with the goal of replacing the existing train control system onboard vehicles and in the Muni Metro subway with a state-of-the-art radio-based technology. TCUP will expand supervision of trains by the train control system from the subway to the entire surface Muni light rail system. The TCUP vendor contract and installation work will be managed by a project management team within the Transit Division (“Muni”).</p><p>Information Technology is at the core of TCUP. SFMTA’s Technology Solutions and Integration (TSI) team will be delivering the technology scope for TCUP.  The role will be supporting delivery of the information technology components.</p><p>Success requires significant investments in expanded network infrastructure, data architecture, wireless communication systems, servers, databases, and cybersecurity. Project systems will need data integration with existing enterprise and intelligent transportation systems. Changes need to be baselined, documented, designed, implemented, and tested.</p><p>This is an opportunity to work with stakeholders and business units across the SFMTA and take a pivotal step in your career. Your work will impact the lives of all users of our transportation services and infrastructure.</p><p> </p><p><strong>Position Description:</strong></p><p>Under the direction of the TCUP Technology Project Manager, the Cybersecurity Engineer works with the team responsible for delivering the network topology, policies, wireless infrastructure, fiber infrastructure, network equipment, security, installation, and testing for the new CBTC system. The Cybersecurity Engineer ensures that communication systems supporting CBTC operations are designed, implemented, and maintained to meet security, resiliency, and regulatory requirements.</p><p> </p><p><strong>Examples of Important and Essential Duties: </strong></p><ul><li>Serve as the lead cybersecurity architect for TCUP, defining the security posture for all networked, wireless, and backhaul train control systems.</li><li>Develop and contribute to redundancy and failover strategies, ensuring network resiliency and availability while aligning with cybersecurity requirements.</li><li>Define and document network policies, including access control, segmentation, QoS, and routing practices, ensuring alignment with cybersecurity principles.</li><li>Assess wireless spectrum usage for security risks, interference vulnerabilities, and resiliency.</li><li>Review and provide security oversight of network architecture, including routing, segmentation (VLANs), and multicast configurations.</li><li>Support the design and configuration of network architecture to ensure support for secure routing, segmentation (VLANs), and multicast communications.</li><li>Define security standards for hardware lifecycle management and support lifecycle planning decisions.</li><li>Implement cybersecurity measures, such as firewalls, intrusion detection/prevention systems (IDS/IPS), and endpoint protection.</li><li>Conduct periodic vulnerability assessments and ensure compliance with industry standards (e.g., NIST, CISA, ISO/IEC 27001).</li><li>Validate cybersecurity controls in end-to-end communication systems supporting train control operations.</li><li>Troubleshoot and resolve issues identified during testing phases.</li><li>Develop and maintain technical documentation for network and cybersecurity architectures, configurations, and operational procedures.</li><li>Ensure cybersecurity controls align with applicable railway safety and security standards and regulatory requirements.</li><li>Define requirements for network and security monitoring and ensure integration with enterprise SOC/NOC tools.</li><li>Performs other related duties as assigned.</li></ul><p> </p> <p><strong><u>Minimum Qualifications:</u></strong></p><p><strong>Education:</strong> An associate degree in computer science, computer engineering, information systems, or a closely related field from an accredited college or university OR its equivalent in terms of total course credits/units [i.e., at least sixty (60) semester or ninety (90) quarter credits/units with a minimum of twenty (20) semester or thirty (30) quarter credits/units in one of the fields above or a closely-related field].</p><p><strong>Experience:</strong> Five (5) years of experience analyzing, installing, configuring, enhancing, and/or maintaining the components of a system or platform.</p><p><strong>Substitution:</strong> One year of additional experience as described above may be substituted for the required degree.</p><p>Completion of the 1010 Information Systems Trainee Program may be substituted for the required degree.</p><p> </p><p><strong><u>Notes:</u></strong></p><p>1. Applicants must meet the minimum qualifications by the final filing date unless otherwise noted.</p><p> </p><p>2. One (1) year full-time experience is equivalent to 2000 hours. (2000 hours of qualifying work experience is based on a 40-hour work week). Any overtime hours that you work above forty (40) hours per week are not included in the calculation to determine full-time experience.</p><p> </p><p><strong><u>Desirable Qualifications:</u></strong></p><p>The stated desirable qualifications may be used to identify candidates advancing to the interview process and/or to identify job finalist(s) at the end of the selection process when referred for hiring.</p><ul><li>5+ years’ experience leading cybersecurity architecture for large, mission‑critical or safety‑critical systems.</li><li>Knowledge of SIEM, SOAR, and/or SOC integrations for network and OT telemetry.</li><li>5-years’ experience securing LTE and 5G (3GPP) wireless communications for mission‑critical or operational technology environments.</li><li>5-years’ experience applying security principles to networks (e.g., BGP security, MPLS segmentation, multicast control).</li><li>5 years’ experience implementing and managing network security protocols, including encryption (e.g., IPSec, TLS), firewalls, IDS/IPS, and endpoint security.</li><li>5 years’ experience of cybersecurity frameworks (e.g., NIST Cybersecurity Framework, EN 50159:2010, IEC 62443) and best practices.</li><li>5 years’ defining, reviewing, and validating network and security test plans.</li><li>Proficiency with tools for security validation, performance monitoring, and troubleshooting (e.g., SIEM platforms, EDR/XDR Wireshark, SolarWinds, NetScout).</li><li>Familiarity with network equipment from major vendors (e.g. Palo Alto, Fortinet, Cisco, Juniper, Nokia, Ericsson) and radio system hardware (e.g., base stations, access points).</li><li>5-years’ experience working with system engineers, project managers, operations teams, and regulatory bodies to ensure alignment of system requirements and performance goals.</li><li>5-years’ experience designing and implementing secure system architectures using Zero Trust principles, including Identity and Access management (IAM), least privilege access, and secure system design practices across system lifecycle.</li><li>5-years’ experience conducting threat modeling and cybersecurity risk assessments for complex systems, with demonstrated ability to coordinate incident response activities and integrate security monitoring with enterprise SOC processes.</li><li>5-years’ experience securing transportation, rail, utilities, o...
Note: Railex aggregates rail industry jobs from public career pages. All applications are processed directly by SFMTA. Railex does not collect application data.

