Security Specialist (SCI)
U.S. Pacific Fleet
Posted: March 26, 2026 (1 day ago)
This job was posted recently. Fresh listings typically have less competition.
State of Colorado
Governor's Office of Information Technology
Base salary range: $147,649 - $221,900
Typical requirements: Executive-level leadership experience. Senior executive qualifications required.
Note: Actual salary includes locality pay (15-40%+ depending on location).
This job involves leading efforts to identify, measure, and reduce security risks in Colorado's state IT systems, including assessing technologies and managing risks from third-party vendors.
You'll guide teams, perform detailed evaluations of systems in various setups like on-site or cloud, and help build a more automated way to handle these risks.
It's ideal for an experienced tech leader who enjoys collaborating across departments to keep government services safe and reliable.
The work of employees at the Governor's Office of Information Technology (OIT) is challenging and diverse because the needs of agencies, customers and Coloradans constantly evolve.
But our focus never changes: improve the lives of all Coloradans through innovation and collaboration.
We're building one of the nation's leading government IT organizations by reimagining how we support agencies, building first-of-their-kind applications, and creating an inclusive, collaborative culture, together.
Join us in the important work of providing equitable access to services.
IMPORTANT NOTE: Please review your application to ensure completion.
For the most equitable applicant experience, OIT’s hiring team considers only the contents of your application to review your qualifications.
Please do not include any attachments (such as resume or cover letter) with your application as these items are not used by OIT’s hiring team.
The Governor’s Office of Information Technology (OIT) is seeking a Senior Security Engineer (Risk) to join the Office of Information Security (OIS).
Our team is currently advancing a strategic transformation to modernize our Risk Management capabilities.
We are evolving our security oversight into a highly integrated, automated maturity model designed to provide a data-driven view of the state's threat landscape.
As the Senior Security Engineer (Risk), you will serve as a technical leader and subject matter expert dedicated to the identification, quantification, and mitigation of technical risk across the state enterprise.
This role requires a seasoned professional with demonstrated leadership experience who can provide technical guidance across the organization and offer strategic direction during complex security evaluations.
A primary function of this role is performing comprehensive technical risk assessments on diverse systems and services to ensure they align with the state’s security posture.
You will be a key contributor in enabling the creation of a Third-Party Risk Management (TPRM) program designed to scale significantly, performing assessments for a high volume of vendors with efficiency and precision.
You will act as a senior technical liaison between system engineers, project managers, and executive leadership, translating high-level vulnerabilities into actionable risk narratives.
Your work will directly support the risk management strategic roadmap, ensuring state technology remains resilient through consistent, expert-level evaluation.
Key Job Responsibilities:
Cross-Functional Technical Guidance & Collaboration: Act as a key security advisor and collaborator for teams across the organization.
You will partner with technical teams to provide technical guidance on risk mitigation.
You will serve as a technical point of escalation during the daily standups to ensure cross-team alignment on remediation strategies.
Perform Complex Risk Assessments: Execute deep-dive technical risk assessments for high-profile state systems.
You will evaluate control implementations across a variety of technical environments, including on-premise, cloud, and hybrid, identifying critical gaps and architecting technical remediation plans.
Support Scalable TPRM Architecture: Serve as a key member in designing a TPRM program capable of handling an enterprise volume of vendors.
You will define technical standards for reviewing technical support documentation and helping establish the automated intake workflows necessary to scale these assessments.
Strategic Roadmap Contribution: Support the execution and refinement of the risk management strategic roadmap. You will be responsible for driving milestones related to risk intake maturity and expanding risk services to state agencies and local government partners.
Enable Automation (ServiceNow IRM): Support the transition from legacy workflows to automated processes within the ServiceNow IRM module. You will provide the technical expertise needed to ensure the platform delivers real-time, asset-level risk visibility for leadership.
Threat Landscape Visibility: Partner with data and engineering teams to help build "Top 10" Enterprise Risk Dashboards in Splunk. You will contribute "Actionable Insight Statements" that help leadership prioritize resources based on data-driven risk findings.
Minimum Qualifications:
Experience: At least five (5) years of professional experience in security engineering, technical risk management, or high-level systems administration with a focus on security.
Leadership Background: Demonstrated experience in a technical leadership capacity, such as serving as a team lead, managing project workstreams, or providing high-level technical guidance to other technical staff.
Risk Management Expertise: Proven experience in the full risk lifecycle, including performing risk assessments, identifying threats, and developing successful remediation strategies.
Substitutions:
Additional appropriate education will substitute for the required experience on a year-for-year basis, but cannot completely substitute for these qualifications.
Training or Certification (CRISC, CISSP, CISA) related to the work assigned to the position will be assigned credit towards substitution for experience and/or education, but cannot completely substitute for these qualifications.
Framework-Based Risk Assessment: Demonstrated experience utilizing industry security frameworks (such as NIST 800-53, CJIS, IRS Pub 1075, or SOC 2) as the technical baseline to perform risk assessments, evaluate control effectiveness, and provide engineering-level guidance on mitigating identified enterprise risks.
Broad Technical Background: Experience validating security controls in a variety of environments, including on-premise infrastructure and modern cloud architectures.
ServiceNow IRM: Experience implementing, configuring, or operationalizing the ServiceNow IRM/GRC module to automate risk workflows is highly helpful.
Program Scaling: Previous experience working within or building a high-volume Third-Party Risk Management program.
Security Analytics: Experience using Splunk or similar tools to visualize and report on risk metrics for executive audiences.
Operational Readiness: Ability to "hit the ground running" to meet aggressive roadmap goals while maintaining a focus on team-wide technical excellence.
OIT employees must comply with any screening procedures in place at state entity locations where they might be required to perform work.
A pre-employment background check will be conducted as part of the selection process.
Positions supporting some agencies, such as the Department of Corrections and the Department of Public Safety, will also require a pre-employment drug test.
This position may require travel within the specified geographic area and to locations across the state as needed.
If this posting indicates “remote from anywhere in CO” in the title, periodic reporting to the primary state work location designated for the position is required. All remote work must be performed in Colorado.
We know it's important to support each other, and that means having a healthy balance of work and personal time. Visit our benefits to learn more about some of our great offerings that allow us all to have fulfilling lives.
The State of Colorado strives to create a Colorado for All by building and maintaining workplaces that value and respect all Coloradans through a commitment to equal opportunity and hiring based on merit and fitness.
The State is resolute in non-discriminatory practices in everything we do, including hiring, employment, and advancement opportunities.
The Governor's Office of Information Technology is committed to the full inclusion of all qualified individuals.
As part of this commitment, our agency will assist individuals who have a disability with any reasonable accommodation requests related to employment, including completing the application process, interviewing, completing any pre-employment testing, participating in the employee selection process, and/or to perform essential job functions where the requested accommodation does not impose an undue hardship.
If you have a disability and require reasonable accommodation to ensure you have a positive experience applying or interviewing for this position, please direct your inquiries to our ADA Coordinator at OIT_HR@state.co.us or call (303) 764-7900.
The Governor's Office of Information Technology does NOT offer sponsored Visas for employment purposes.
Check your resume before applying to catch common mistakes