City and County of San Francisco · San Francisco, CA

Cybersecurity Engineer– Administration Division – SF Municipal Transportation Agency (1044) — San Francisco, CA

Full-timeSan Francisco, CAPosted 2026-07-21Apply on SmartRecruiters

Full job description

The San Francisco Municipal Transportation Agency (SFMTA) is a department of the City and County of San Francisco responsible for the management of all ground transportation in the City. The SFMTA has oversight over the Municipal Railway public transit (Transit Division or “Muni”), as well as bicycling, paratransit, parking, traffic, walking, and taxis. SFMTA is currently in the process of implementing an upgrade of the technology used to manage light rail operations on the surface and in the subway.

The Train Control Upgrade Project (TCUP) is a multi-year, multimillion dollar project with the goal of replacing the existing train control system onboard vehicles and in the Muni Metro subway with a state-of-the-art radio-based technology. TCUP will expand supervision of trains by the train control system from the subway to the entire surface Muni light rail system. The TCUP vendor contract and installation work will be managed by a project management team within the Transit Division (“Muni”).

Information Technology is at the core of TCUP. SFMTA’s Technology Solutions and Integration (TSI) team will be delivering the technology scope for TCUP. The role will be supporting delivery of the information technology components.

Success requires significant investments in expanded network infrastructure, data architecture, wireless communication systems, servers, databases, and cybersecurity. Project systems will need data integration with existing enterprise and intelligent transportation systems. Changes need to be baselined, documented, designed, implemented, and tested.

This is an opportunity to work with stakeholders and business units across the SFMTA and take a pivotal step in your career. Your work will impact the lives of all users of our transportation services and infrastructure.

Position Description:

Under the direction of the TCUP Technology Project Manager, the Cybersecurity Engineer works with the team responsible for delivering the network topology, policies, wireless infrastructure, fiber infrastructure, network equipment, security, installation, and testing for the new CBTC system. The Cybersecurity Engineer ensures that communication systems supporting CBTC operations are designed, implemented, and maintained to meet security, resiliency, and regulatory requirements.

Examples of Important and Essential Duties:

  • Serve as the lead cybersecurity architect for TCUP, defining the security posture for all networked, wireless, and backhaul train control systems.
  • Develop and contribute to redundancy and failover strategies, ensuring network resiliency and availability while aligning with cybersecurity requirements.
  • Define and document network policies, including access control, segmentation, QoS, and routing practices, ensuring alignment with cybersecurity principles.
  • Assess wireless spectrum usage for security risks, interference vulnerabilities, and resiliency.
  • Review and provide security oversight of network architecture, including routing, segmentation (VLANs), and multicast configurations.
  • Support the design and configuration of network architecture to ensure support for secure routing, segmentation (VLANs), and multicast communications.
  • Define security standards for hardware lifecycle management and support lifecycle planning decisions.
  • Implement cybersecurity measures, such as firewalls, intrusion detection/prevention systems (IDS/IPS), and endpoint protection.
  • Conduct periodic vulnerability assessments and ensure compliance with industry standards (e.g., NIST, CISA, ISO/IEC 27001).
  • Validate cybersecurity controls in end-to-end communication systems supporting train control operations.
  • Troubleshoot and resolve issues identified during testing phases.
  • Develop and maintain technical documentation for network and cybersecurity architectures, configurations, and operational procedures.
  • Ensure cybersecurity controls align with applicable railway safety and security standards and regulatory requirements.
  • Define requirements for network and security monitoring and ensure integration with enterprise SOC/NOC tools.
  • Performs other related duties as assigned.

Minimum Qualifications:

Education: An associate degree in computer science, computer engineering, information systems, or a closely related field from an accredited college or university OR its equivalent in terms of total course credits/units [i.e., at least sixty (60) semester or ninety (90) quarter credits/units with a minimum of twenty (20) semester or thirty (30) quarter credits/units in one of the fields above or a closely-related field].

Experience: Five (5) years of experience analyzing, installing, configuring, enhancing, and/or maintaining the components of a system or platform.

Substitution: One year of additional experience as described above may be substituted for the required degree.

Notes:

  • Applicants must meet the minimum qualifications by the final filing date unless otherwise noted.
  • One (1) year full-time experience is equivalent to 2000 hours. (2000 hours of qualifying work experience is based on a 40-hour work week). Any overtime hours that you work above forty (40) hours per week are not included in the calculation to determine full-time experience.

Desirable Qualifications:

The stated desirable qualifications may be used to identify candidates advancing to the interview process and/or to identify job finalist(s) at the end of the selection process when referred for hiring.

  • 5+ years’ experience leading cybersecurity architecture for large, mission‐critical or safety‐critical systems.
  • Knowledge of SIEM, SOAR, and/or SOC integrations for network and OT telemetry.
  • 5-years’ experience securing LTE and 5G (3GPP) wireless communications for mission‐critical or operational technology environments.
  • 5-years’ experience applying security principles to networks (e.g., BGP security, MPLS segmentation, multicast control).
  • 5 years’ experience implementing and managing network security protocols, including encryption (e.g., IPSec, TLS), firewalls, IDS/IPS, and endpoint security.
  • 5 years’ experience of cybersecurity frameworks (e.g., NIST Cybersecurity Framework, EN 50159:2010, IEC 62443) and best practices.
  • 5 years’ defining, reviewing, and validating network and security test plans.
  • Proficiency with tools for security validation, performance monitoring, and troubleshooting (e.g., SIEM platforms, EDR/XDR Wireshark, SolarWinds, NetScout).
  • Familiarity with network equipment from major vendors (e.g. Palo Alto, Fortinet, Cisco, Juniper, Nokia, Ericsson) and radio system hardware (e.g., base stations, access points).
  • 5-years’ experience working with system engineers, project managers, operations teams, and regulatory bodies to ensure alignment of system requirements and performance goals.
  • 5-years’ experience designing and implementing secure system architectures using Zero Trust principles, including Identity and Access management (IAM), least privilege access, and secure system design practices across system lifecycle.
  • 5-years’ experience conducting threat modeling and cybersecurity risk assessments for complex systems, with demonstrated ability to coordinate incident response activities and integrate security monitoring with enterprise SOC processes.
  • 5-years’ experience securing transportation, rail, utilities, or other critical infrastructure environments.
  • Ability to communicate progress and issues to stakeholders through regular status updates and technical reports.
  • Experience collaborating with diverse stakeholders and fostering an inclusive environment that values different perspectives, backgrounds, and expertise to drive effective decision-making.

Verification:

Applicants may be required to submit verification of qualifying education and experience at any point during the recruitment and selection process. More information can be found at: https://careers.sf.gov/knowledge/#verification. Falsifying one’s education, training, or work experience or attempted deception on the application may result in disqualification for this and future job opportunities with the City and County of San Francisco.

All work experience, education, training and other information substantiating how you meet the minimum qualifications must be included in your application by the filing deadline. Information submitted after the filing deadline will not be considered in determining whether you meet the minimum qualifications.

Selection Process:

Applications will be screened for relevant qualifying experience. Additional screening mechanisms may be used to determine candidates' qualifications. Only those applicants who most closely meet the needs of the Agency will be invited to move forward in the selection process.

  • Information About the Hiring Process
  • Conviction History
  • Employee Benefits Overview
  • Equal Employment Opportunity
  • Disaster Service Worker
  • ADA Accommodation
  • Right to Work
  • Copies of Application Documents
  • Diversity Statement

How to Apply: Applications for City and County of San Francisco jobs are only accepted through an online process.

  • Visit Careers With Purpose | City and County of San Francisco
  • Type “1044” in the “Search by class or keyword” field.
  • Click the link to open the Job Announcement.
  • Select the “Apply Now” button and follow the instructions on the screen.
  • A cover letter and resume should be attached to the online application.
  • Submit response to supplemental questionnaire: https://forms.cloud.microsoft/r/HbiPYHNPBN

For questions or inquiries, please contact the Human Resources Analyst, Melissa Lee at Melissa.Lee@sfmta.com.

This recruitment may be utilized to fill similar positions in this classification at SFMTA.