Cybersecurity Engineer– Administration Division – SF Municipal Transportation Agency (1044)

City and County of San FranciscoSan Francisco, CA
$171,158 - $215,306Hybrid

About The Position

The San Francisco Municipal Transportation Agency (SFMTA) is seeking a Cybersecurity Engineer to support the Train Control Upgrade Project (TCUP). This project involves replacing the existing train control system with a state-of-the-art radio-based technology, expanding supervision of trains across the entire light rail system. The Technology Solutions and Integration (TSI) team will deliver the technology scope for TCUP, requiring significant investments in network infrastructure, data architecture, wireless communication systems, servers, databases, and cybersecurity. This role is crucial for ensuring the security, resiliency, and regulatory compliance of communication systems supporting CBTC operations. The Cybersecurity Engineer will work under the direction of the TCUP Technology Project Manager, contributing to the design, implementation, and maintenance of network topology, policies, wireless and fiber infrastructure, network equipment, and security for the new CBTC system.

Requirements

  • An associate degree in computer science, computer engineering, information systems, or a closely related field from an accredited college or university OR its equivalent in terms of total course credits/units [i.e., at least sixty (60) semester or ninety (90) quarter credits/units with a minimum of twenty (20) semester or thirty (30) quarter credits/units in one of the fields above or a closely-related field].
  • Five (5) years of experience analyzing, installing, configuring, enhancing, and/or maintaining the components of a system or platform.
  • One year of additional experience as described above may be substituted for the required degree.
  • Completion of the 1010 Information Systems Trainee Program may be substituted for the required degree.

Nice To Haves

  • 5+ years’ experience leading cybersecurity architecture for large, mission‑critical or safety‑critical systems.
  • Knowledge of SIEM, SOAR, and/or SOC integrations for network and OT telemetry.
  • 5-years’ experience securing LTE and 5G (3GPP) wireless communications for mission‑critical or operational technology environments.
  • 5-years’ experience applying security principles to networks (e.g., BGP security, MPLS segmentation, multicast control).
  • 5 years’ experience implementing and managing network security protocols, including encryption (e.g., IPSec, TLS), firewalls, IDS/IPS, and endpoint security.
  • 5 years’ experience of cybersecurity frameworks (e.g., NIST Cybersecurity Framework, EN 50159:2010, IEC 62443) and best practices.
  • 5 years’ defining, reviewing, and validating network and security test plans.
  • Proficiency with tools for security validation, performance monitoring, and troubleshooting (e.g., SIEM platforms, EDR/XDR Wireshark, SolarWinds, NetScout).
  • Familiarity with network equipment from major vendors (e.g. Palo Alto, Fortinet, Cisco, Juniper, Nokia, Ericsson) and radio system hardware (e.g., base stations, access points).
  • 5-years’ experience working with system engineers, project managers, operations teams, and regulatory bodies to ensure alignment of system requirements and performance goals.
  • 5-years’ experience designing and implementing secure system architectures using Zero Trust principles, including Identity and Access management (IAM), least privilege access, and secure system design practices across system lifecycle.
  • 5-years’ experience conducting threat modeling and cybersecurity risk assessments for complex systems, with demonstrated ability to coordinate incident response activities and integrate security monitoring with enterprise SOC processes.
  • 5-years’ experience securing transportation, rail, utilities, or other critical infrastructure environments.
  • Ability to communicate progress and issues to stakeholders through regular status updates and technical reports.
  • Experience collaborating with diverse stakeholders and fostering an inclusive environment that values different perspectives, backgrounds, and expertise to drive effective decision-making.

Responsibilities

  • Serve as the lead cybersecurity architect for TCUP, defining the security posture for all networked, wireless, and backhaul train control systems.
  • Develop and contribute to redundancy and failover strategies, ensuring network resiliency and availability while aligning with cybersecurity requirements.
  • Define and document network policies, including access control, segmentation, QoS, and routing practices, ensuring alignment with cybersecurity principles.
  • Assess wireless spectrum usage for security risks, interference vulnerabilities, and resiliency.
  • Review and provide security oversight of network architecture, including routing, segmentation (VLANs), and multicast configurations.
  • Support the design and configuration of network architecture to ensure support for secure routing, segmentation (VLANs), and multicast communications.
  • Define security standards for hardware lifecycle management and support lifecycle planning decisions.
  • Implement cybersecurity measures, such as firewalls, intrusion detection/prevention systems (IDS/IPS), and endpoint protection.
  • Conduct periodic vulnerability assessments and ensure compliance with industry standards (e.g., NIST, CISA, ISO/IEC 27001).
  • Validate cybersecurity controls in end-to-end communication systems supporting train control operations.
  • Troubleshoot and resolve issues identified during testing phases.
  • Develop and maintain technical documentation for network and cybersecurity architectures, configurations, and operational procedures.
  • Ensure cybersecurity controls align with applicable railway safety and security standards and regulatory requirements.
  • Define requirements for network and security monitoring and ensure integration with enterprise SOC/NOC tools.
  • Performs other related duties as assigned.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service