Jobs and Careers
CI

PRINCIPAL CYBERSECURITY ENGINEER

City and County of San Francisco
San Francisco, United Statesfull_timeVerifiedPosted 7 Oct 2025
💰 $207,974/yr($165,334/yr$207,974/yr)

About the role

Company Description

San Francisco International Airport (SFO), an enterprise department of the City and County of San Francisco, has a workforce of approximately 1,900 City employees and is committed to being a diverse, equitable, and inclusive employer.

SFO is more than an airport—we are a dynamic organization where employees collaborate with a wide range of stakeholders to support global travel, economic development, and public service. We are recognized as a leader in environmental sustainability, equity, and forward-thinking infrastructure, and continue to be at the forefront of transforming the travel experience.

Our mission is to deliver an airport experience where people and our planet come first.

Our Vision, Mission, and Core Values shape our culture and operations as we continue to build a supportive, purpose-driven workplace where all employees can thrive.

Learn more about careers at SFO at flysfo.com, and follow us on FacebookInstagramYouTubeLinkedInBluesky and Threads.

APPOINTMENT TYPE: Permanent Exempt. This position is excluded by the Charter from the competitive civil service examination process and shall serve at the discretion of the Appointing Officer.

Specific information regarding this recruitment and position are listed below:

  • Application Opened: Monday, October 6, 2025
  • Application Deadline: Thursday, October 16, 2025
  • Compensation: $165,334 to $207,974 Annually
  • Work Schedule: Full-time, 40 hours per week.
  • Work Location: San Francisco International Airport –ITT Division
  • Recruitment ID: PEX-9976-160108

Job Description

Under the direction of the Director, Cybersecurity and Compliance, the Principal Cybersecurity Engineer analyzes, plans, designs, implements, maintains, troubleshoots, and enhances the confidentiality, integrity, and availability of large complex systems and networks. This position contributes to the overall security of Airport information assets and technologies through the creation and ongoing support of preventative detective and corrective controls.  The Principal Cybersecurity Engineer identifies, refines, and analyzes cybersecurity data across a wide variety of sources to report against agree upon key performance indicators measuring the efficacy of these controls.  This position works closely with Airport's operations and engineering teams to remediate cybersecurity issues and concerns.

You are excited about this opportunity because you will:

  1. Serve as a primary subject matter expert for information security and cyber-security for SFO: maintain skills and expertise within areas of cybersecurity and information security for ICT and ICS environments. Contribute to requirements definitions on SFO initiatives and projects, including analysis of risks aligned with IT and OT reference architecture and standards.
  2. Work with clients to identify business and technical cybersecurity requirements. Determine cybersecurity requirements for the development or enhancement of large complex systems and networks that comprise the backbone of the Airport's information technology and infrastructure; determine the suitability of existing solutions to meet these requirements. Lead the design, implementation, and monitoring of all remote-access mechanisms associated with Airport information assets.
  3. Assess the effectiveness of existing processes, procedures, controls, and safeguards to prevent cyber-security breaches across SFO's infrastructure. Facilitate a consistent and positive security posture across multiple independent information systems throughout SFO. Assess and provide recommended cloud security controls to facilitate security of SFO cloud presence, including adequate accounting of data access controls. Identify and remediate threats and vulnerabilities to these assets.
  4. Maintain and continually improve SFO’s vulnerability management program, including but not limited to patch management, vulnerability scanning, and reporting monthly status on the program’s effectiveness. Recommend and implement new or revised security measures based on risk analysis for purposes of protecting SFO information systems and resources, performing periodic analysis of security measure effectivene

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

City and County of San Francisco

View company profile →