Cybersecurity Engineer (FedRAMP) US Remote
$90,000–$100,000 year
RemoteUnited States
Job Summary
Execute advanced security assessments for client information systems by conducting interviews, leading discussions, and performing evidence collection to evaluate compliance with FedRAMP, FISMA, and NIST RMF requirements. Utilize tools such as Nessus, ACAS, and NMAP to perform vulnerability scanning, analyze findings, and validate remediation strategies. Lead technical discussions, mentor team members, and prepare original reports, attestations, and customer-facing documentation while guiding cross-functional teams through secure cloud architecture and risk mitigation activities. Operate independently in a remote, deadline-driven environment with up to 25% travel, requiring a US citizen with an active SECRET security clearance.
Required Qualifications
- Bachelor's Degree in Computer Science, Engineering, Information Systems, or Technology
- Must be a U.S. citizen with the ability to obtain a necessary security clearance as required by our government customers
- Legal authorization to work in the U.S. indefinitely
- Employer work permit sponsorship is not available for this position
- Must be a US Citizen and able to obtain an active SECRET Security Clearance
- Must hold one other advanced certification such as CISA, CISM, etc. in accordance with the A2LA R311
- The candidate must have at least one industry certification from the following list: Cisco Certified Network Associate Security (CCNA Security), Cisco Certified Network Associate Cyber Security Operations (CCNA Cyber Ops), Cybersecurity Analyst (CySA+), GIAC Certified Incident Handler (GCIH), GIAC Systems and Network Auditor (GSNA), GIAC Certified Intrusion Analyst (GCIA), Certified Information Systems Auditor (CISA), Certified Information System Security Professional or Associate (CISSP or A...
- Must be able to travel up to 25% as required for various client engagements
- Must be a U.S. Citizen and able to obtain an active SECRET Security Clearance
- Must hold one other advanced certification such as CISA, CISM, etc. in accordance with the A2LA R311
- The candidate must have at least one industry certification from the following list: Cisco Certified Network Associate Security (CCNA Security), Cisco Certified Network Associate Cyber Security Operations (CCNA Cyber Ops), Cybersecurity Analyst (CySA+), GIAC Certified Incident Handler (GCIH), GIAC Systems and Network Auditor (GSNA), GIAC Certified Intrusion Analyst (GCIA), Certified Information Systems Auditor (CISA), Certified Information System Security Professional or Associate (CISSP or A...
Desired Qualifications
- Bachelor's Degree or 5+ years equivalent experience
- 3+ years of experience in performing and/or participating in FISMA based security Assessment and Authorization (A&A) activities
- Strong technical background in security engineering, secure architecture, system and network security, authentication protocols, applied cryptography, and application security
- Expert knowledge of Cloud Computing, FedRAMP, FISMA, NIST/DoD RMF, and NIST SP 800-series publications
- Intermediate experience with testing and assessment tools such as Nessus/ACAS, SCC, DISA STIGs/STIG Viewer, NMAP, and Acunetix
- Self-motivated and able to operate independently or as part of a team
- Ability to author original assessment reports, attestations, and compliance documentation
- Strong verbal communication, organizational, planning, and attention to detail skills
- Successful completion of the FedRAMP Baltimore Cyber Range
- Knowledge of the Software Development Lifecycle (SDLC) as it relates to Information Security and Information Assurance
- Must hold one other advanced certification such as CISA, CISM, etc. in accordance with the A2LA R311
- The candidate must have at least one industry certification from the following list: Cisco Certified Network Associate Security (CCNA Security), Cisco Certified Network Associate Cyber Security Operations (CCNA Cyber Ops), Cybersecurity Analyst (CySA+), GIAC Certified Incident Handler (GCIH), GIAC Systems and Network Auditor (GSNA), GIAC Certified Intrusion Analyst (GCIA), Certified Information Systems Auditor (CISA), Certified Information System Security Professional or Associate (CISSP or A...
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.