Geospatial Cyber Security Engineer – Multiple Positions at Junior/Mid/Senior Levels
On-siteSpringfield, Virginia, United States
Job Summary
Conduct system Assessment & Authorization (A&A) using RMF processes, including control selection, implementation, assessment, and continuous monitoring. Develop, review, and maintain security documentation such as SSPs, POA&Ms, SARs, and ATO artifacts in XACTA or eMASS tools. Perform vulnerability assessments and compliance scans like ACAS, tracking remediation of findings and IAVM requirements. Implement and validate security controls aligned with NIST 800-53, CNSSI 1253, and DOD guidance while supporting system hardening, patching, and configuration management for Linux, Windows, and network devices. Monitor systems for security events, support incident response, and assess security impacts of system changes for configuration control boards. Collaborate with systems engineers, administrators, and DevSecOps teams to integrate security throughout the system lifecycle, providing risk input to program leadership and Authorizing Officials. Requires Top Secret Clearance with SCI eligibility and 5+ years of relevant experience.
Required Qualifications
- US citizenship
- Active or Current (within two years of active) Top Secret Security Clearance with SCI eligibility
- Bachelor's degree in Computer Science, Engineering, DevOps, or related technical field
- 5+ years of relevant experience
- DoD 8570 IAT Level II or higher certification (e.g., Security+, CySA+, CISSP)
- Experience with RM, A&A, POA&M, and ATO documentation (XACTA/eMASS)
- Hands-on vulnerability scanning and compliance tracking (ACAS, IAVM)
- Experience securing Linux and Windows systems, STIGs, patching, and system hardening
- Knowledge of NIST 800-series publications and incident response processes
- Strong analytical, communication, and collaborative skills
- Active/Current Top Secret Clearance with SCI Eligibility
- Travel up to 15% of the time
Desired Qualifications
- Scripting or development experience (Python, Java, React)
- DevSecOps tools and pipeline experience
- Experience with Linux (RedHat/CentOS), database, web apps, or big data platforms
- Familiarity with Agile environments and tools (Jira, Confluence)
- Experience with NIST SP 800-171 and Systems Security Engineering (SSE)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.