Mid Cyber Security Engineer
$145,000–$145,000 year
On-siteVienna, Virginia, United States
Job Summary
Apply RMF processes to support system Assessment & Authorization, including control selection, implementation, assessment, and continuous monitoring. Develop, review, and maintain security documentation such as SSPs, POA&Ms, and ATO artifacts in XACTA or eMASS. Conduct vulnerability assessments and compliance scans, tracking remediation of findings and IAVM requirements. Implement and validate security controls aligned with NIST 800-53, CNSSI 1253, and related DoD guidance. Support system hardening, patching, and configuration management in compliance with STIGs for Linux, Windows, and network devices. Monitor systems for security events and support incident response and risk mitigation activities. Assess security impacts of system changes and support configuration control boards. Collaborate with system engineers, administrators, and DevSecOps teams to integrate security throughout the system lifecycle. Provide cybersecurity risk input to program leadership, Authorizing Officials, and stakeholders.
Required Qualifications
- Bachelor's degree with 3+ years of experience (or equivalent experience)
- Experience with RMF, A&A, POA&M, and ATO documentation (XACTA/eMASS)
- Experience securing Linux and Windows systems, STIGs, patching, and system hardening
- DoD 8570 IAT Level II or higher certification (e.g., Security+, CySA+, CISSP)
- Active or Current (within two years of active) Top Secret Security Clearance with SCI eligibility
Desired Qualifications
- Scripting or development experience (Python, Java, React)
- DevSecOps tools and pipeline experience
- Experience with Linux (Red Hat/CentOS), databases, web apps, or big data platforms
- Familiarity with Agile environments and tools (Jira, Confluence)
- Experience with NIST SP 800-171 and System Security Engineering (SSE)
- Ability to work independently and yet be effective within a team setting
- Must be capable of managing multiple efforts with time-related constraints in a fast-paced contracting environment
- Demonstrated ability to effectively communicate and collaborate with diverse internal and external stakeholder groups and individuals
- Friendly presence, helpful attitude, good interpersonal skills, and ability to work well with others
- Excellent skills in Microsoft Word, Excel, and other Office applications
- Proficient with Microsoft Office Applications, and experience working in a home office setting, as well as the ability to train end users on frequently asked technical issues
- Ability to provide technical assistance and support over the phone; good phone skills, professional demeanor, and previous customer service experience strongly desired
- Good problem-solving skills; ability to visualize a problem/situation and think abstractly to solve it
- Hands-on vulnerability scanning and compliance tracking (ACAS, IAVM)
- Knowledge of NIST 800-series publications and incident response processes
- Strong analytical, communication, and collaboration skills
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.