Position Title: Cyber Security Engineer
Location: Remote; must reside within the National Capital Region (NCR).
Work Schedule: Full-time, 40 hours per week. Must be available during Department core hours of 9:00 a.m. - 3:00 p.m. ET, Monday - Friday, and flex working hours as needed to meet CST day-to-day and emergent requirements. No work is performed on Federal holidays or during Government closures. Participates in a rotating on-call schedule supporting 24x7x365 availability of the vulnerability and compliance scanning platforms.
Employment Type: Full-Time, Exempt (W-2), contingent upon Call Order award
Clearance: Secret
Position SummaryThe Cyber Security Engineer III is the dedicated, full-time Tenable platform lead. The engineer owns engineering, operations, and maintenance of the CA Tenable vulnerability and compliance scanning platform used to assess on-premises consular systems (platform integrations, troubleshooting, backups, patching, user access, dashboard development, plugin updates, scan template design, and scan scheduling) and sustains 24x7x365 platform availability. The engineer also leads ad-hoc and BOD-driven scanning and agent deployment and integration efforts.
Key Responsibilities- Serve as the dedicated, full-time Tenable subject matter expert; maintain 24x7x365 platform availability and lead the on-call rotation.
- Administer the Tenable platform end toend:integrations, troubleshooting, backups, patching and version upgrades, user access and role management, plugin and feed updates.
- Design and maintain scan templates, policies, and schedules to ensure requiredcoverage: weeklyservers, monthly workstations, and any additional cadence required by Binding Operational Directives (RMF Step 6).
- Perform ad-hoc and BOD-specific scans on request to confirm hardened server builds for developers, production applications, and appliances.
- Ensure all in-scope assets are onboarded, grouped, and tagged in Tenable in accordance with CA configuration standards; support CA iPost application groupings and asset inventory accuracy.
- Develop dashboards, reports, and metrics for the ISSM, AO, ISSOs, and other stakeholders, including KEV, CVE, and STIG compliance reporting.
- Lead Nessus Agent deployment, data ingest and sharing, pipeline, and other integration efforts.
- Deliver vulnerability and compliance scan results to ISSOs within timelines and to the assessment team during RMF Step 4.
- Coordinate logistics for Red Cell penetration testing and Blue Team cyber hygiene scans; support hardened-build verification.
- Document platform architecture, SOPs, and configuration baselines; provide Tenable evidence for the Evidence Index and SSPs.
- Mentor the Cyber Security Engineer on platform operations and serve as escalation point for scanning issues.
Required Qualifications- Seven (7)+ years of cybersecurity or systems engineering experience, including four (4)+ years administering Tenable (Tenable Security Center / tenable.sc, Nessus, Nessus Agents, Tenable One / Vulnerability Management) at enterprise scale.
- Strong Linux and Windows administration skills and scripting proficiency (Python, PowerShell, or Bash) including use of REST APIs for automation and reporting.
- Experience with STIG/SCAP compliance scanning and audit files.
- Active, final SECRET security clearance; U.S. citizenship.
- DoD 8140/8570 IAT Level III baseline certification (e.g., CISSP, CASP+, GCIH, GCED) or IAT Level II with ability to obtain Level III within 6 months.
- Experience supporting a 24x7 on-call rotation for a production security platform.
Preferred Qualifications- Tenable certifications (Tenable Security Center Specialist, Nessus Specialist, Tenable One).
- Department of State experience, including iPost integration; DoD ACAS experience.
- Experience with Wiz or another CNAPP for cloud scanning; SIEM (Splunk) integration.
- Experience with CISA BOD 22-01 (KEV) and BOD 23-01 asset visibility reporting.
Technical Skills- Tenable Security Center / tenable.sc, Nessus Manager and Scanners, Nessus Agents, Tenable One; plugin/feed management; scan policy and credentialed-scan design.
- SCAP/STIG benchmarks, DISA STIG Viewer, CIS benchmarks.
- Linux (RHEL) and Windows Server administration; Python/PowerShell/Bash; Tenable REST API.
- Dashboards and reporting; ticketing (ServiceNow or equivalent); SIEM integration.
EducationBachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field, or an additional four (4) years of directly relevant experience in lieu of degree.
Remote/Hybrid/On-site and any other relevant work-environment requirementRemote. Duties are performed remotely; the selected candidate must reside within the National Capital Region (NCR). The Government does not furnish equipment; OneZero provides the laptop and collaboration tools. Position requires an OpenNet account, DoS PIV badge, multifactor authentication, and adherence to DoS SBU/CUI handling requirements. Local travel within the National Capital Region; minimal other travel.
Position Status:New Position, contingent upon Call Order award