Position: Cyber Security Engineer
Location: Fairfax, VA
Clearance: TS/SCI
Salary Range: $135,000 - $155,000
The Cyber Security Engineer serves as a key contributor to the organization's cybersecurity program, supporting the implementation of security controls, Risk Management Framework (RMF) activities, continuous monitoring, and Assessment and Authorization (A&A) efforts. This hands-on position requires a strong understanding of information assurance principles, cybersecurity best practices, and federal and DoD regulatory requirements to ensure the confidentiality, integrity, and availability of mission-critical information systems. The position is located at the company's headquarters in Fairfax, Virginia.
Duties and Responsibilities:
- Support Assessment and Authorization (A&A) activities, including RMF package development, security control implementation, assessment, validation, continuous monitoring, vulnerability management, POA&M tracking, and Authority to Operate (ATO) processes using eMASS and/or Xacta.
- Verify that system changes, upgrades, and modifications that may impact the security posture or authorization status of information systems are identified, documented, and communicated to appropriate stakeholders.
- Serve as the primary liaison between system owners, Information System Security Managers (ISSMs), Information System Security Officers (ISSOs), engineers, assessors, and other cybersecurity stakeholders.
- Ensure the day-to-day implementation, oversight, continuous monitoring, and security compliance of multiple information systems.
- Lead and facilitate meetings with technical and functional subject matter experts to identify, document, validate, and track cybersecurity and compliance requirements.
- Conduct vulnerability assessments and security scans using tools such as Nessus, SCAP Compliance Checker, and other approved scanning solutions.
- Ensure appropriate protective and corrective actions are implemented and tracked when security incidents, vulnerabilities, or compliance deficiencies are identified.
- Perform risk assessments and assist with the identification, analysis, and mitigation of cybersecurity risks.
- Support the installation, configuration, and maintenance of hardware and software within secure computing environments.
- Apply security patches, updates, and configuration changes to maintain system compliance and reduce cybersecurity risk.
- Conduct cybersecurity investigations and develop reports, findings, recommendations, and corrective action plans as required.
- Research emerging technologies, cybersecurity threats, vulnerabilities, and industry best practices to support continuous improvement of security programs.
- Stay current with applicable federal and DoD cybersecurity policies, standards, regulations, and framework updates.
- Support audit activities, compliance reviews, and security inspections to ensure adherence to organizational and regulatory requirements.
- Assist with continuous monitoring activities, including vulnerability remediation, incident tracking, configuration management, and ongoing authorization support.
- Develop and maintain Security Control Traceability Matrices (SCTMs) to map security requirements to DoD and NIST security controls.
Minimum Qualifications:
- Active TS clearance
- Bachelor's degree in computer science, Information Systems, Cybersecurity, Information Technology
- Minimum of Five (5) years of Cyber Security experience
- Minimum of three (3) years of experience applying the NIST Risk Management Framework (RMF) in accordance with NIST SP 800-37 Revision 2
- Working knowledge of federal and DoD cybersecurity standards and guidance, including NIST SP 800-60, NIST SP 800-53 Revision 5, CNSSI 1253 Revision 5, DoDI 8510.01 (RMF), and related authorization/accreditation processes.
- Experience supporting, administering, and maintaining SIPRNet-connected systems and environments.
- Strong knowledge and hands-on administration of Microsoft Windows server and workstation operating environments.
- Experience managing RMF packages and authorization activities using eMASS and/or Xacta workflow tools.
- Practical experience implementing and supporting cybersecurity technologies and controls, including encryption, data protection, identity and access management, privileged access management, vulnerability management, and continuous monitoring.
- Possession of a current CompTIA Security+ certification or equivalent DoD 8570/8140-approved baseline certification.