Cybersecurity Engineer Senior

ASM Research$100K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Information Assurance, IT, Engineering, or equivalent experience.
  • 7-10 years of progressive cybersecurity engineering experience with complex enterprise or government systems.
  • Expertise in implementing NIST SP 800-53 and RMF controls in regulated environments.
  • Experience integrating security into CI/CD pipelines with automated SAST/DAST tools.
  • Strong background in designing Zero Trust architectures and identity management.
  • Hands-on experience with SIEM platforms and network security tools.
  • Ability to obtain and maintain a SECRET security clearance.

Responsibilities

  • Design and implement enterprise security architectures for complex systems aligned with NIST SP 800-53.
  • Integrate security into CI/CD pipelines with automated security scanning and validation practices.
  • Architect and manage Zero Trust security models, including identity and device segmentation.
  • Optimize SIEM and log aggregation tools for real-time threat detection.
  • Implement network security technologies such as firewalls and micro-segmentation.
  • Lead threat modeling and vulnerability assessments, providing remediation plans.
  • Oversee incident response activities, including forensic analysis and recovery efforts.

Benefits

  • Opportunities for professional development and continued learning.
  • Collaborative work environment with cross-functional teams.
  • Possibility of contributing to cutting-edge security projects.
  • Experience in a highly regulated government environment.
Full Job Description
Position Overview

The Cybersecurity Engineer Senior designs and implements enterprise security architectures across mission-critical systems, aligning solutions to federal cybersecurity frameworks and modern DevSecOps practices. This role integrates security controls throughout the software development lifecycle, embedding automated testing, secure coding, and continuous monitoring into CI/CD pipelines. The engineer leads advanced risk assessments, threat modeling, and incident response while managing Zero Trust architectures and enterprise security platforms in a highly regulated government environment.

Key Responsibilities
  • Design and implement enterprise security architectures for complex systems, ensuring alignment with NIST SP 800-53 and Risk Management Framework (RMF) controls across on-premises and cloud environments.
  • Integrate security into CI/CD pipelines by configuring automated SAST/DAST scans, container security controls, and infrastructure-as-code validation to support DevSecOps practices.
  • Architect, implement, and manage Zero Trust security models, including identity, device, and network segmentation strategies to protect sensitive data and services.
  • Configure, operate, and optimize SIEM platforms and log aggregation solutions to enable real-time threat detection, correlation, and security event monitoring.
  • Implement and manage network security technologies such as firewalls, IDS/IPS, VPNs, and micro segmentation, ensuring secure connectivity across enterprise and remote environments.
  • Lead threat modeling, vulnerability assessments, and penetration testing activities, translating findings into prioritized remediation plans and secure design recommendations.
  • Direct incident response activities, including forensic analysis, containment, eradication, and recovery, and provide post-incident lessons learned and process improvements.
  • Implement secure authentication, authorization, and encryption mechanisms across distributed systems, enforcing identity and access management and data protection policies.
  • Develop security policies, procedures, and compliance documentation, and support audit preparation and governance activities in highly regulated environments.
  • Collaborate with development, infrastructure, and operations teams to embed security best practices, promote secure coding, and maintain continuous security posture improvement.

Required Qualifications
  • Bachelor's degree in Computer Science, Information Assurance, Information Technology, Engineering, or a related field, or equivalent relevant experience.
  • Typically 7-10 years of progressive cybersecurity engineering experience supporting complex enterprise or government systems, including hands-on work with application and infrastructure security.
  • Demonstrated expertise implementing NIST SP 800-53 and RMF controls, including assessment, documentation, and continuous monitoring in federal or similarly regulated environments.
  • Advanced experience integrating security into CI/CD pipelines, with practical use of automated SAST/DAST tools, container security, and infrastructure-as-code security controls.
  • Strong experience designing and operating Zero Trust architectures, identity and access management, and network segmentation strategies.
  • Hands-on proficiency with SIEM platforms, log aggregation, and network security tools (firewalls, IDS/IPS, VPNs), including configuring rules, alerts, and response playbooks.
  • Experience leading incident response activities and conducting forensic analysis, vulnerability assessments, and penetration testing.
  • Ability to obtain and maintain a SECRET security clearance as required, with U.S. citizenship.

Preferred Qualifications
  • Certified Information Systems Security Professional (CISSP) or equivalent advanced cybersecurity certification.
  • Experience supporting highly regulated government or defense environments with formal audit and compliance requirements.
  • Hands-on experience with cloud security in AWS or Azure, including native security services, identity and access management, and secure landing zone configurations.
  • Background in leading or mentoring other cybersecurity engineers, analysts, or DevSecOps practitioners.


Compensation Ranges

Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.

Similar Jobs

More Jobs at ASM Research

More Information Technology Jobs

Find similar Cybersecurity Engineer Senior jobs: