Position OverviewThe Cybersecurity Engineer Senior designs and implements enterprise security architectures across mission-critical systems, aligning solutions to federal cybersecurity frameworks and modern DevSecOps practices. This role integrates security controls throughout the software development lifecycle, embedding automated testing, secure coding, and continuous monitoring into CI/CD pipelines. The engineer leads advanced risk assessments, threat modeling, and incident response while managing Zero Trust architectures and enterprise security platforms in a highly regulated government environment.
Key Responsibilities- Design and implement enterprise security architectures for complex systems, ensuring alignment with NIST SP 800-53 and Risk Management Framework (RMF) controls across on-premises and cloud environments.
- Integrate security into CI/CD pipelines by configuring automated SAST/DAST scans, container security controls, and infrastructure-as-code validation to support DevSecOps practices.
- Architect, implement, and manage Zero Trust security models, including identity, device, and network segmentation strategies to protect sensitive data and services.
- Configure, operate, and optimize SIEM platforms and log aggregation solutions to enable real-time threat detection, correlation, and security event monitoring.
- Implement and manage network security technologies such as firewalls, IDS/IPS, VPNs, and micro segmentation, ensuring secure connectivity across enterprise and remote environments.
- Lead threat modeling, vulnerability assessments, and penetration testing activities, translating findings into prioritized remediation plans and secure design recommendations.
- Direct incident response activities, including forensic analysis, containment, eradication, and recovery, and provide post-incident lessons learned and process improvements.
- Implement secure authentication, authorization, and encryption mechanisms across distributed systems, enforcing identity and access management and data protection policies.
- Develop security policies, procedures, and compliance documentation, and support audit preparation and governance activities in highly regulated environments.
- Collaborate with development, infrastructure, and operations teams to embed security best practices, promote secure coding, and maintain continuous security posture improvement.
Required Qualifications- Bachelor's degree in Computer Science, Information Assurance, Information Technology, Engineering, or a related field, or equivalent relevant experience.
- Typically 7-10 years of progressive cybersecurity engineering experience supporting complex enterprise or government systems, including hands-on work with application and infrastructure security.
- Demonstrated expertise implementing NIST SP 800-53 and RMF controls, including assessment, documentation, and continuous monitoring in federal or similarly regulated environments.
- Advanced experience integrating security into CI/CD pipelines, with practical use of automated SAST/DAST tools, container security, and infrastructure-as-code security controls.
- Strong experience designing and operating Zero Trust architectures, identity and access management, and network segmentation strategies.
- Hands-on proficiency with SIEM platforms, log aggregation, and network security tools (firewalls, IDS/IPS, VPNs), including configuring rules, alerts, and response playbooks.
- Experience leading incident response activities and conducting forensic analysis, vulnerability assessments, and penetration testing.
- Ability to obtain and maintain a SECRET security clearance as required, with U.S. citizenship.
Preferred Qualifications- Certified Information Systems Security Professional (CISSP) or equivalent advanced cybersecurity certification.
- Experience supporting highly regulated government or defense environments with formal audit and compliance requirements.
- Hands-on experience with cloud security in AWS or Azure, including native security services, identity and access management, and secure landing zone configurations.
- Background in leading or mentoring other cybersecurity engineers, analysts, or DevSecOps practitioners.
Compensation RangesCompensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.