Mid-Level Cybersecurity Engineer

Drawbridge

• $150K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Active TS/SCI with CI Polygraph required at time of hire
  • 4-7 years in IT or cybersecurity
  • 2+ years of hands-on Carbon Black administration experience
  • Experience with DLP and device control policy enforcement
  • Knowledge of Windows/Linux endpoints and Active Directory
  • Familiar with NIST 800-53 and DoD/IC security requirements
  • IAT Level II certification or ability to obtain in 6 months
  • Bachelor's degree in a related field or equivalent experience

Responsibilities

  • Administer and tune Carbon Black across enterprise endpoints
  • Build and enforce DLP policies to protect sensitive data
  • Create and maintain application allow-listing and device control rules
  • Monitor and investigate endpoint alerts and data exfiltration events
  • Collaborate with SOC and Incident Response teams for investigations
  • Handle Carbon Black upgrades and platform health monitoring
  • Support RMF/ATO activities and security control documentation
  • Produce reports on endpoint posture and policy violations

Benefits

  • Comprehensive medical, dental, and vision insurance
  • 401(k) plan
  • Paid time off and federal holidays
  • Training and certification reimbursement
  • Long-term stability in supporting national security mission
Full Job Description
Mid-Level Cybersecurity Engineer - Carbon Black / DLP
Active TS/SCI with CI Polygraph Required

Location: Gaithersburg, MD or Tysons Corner, VA (Hybrid)
Clearance: Active TS/SCI with Counterintelligence (CI) Polygraph
Employment Type: Full-time, Direct Hire
Compensation: $150,000 + benefits

Drawbridge Recruiting is partnering with a leading national security contractor to hire a Mid-Level Cybersecurity Engineer for a mission-critical government program. You'll own the Carbon Black endpoint security platform and the data loss prevention (DLP) controls that keep sensitive and classified information where it belongs.

This is a hands-on engineering role. You'll deploy, configure and tune the tools, write the policies, investigate what gets flagged, and work alongside the SOC, Insider Threat and Incident Response teams. You'll split your time between a hybrid schedule and a secure facility in Gaithersburg or Tysons Corner.

What You'll Do
  • Administer, configure and tune Carbon Black (EDR, App Control and Device Control) across enterprise Windows and Linux endpoints
  • Build and enforce DLP policies that stop unauthorized transfer of sensitive or classified data through removable media, applications and network channels
  • Create and maintain application allow-listing and device control rules that protect the environment without slowing the mission
  • Monitor, triage and investigate endpoint alerts and data exfiltration events, and escalate incidents when needed
  • Partner with SOC, Insider Threat and Incident Response teams on investigations and remediation
  • Handle Carbon Black upgrades, patching, sensor deployment and platform health monitoring
  • Support RMF/ATO activities, including security control documentation, POA&Ms and audit evidence
  • Produce reports and metrics on endpoint posture, policy violations and data protection trends
  • Maintain SOPs, configuration baselines and technical documentation

What You'll Bring
  • Active TS/SCI with CI Polygraph (must be current at time of hire)
  • 4-7 years of IT or cybersecurity experience
  • At least 2 years of hands-on Carbon Black administration (EDR/Response, App Control/Protection/Bit9, or Device Control)
  • Experience designing and enforcing DLP and device control policies in an enterprise environment
  • Working knowledge of Windows and Linux endpoints, Active Directory and Group Policy
  • Familiarity with NIST 800-53, RMF and DoD/IC security requirements
  • DoD 8140/8570 IAT Level II certification (such as Security+ CE), or the ability to obtain it within 6 months of hire
  • Bachelor's degree in IT, Cybersecurity or a related field, or equivalent experience

Nice to Have
  • Experience with other DLP platforms such as Forcepoint, Symantec/Broadcom DLP, Microsoft Purview or Trellix
  • SIEM experience (Splunk, Elastic or ArcSight), including building correlation searches for endpoint and DLP events
  • PowerShell or Python scripting for automation
  • Certifications such as CySA+, CASP+, GCIH or CISSP
  • Experience supporting Intelligence Community or insider threat programs

Work Schedule

Hybrid, with on-site days set by program needs. Classified work must be done on-site in a SCIF.

Why This Role
  • Competitive salary and comprehensive benefits (medical, dental, vision, 401(k))
  • Paid time off and federal holidays
  • Training and certification reimbursement
  • Long-term program stability supporting the national security mission

Interested? If you've run Carbon Black in a cleared environment and want to own endpoint and data protection on a program that matters, apply today.

Similar Jobs

More Jobs at Drawbridge

More Information Technology Jobs

Find similar Mid-Level Cybersecurity Engineer jobs: