Cyber Security Engineer (5462)
SMX · Quantico, VA · Yesterday
On-siteInformation Technology$103k/yrFull-time
About the role
The Cyber Security Engineer will provide security engineering, compliance, and risk management support for cloud-based systems aligned with NIST SP 800-53, FedRAMP, and DoD IL4–6 requirements. The role will advise partners and customers navigating government security requirements while supporting authorization, audit readiness, and continuous monitoring activities.
Responsibilities
- Provide cybersecurity engineering and compliance support for FedRAMP and DoD-authorized cloud environments, including IL4–6.
- Advise partners and customers on federal and DoD security requirements, authorization strategies, control implementation, and audit readiness.
- Develop, review, and maintain authorization documentation, including SSPs, SAPs, SARs, POA&Ms, FedRAMP appendices, policies, and supporting evidence.
- Support system authorization and reauthorization activities across FedRAMP/RMF, including gap assessments, control validation, evidence development, and remediation planning.
- Leverage GRC platforms, APIs, scripts, and automation to streamline compliance workflows, evidence collection, documentation updates, control testing, and reporting.
- Develop repeatable and auditable processes that reduce manual compliance effort and improve the accuracy and consistency of authorization artifacts.
- Collaborate with cloud engineering and DevOps teams to design, implement, and validate security controls across AWS, Azure, and hybrid environments.
- Review system changes and significant change requests to assess security impact, identify documentation updates, and maintain authorization boundaries.
- Coincide with system owners, engineers, 3PAOs, Authorizing Officials, and government stakeholders to address findings and support authorization outcomes.
- Support continuous monitoring, vulnerability management, POA&M updates, remediation tracking, and recurring compliance deliverables.
- Evaluate security tooling and data sources to identify opportunities for automated control validation and compliance reporting.
- Track evolving federal cybersecurity requirements and translate them into practical technical and operational actions.
Requirements
- Strong analytical, documentation, and problem-solving skills with a focus on secure and compliant outcomes.
- Excellent communication and stakeholder-management skills, including the ability to advise partners, customers, engineers, and government stakeholders.
- Ability to translate federal security requirements into practical technical controls and operational processes.
- U.S. citizenship with the ability to obtain and maintain a Secret or higher security clearance.
- Bachelor’s degree in Information Security, Cybersecurity, Computer Science, or a related field, or equivalent practical experience.
- Five or more years of cybersecurity experience, including at least three years supporting federal cloud security engineering, information assurance, RMF, or ISSO functions.
- Knowledge of NIST SP 800-53 Rev. 5, FedRAMP Moderate and High, DoD IL4–6 overlays, RMF, and related federal compliance frameworks.
- Experience developing and maintaining SSPs, POA&Ms, SARs, policies, control evidence, and other authorization artifacts.
- Experience supporting authorization planning, gap assessments, audit readiness, control implementation, and remediation activities.
- Hands-on experience with AWS, Azure, or hybrid cloud environments, including IAM, encryption, logging, configuration management, and security monitoring.
- Experience using GRC platforms, APIs, scripting, or automation to improve compliance and security workflows.
- Familiarity with tools such as eMASS, Paramify, Nessus/Tenable, Splunk, Prisma Cloud, or comparable solutions.
Qualifications
- Experience supporting FedRAMP, DoD, DISA, or federal agency ATO activities.
- CISSP, CGRC/CAP, CISM, Security+, or similar cybersecurity certification.
- Experience developing automation with Python, PowerShell, REST APIs, infrastructure-as-code, or cloud-native services.
- Experience integrating vulnerability, configuration, and cloud-security data into GRC (Paramify) and POA&M workflows.
- Familiarity with DevSecOps pipelines, automated security testing, policy-as-code, and continuous control validation.
- Knowledge of FISMA, the Privacy Act, and agency-specific security requirements.