Jobs · Information Technology · Virginia

Cyber Security Engineer (5462)

SMX · Quantico, VA · Yesterday
On-siteInformation Technology$103k/yrFull-time

About the role

The Cyber Security Engineer will provide security engineering, compliance, and risk management support for cloud-based systems aligned with NIST SP 800-53, FedRAMP, and DoD IL4–6 requirements. The role will advise partners and customers navigating government security requirements while supporting authorization, audit readiness, and continuous monitoring activities.

Responsibilities

  • Provide cybersecurity engineering and compliance support for FedRAMP and DoD-authorized cloud environments, including IL4–6.
  • Advise partners and customers on federal and DoD security requirements, authorization strategies, control implementation, and audit readiness.
  • Develop, review, and maintain authorization documentation, including SSPs, SAPs, SARs, POA&Ms, FedRAMP appendices, policies, and supporting evidence.
  • Support system authorization and reauthorization activities across FedRAMP/RMF, including gap assessments, control validation, evidence development, and remediation planning.
  • Leverage GRC platforms, APIs, scripts, and automation to streamline compliance workflows, evidence collection, documentation updates, control testing, and reporting.
  • Develop repeatable and auditable processes that reduce manual compliance effort and improve the accuracy and consistency of authorization artifacts.
  • Collaborate with cloud engineering and DevOps teams to design, implement, and validate security controls across AWS, Azure, and hybrid environments.
  • Review system changes and significant change requests to assess security impact, identify documentation updates, and maintain authorization boundaries.
  • Coincide with system owners, engineers, 3PAOs, Authorizing Officials, and government stakeholders to address findings and support authorization outcomes.
  • Support continuous monitoring, vulnerability management, POA&M updates, remediation tracking, and recurring compliance deliverables.
  • Evaluate security tooling and data sources to identify opportunities for automated control validation and compliance reporting.
  • Track evolving federal cybersecurity requirements and translate them into practical technical and operational actions.

Requirements

  • Strong analytical, documentation, and problem-solving skills with a focus on secure and compliant outcomes.
  • Excellent communication and stakeholder-management skills, including the ability to advise partners, customers, engineers, and government stakeholders.
  • Ability to translate federal security requirements into practical technical controls and operational processes.
  • U.S. citizenship with the ability to obtain and maintain a Secret or higher security clearance.
  • Bachelor’s degree in Information Security, Cybersecurity, Computer Science, or a related field, or equivalent practical experience.
  • Five or more years of cybersecurity experience, including at least three years supporting federal cloud security engineering, information assurance, RMF, or ISSO functions.
  • Knowledge of NIST SP 800-53 Rev. 5, FedRAMP Moderate and High, DoD IL4–6 overlays, RMF, and related federal compliance frameworks.
  • Experience developing and maintaining SSPs, POA&Ms, SARs, policies, control evidence, and other authorization artifacts.
  • Experience supporting authorization planning, gap assessments, audit readiness, control implementation, and remediation activities.
  • Hands-on experience with AWS, Azure, or hybrid cloud environments, including IAM, encryption, logging, configuration management, and security monitoring.
  • Experience using GRC platforms, APIs, scripting, or automation to improve compliance and security workflows.
  • Familiarity with tools such as eMASS, Paramify, Nessus/Tenable, Splunk, Prisma Cloud, or comparable solutions.

Qualifications

  • Experience supporting FedRAMP, DoD, DISA, or federal agency ATO activities.
  • CISSP, CGRC/CAP, CISM, Security+, or similar cybersecurity certification.
  • Experience developing automation with Python, PowerShell, REST APIs, infrastructure-as-code, or cloud-native services.
  • Experience integrating vulnerability, configuration, and cloud-security data into GRC (Paramify) and POA&M workflows.
  • Familiarity with DevSecOps pipelines, automated security testing, policy-as-code, and continuous control validation.
  • Knowledge of FISMA, the Privacy Act, and agency-specific security requirements.

Similar jobs

Engineer - Cyber Security

Las Vegas Sands Corp.Las Vegas, NV· 6 days ago
Information Technologyapply on sands.wd1.myworkdayjobs.com

Cyber Security Engineer

TekWissen ®Seattle, WA· 6 days ago
Information Technology$60–$65/hrapply on candidateportal.ceipal.com