Jobs · Virginia

Cybersecurity Engineer

Electrosoft · Fort Belvoir, VA · 1 mo ago
HybridFull-time

Cybersecurity Engineer Position Summary

The Cybersecurity Engineer serves as the technical lead for enterprise web application and infrastructure vulnerability management. The engineer is responsible for planning, executing, and supporting vulnerability assessments, validating findings, prioritizing remediation activities, and implementing security controls to reduce organizational cyber risk. This position collaborates with system owners, developers, network engineers, and cybersecurity teams to ensure compliance with DoD cybersecurity requirements.

Primary Responsibilities

  • Conduct authenticated and unauthenticated vulnerability scans of web applications, APIs, servers, databases, operating systems, and network devices.

  • Perform web application security assessments using automated and manual testing techniques.

  • Validate vulnerabilities to eliminate false positives.

  • Analyze Common Vulnerabilities and Exposures (CVEs), Common Weakness Enumerations (CWEs), and associated security risks.

  • Prioritize vulnerabilities using CVSS, exploitability, mission impact, and threat intelligence.

  • Develop remediation recommendations and mitigation strategies.

  • Support patch management activities and verify remediation effectiveness.

  • Perform secure configuration reviews against DISA STIGs and other security baselines.

  • Produce technical reports, executive dashboards, and risk summaries.

  • Support continuous monitoring (RMF Step 6).

  • Coordinate with ISSOs, ISSMs, developers, and infrastructure teams.

  • Support Authority to Operate (ATO) activities and POA&M management.

  • Assist during security audits and inspections.

  • Maintain vulnerability management metrics and KPIs.

  • Support incident response investigations involving vulnerable systems.

  • Develop scripts or automation to improve vulnerability management processes.

Basic Qualifications

  • Ten (10) years of relevant IT experience
  • Five (5) Years of relevant OT experience
  • Investigative Requirement: At time of proposal the contractor must possess a Moderate Risk, Confidential, Non-Critical Sensitive, Tier 3/NACLC/ANACI investigation.
  • Relevant certification meeting DOD 8570/8140 IAT level III, and IASAE level III. (Must have IASAE III Certification within 6 months of coming on the contract. Must meet all other requirements.)
  • Computing Environment (CE): Microsoft Certified Solutions Associate or Expert, Cisco Certified Network Administrator, Microsoft Azure Security Technologies, Amazon Certified Security.

Similar jobs

Cybersecurity Engineer

Los Angeles TimesEl Segundo, CA· 4 wk ago
Information Technology$125k–$140k/yrapply on jobs.dayforcehcm.com

Cybersecurity Engineer

MITREOklahoma City, OK· 4 wk ago
Information Technology$129k–$162k/yrapply on careers.mitre.org

Cybersecurity Engineer

AMERICAN SYSTEMSMiddletown, RI· 4 wk ago
$59k/yrapply on careers-americansystems.icims.com

Cybersecurity Engineer

10a LabsWashington, DC· 1 mo ago
RemoteInformation Technology$135k–$160k/yrapply on grnh.se

Cybersecurity Engineer

KDDI America, Inc.New York, NY· 1 mo ago
Information Technology$70k–$100k/yrapply on app.jazz.co