Cybersecurity Engineer
Haystack · Washington, VA · 1 mo ago
RemoteRemoteInformation TechnologyFull-time
About the role
Build and secure multi-tenant cloud environments for critical missions. Implement and maintain security baselines (JSIG, NIST SP 800-53, STIG, MLS/MILS) across development, integration, and test cloud enclaves. Own Risk Management Framework (RMF) and Authority to Operate (ATO) packages for cloud environments, producing necessary documentation. Validate various security outputs including STIG, ACAS/Nessus, SAST/DAST, and container security prior to environment promotion. Perform functional validation of cyber artifacts and coordinate delivery of validated evidence. Support continuous monitoring, including audit logs, cloud telemetry, and security metrics.
Responsibilities
- Secure multi-classification cloud environments
- Perform STIG review/hardening and validate ACAS/Nessus outputs
- Maintain RMF/ATO artifacts such as SSP and POA&M
- Use Jira/Xacta workflows for RMF and vulnerability tracking
- Produce and validate security documentation and evidence
- Support continuous monitoring of audit logs, cloud telemetry, and security metrics
Requirements
- Proven experience securing multi-classification cloud environments
- Hands-on experience with STIG hardening and ACAS/Nessus validation
- Experience maintaining RMF/ATO artifacts (SSP, POA&M)
- Familiarity with Jira/Xacta workflows
- DoD 8140 aligned certifications: CISSP, CCSP, CASP+, or equivalent
- Strong documentation and communication skills
Benefits
- Opportunity to directly shape how the Air Force sees, decides, and acts across all domains
- Work on projects with tangible and immediate impact on warfighter effectiveness
- Competitive salary range
- Potential for hybrid remote work