Jobs · Information Technology · Pennsylvania

Cybersecurity Engineer

ThinkTek · Mechanicsburg, PA · 1 wk ago
Information Technology$150k–$185k/yrFull-time

About the role

ThinkTek LLC is a fast-growing Certified SBA 8(a) and Service-Disabled Veteran-Owned Small Business (SDVOSB) company specializing in management and technology consulting services that support the business and technology modernization efforts of the Federal Government. We provide tailored solutions around Program & Project Management, Strategic Planning, and IT Operations.

We are seeking an experienced Cybersecurity Engineer to support a Federal Government customer by providing advanced cybersecurity engineering, assessment, and compliance support. This position serves as a senior cybersecurity practitioner responsible for implementing and assessing security controls, maintaining system authorization packages, conducting security assessments, and supporting risk-based authorization decisions across a portfolio of mission-critical systems. The Cybersecurity Engineer will work across traditional, cloud-native, and SaaS environments, supporting the Risk Management Framework (RMF), Cybersecurity Risk Management Construct (CSRMC), Continuous Authorization to Operate (cATO), and Zero Trust initiatives.

Responsibilities

  • Serve as the lead cybersecurity engineer and Information System Security Officer (ISSO) supporting a portfolio of DSCA mission systems across on-premises, cloud, and SaaS environments.
  • Lead RMF and Cybersecurity Risk Management Construct (CSRMC) activities, including system authorization, continuous monitoring, and maintenance of ATO/cATO packages.
  • Manage and maintain eMASS records, authorization artifacts, control implementation evidence, and Plans of Action & Milestones (POA&Ms).
  • Assess and validate NIST 800-53, DoD RMF, DISA STIG, FedRAMP, and DoD Cloud Computing Security Requirements Guide (CC SRG) security controls.
  • Conduct security control assessments and independent validations to evaluate control effectiveness and support risk-informed authorization decisions.
  • Develop Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), and authorization recommendation memorandums.
  • Analyze vulnerabilities, security findings, automated scan results, and threat data to assess mission impact and prioritize remediation activities.
  • Review and validate Compliance-as-Code (CaC), Policy-as-Code (PaC), and automated security assessment outputs to ensure accuracy and compliance.
  • Collaborate with system owners, developers, engineers, and program stakeholders to implement security controls, address findings, and reduce enterprise risk.
  • Support DevSecOps and cloud security initiatives by integrating security throughout the system development lifecycle and continuous delivery processes.
  • Monitor security posture across AWS cloud, traditional infrastructure, and SaaS platforms, ensuring compliance with federal and DoD cybersecurity requirements.
  • Brief government leadership and Authorizing Officials on system risk posture, assessment results, remediation strategies, and authorization recommendations.

Required Qualifications

  • Active Secret Security Clearance.
  • Bachelor's degree in Information Technology, Computer Science, Engineering or a related technical field from an accredited college or university.
  • Minimum 5 years of dedicated Information Assurance, Cybersecurity, or Information Security experience.
  • At least 3 consecutive years of recent experience supporting DoD cybersecurity programs.
  • Experience with Risk Management Framework (RMF) authorization processes.
  • Experience administering and maintaining eMASS authorization packages.
  • Experience conducting security control assessments, validations, and risk assessments.
  • Experience supporting ATO, cATO, and continuous monitoring programs.
  • Experience analyzing vulnerabilities, security findings, and organizational risk posture.
  • Experience supporting cloud security initiatives in AWS, Azure, or other FedRAMP-authorized environments.
  • Strong understanding of NIST 800-53 security controls and DISA STIG requirements.

Required Certifications

Candidates must possess one DoD 8570/8140 IAM Level II or IAT Level II baseline requirement, such as:

  • CISSP
  • Security+ CE
  • CISM
  • CASP+ CE

Pay Range

The anticipated annual salary range for this position is $150,030 – $185,020. This range is a good-faith estimate and not a guarantee of compensation. Final compensation will be based on factors including experience, education, skills, geographic location, internal equity, market data, and applicable contract requirements, and may fall outside the posted range.

Similar jobs

Cybersecurity Engineer

VisaAustin, TX· 3 days ago
Information Technology$124k–$191k/yrapply on visa.wd5.myworkdayjobs.com

Cybersecurity Engineer

Applied Network Solutions, Inc.San Antonio, TX· 2 wk ago
Information Technology$150k–$200k/yrapply on recruiting.paylocity.com

Cybersecurity Engineer

MITREChase City, VA· 1 mo ago
Information Technology$129k–$162k/yrapply on careers.mitre.org

Cybersecurity Engineer

Booz Allen HamiltonAnnapolis Junction, MD· 1 mo ago
$62k–$141k/yrapply on careers.boozallen.com

Cybersecurity Engineer

Life Cycle EngineeringCharleston, SC· 2 mo ago
Information Technologyapply on www2.jobdiva.com