Geospatial Cyber Security Engineer – Multiple Positions at Junior/Mid/Senior Levels
NV5 Geospatial (NV5G) is recruiting qualified and cleared Geospatial Cyber Security Engineers at Junior, Mid, and Senior levels to support national security client sites in the Northern Virginia and St. Louis, MO areas. Candidates will support critical DoW and Intel missions and programs, focusing on cybersecurity engineering, risk management, and compliance across cloud and on-prem systems, including system authorization, vulnerability management, and secure operations in classified environments.
Work Environment
- Location: Northern Virginia Area (Springfield, VA and/or Vienna, VA)
- Travel up to 15% of the time
NV5 is a collaboration of intelligent, innovative thinkers who care for each other, our communities, and the environment. The company values both heart and head, the diversity of its people, and their experiences. NV5 is a global technology solutions and consulting services company with a workforce of over 4,500 professionals in more than 100 offices worldwide. Its continued growth has been spurred through strategic investments in firms with unique capabilities to help current and future customers solve the world's toughest problems. The NV5 family brings together talent across a wide range of markets and fields, including Professional Engineers, Professional Land Surveyors, Architects, Photogrammetrists, GIS Professionals, Software Developers, IT, Project Management Professionals, and more.
Responsibilities
- Applying RMF processes to support system Assessment & Authorization (A&A), including control selection, implementation, assessment, and continuous monitoring
- Developing, reviewing, and maintaining security documentation such as SSPs, POA&Ms, SARs, and ATO artifacts in tools such as XACTA or eMASS
- Conducting vulnerability assessments and compliance scans (e.g., ACAS) and tracking remediation of findings and IAVM requirements
- Implementing and validating security controls aligned with NIST 800-53, CNSSI 1253, and related DOD guidance
- Supporting system hardening, patching, and configuration management in compliance with STIGs for Linux, Windows, and network devices
- Monitoring systems for security events and supporting incident response and risk mitigation activities
- Assessing security impacts of system changes and supporting configuration control boards (CCBs)
- Collaborating with systems engineers, administrators, and DevSecOps teams to integrate security throughout the system lifecycle
- Providing cybersecurity risk input to program leadership, Authorizing Officials (AOs), and stakeholders
Required Qualifications
- US citizenship with Active or Current (within two years of active) Top Secret Security Clearance with SCI eligibility
- Bachelor's degree in Computer Science, Engineering, DevOps, or related technical field
- 5+ years of relevant experience
- DoD 8570 IAT Level II or higher certification (e.g., Security+, CySA+, CISSP)
- Experience with RMF, A&A, POA&M, and ATO documentation (XACTA/eMASS)
- Hands-on vulnerability scanning and compliance tracking (ACAS, IAVM)
- Experience securing Linux and Windows systems, STIGs, patching, and system hardening
- Knowledge of NIST 800-series publications and incident response processes
- Strong analytical, communication, and collaborative skills
Preferred Qualifications
- Scripting or development experience (Python, Java, React)
- DevSecOps tools and pipeline experience
- Experience with Linux (RedHat/CentOS), database, web apps, or big data platforms
- Familiarity with Agile environments and tools (Jira, Confluence)
- Experience with NIST SP 800-171 and Systems Security Engineering (SSE)
Clearance Requirement
Active/Current Top Secret Clearance with SCI Eligibility.
Benefits
NV5 offers a competitive compensation and benefits package including medical, dental, life insurance, FTO, 401(k), and professional development/advancement opportunities.
Employment is contingent upon successful completion of a background check and drug screening.