Principal Cybersecurity Engineer
Constellation Software Engineering, LLC (CSEngineering) · Hill, NH · Yesterday
Information TechnologyFull-time
About the role
This role will support cybersecurity and information security initiatives within a federal government environment, contributing to mission-critical operations. The ideal candidate will bring extensive experience in information security, cybersecurity engineering, risk management, secure architecture, and the implementation of cybersecurity controls within complex environments.
Responsibilities
- Fulfill the Information Systems Security Engineering (ISSE) responsibilities defined in DoD Instructions 8500.01 and 8510.01, AFI 17-101 Risk Management Framework (RMF) for Air Force Information Technology (IT), and the DoD Program Manager's Guidebook for Integrating the Cybersecurity Risk Management Framework (RMF) into the System Acquisition Lifecycle.
- Coordinate closely with Information Systems Security Managers (ISSMs) to ensure compliance with DoD Instructions 8500.01 and 8510.01, AFI 17-101 Risk Management Framework (RMF) for Air Force Information Technology (IT), and the DoD Program Manager's Guidebook for Integrating the Cybersecurity Risk Management Framework (RMF) into the System Acquisition Lifecycle.
- Support efforts to integrate cybersecurity throughout the lifecycle of IT systems, including the development and review of cybersecurity-related artifacts such as System Security Plans, Cybersecurity Strategies, Cybersecurity Impact Assessments, policies, plans, and procedures.
- Continually assess activities and controls to secure information.
- Assess gaps in security and identify solutions to mitigate risk, including business processes, technical controls, and policy improvements.
- Assist in the development of security policies, plans, and procedures to meet government regulations and industry best practices.
- Develop security impact analyses.
- Review technical assessments.
- Use automated tools to analyze system security control compliance.
- Collaborate with technical managers to ensure required controls are implemented and security processes are followed.
- Build collaborative internal relationships with program and project teams, as well as external relationships with customers, regulatory bodies, other agencies, and business partners.
- Perform other duties as assigned.
Required Qualifications
- Security Clearance: Secret
- Certification Requirement: The applicant must meet DoD 8570.01-M IAT Level II, IAM Level I, or higher certification requirements on the date of hire.
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related Engineering field and a minimum of eight (8) years of experience; or Master's degree (MS or MBA) and six (6) years of relevant experience.
- Certification such as CISSP, CISSP-ISSEP, CASP+ CE (CompTIA SecurityX), or CSSLP.
- Professional experience in information security, with a proven track record of leading large-scale projects.
- Experience designing and implementing secure network architectures, Zero Trust environments, and cloud security frameworks (AWS, Azure, or GCP).
- Deep experience operating within regulatory frameworks such as NIST 800-53, NIST 800-171, ISO 27001, CMMC, or SOC 2.
- Experience leading high-severity security incident responses and conducting post-mortem root cause analyses.
- Proficiency in threat modeling frameworks such as STRIDE or PASTA to identify vulnerabilities.
- Expert-level knowledge of security tooling, including SIEM (Splunk, Sentinel), EDR/XDR, firewalls, and vulnerability scanners (Nessus, Qualys).
- Expertise in Identity and Access Management (IAM), including OAuth, SAML, and multi-factor authentication (MFA) implementation.
- Ability to integrate security into CI/CD pipelines using SAST (Static Analysis) and DAST (Dynamic Analysis) tools.
- Ability to translate business requirements into a technical security roadmap.
- Ability to communicate complex technical risks to non-technical executives to secure budget and buy-in.
Preferred Qualifications
- Experience transitioning security postures across different environments, such as moving a legacy on-premises system to a hybrid-cloud or fully cloud-native environment.
- In the defense and aerospace environment, experience with Cross-Domain Solutions (CDS), air-gapped networks, and highly classified environments.
- Proven experience as a Lead or Architect responsible for the security roadmap of an entire product line or business unit.
- History of contributing to the security community through white papers, conference presentations, or open-source security projects.
- Proficiency in Python, Go, or PowerShell to automate security responses (SOAR) and infrastructure as code using Terraform or Ansible.
- Deep understanding of Public Key Infrastructure (PKI), quantum-resistant encryption, and Hardware Security Modules (HSMs).
- Ability to perform Red Teaming and adversarial simulations to test organizational resilience against advanced persistent threats (APTs).
- Ability to apply machine learning (ML) and artificial intelligence (AI) to anomaly detection and threat hunting.
Location
Hill Air Force Base, UT (Onsite)
Travel
Less than 10%