Jobs · Information Technology · New Hampshire

Principal Cybersecurity Engineer

Information TechnologyFull-time

About the role

This role will support cybersecurity and information security initiatives within a federal government environment, contributing to mission-critical operations. The ideal candidate will bring extensive experience in information security, cybersecurity engineering, risk management, secure architecture, and the implementation of cybersecurity controls within complex environments.

Responsibilities

  • Fulfill the Information Systems Security Engineering (ISSE) responsibilities defined in DoD Instructions 8500.01 and 8510.01, AFI 17-101 Risk Management Framework (RMF) for Air Force Information Technology (IT), and the DoD Program Manager's Guidebook for Integrating the Cybersecurity Risk Management Framework (RMF) into the System Acquisition Lifecycle.
  • Coordinate closely with Information Systems Security Managers (ISSMs) to ensure compliance with DoD Instructions 8500.01 and 8510.01, AFI 17-101 Risk Management Framework (RMF) for Air Force Information Technology (IT), and the DoD Program Manager's Guidebook for Integrating the Cybersecurity Risk Management Framework (RMF) into the System Acquisition Lifecycle.
  • Support efforts to integrate cybersecurity throughout the lifecycle of IT systems, including the development and review of cybersecurity-related artifacts such as System Security Plans, Cybersecurity Strategies, Cybersecurity Impact Assessments, policies, plans, and procedures.
  • Continually assess activities and controls to secure information.
  • Assess gaps in security and identify solutions to mitigate risk, including business processes, technical controls, and policy improvements.
  • Assist in the development of security policies, plans, and procedures to meet government regulations and industry best practices.
  • Develop security impact analyses.
  • Review technical assessments.
  • Use automated tools to analyze system security control compliance.
  • Collaborate with technical managers to ensure required controls are implemented and security processes are followed.
  • Build collaborative internal relationships with program and project teams, as well as external relationships with customers, regulatory bodies, other agencies, and business partners.
  • Perform other duties as assigned.

Required Qualifications

  • Security Clearance: Secret
  • Certification Requirement: The applicant must meet DoD 8570.01-M IAT Level II, IAM Level I, or higher certification requirements on the date of hire.
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related Engineering field and a minimum of eight (8) years of experience; or Master's degree (MS or MBA) and six (6) years of relevant experience.
  • Certification such as CISSP, CISSP-ISSEP, CASP+ CE (CompTIA SecurityX), or CSSLP.
  • Professional experience in information security, with a proven track record of leading large-scale projects.
  • Experience designing and implementing secure network architectures, Zero Trust environments, and cloud security frameworks (AWS, Azure, or GCP).
  • Deep experience operating within regulatory frameworks such as NIST 800-53, NIST 800-171, ISO 27001, CMMC, or SOC 2.
  • Experience leading high-severity security incident responses and conducting post-mortem root cause analyses.
  • Proficiency in threat modeling frameworks such as STRIDE or PASTA to identify vulnerabilities.
  • Expert-level knowledge of security tooling, including SIEM (Splunk, Sentinel), EDR/XDR, firewalls, and vulnerability scanners (Nessus, Qualys).
  • Expertise in Identity and Access Management (IAM), including OAuth, SAML, and multi-factor authentication (MFA) implementation.
  • Ability to integrate security into CI/CD pipelines using SAST (Static Analysis) and DAST (Dynamic Analysis) tools.
  • Ability to translate business requirements into a technical security roadmap.
  • Ability to communicate complex technical risks to non-technical executives to secure budget and buy-in.

Preferred Qualifications

  • Experience transitioning security postures across different environments, such as moving a legacy on-premises system to a hybrid-cloud or fully cloud-native environment.
  • In the defense and aerospace environment, experience with Cross-Domain Solutions (CDS), air-gapped networks, and highly classified environments.
  • Proven experience as a Lead or Architect responsible for the security roadmap of an entire product line or business unit.
  • History of contributing to the security community through white papers, conference presentations, or open-source security projects.
  • Proficiency in Python, Go, or PowerShell to automate security responses (SOAR) and infrastructure as code using Terraform or Ansible.
  • Deep understanding of Public Key Infrastructure (PKI), quantum-resistant encryption, and Hardware Security Modules (HSMs).
  • Ability to perform Red Teaming and adversarial simulations to test organizational resilience against advanced persistent threats (APTs).
  • Ability to apply machine learning (ML) and artificial intelligence (AI) to anomaly detection and threat hunting.

Location

Hill Air Force Base, UT (Onsite)

Travel

Less than 10%

Similar jobs