Design, implement, and harden security controls across cloud, on-premises, and hybrid environments
Partner with engineering, data, and operations teams to bake security into the build
Lead vulnerability management, conduct security architecture reviews, configure and tune security tooling (SIEM, EDR, IDS/IPS, vulnerability scanners), and respond to incidents end-to-end
Produce and maintain artifacts required for Authorization to Operate (ATO) under the DoD Risk Management Framework (RMF)
Translate NIST 800-53, DISA STIGs, and CNSSI guidance into practical engineering decisions
Work directly with the ISSO and ISSM to keep the system’s security posture defensible and auditable
Proactively solve unusual and/or complex problems with little, or no direction given
Thrive in a fast-paced technical environment that prioritizes mission impact and speed
Requirements
Active Secret clearance required with the ability to obtain and maintain a Top-Secret clearance
Minimum of 5 years of hands-on cybersecurity engineering experience in DoD, IC, or other federal environments
Demonstrated experience implementing and maintaining controls under the NIST Risk Management Framework (RMF) and NIST SP 800-53
Hands-on experience with SIEM platforms (Splunk, Sentinel, or Elastic), EDR tooling, and vulnerability management platforms (Tenable, Rapid7, or equivalent)
Experience applying DISA STIGs, SCAP scanning, and remediating findings on Windows, Linux, and network devices
DoD 8570/8140 IAT Level II certification (Security+ CE, CCNA-Security, GSEC, or equivalent) at time of hire
Proficiency scripting in PowerShell, Python, or Bash to automate security tasks