Cybersecurity Engineer
Core
Issuing and maintaining security authorizations for systems within the Risk Management Framework (RMF) lifecycle while integrating security into DevOps pipelines.
Role type
Senior IC Cybersecurity Engineer (ISSO)
Builds
Authorized systems compliant with NIST SP 800-53 and STIG baselines
Domain
US Government / Cybersecurity / Compliance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
RMF lifecycle management, NIST SP 800-53 controls, authorization package preparation (SSP, POA&M), vulnerability scanning, STIG compliance, Linux/Windows hardening, security documentation
Preferred skills
GRC platforms (eMASS), CI/CD tools (GitLab, Jenkins), containerization (Docker, Kubernetes), scripting (Bash, Python, PowerShell), cloud security (AWS, Azure), SIEM (Splunk, Elastic), zero trust architecture
Technologies
AWS, Azure, Bash, CI/CD, Cloud, DevSecOps, DevOps, Docker, GitHub, GitLab, Jenkins, Kubernetes, Linux, Network, PowerShell, Python, Splunk, Windows
Responsibilities
Perform ISSO duties and maintain security posture throughout the RMF lifecycle; develop and maintain authorization artifacts including System Security Plans and risk assessments; implement and validate security controls; conduct vulnerability scanning and STIG compliance checks; harden operating systems and network components; collaborate with DevSecOps to integrate security tools into CI/CD pipelines; automate compliance evidence collection; investigate and document security incidents.
Seniority
Senior, hands-on IC