Cybersecurity Engineer
$100k - $153kPioneering Evolution
If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.
Cybersecurity Engineer
Arlington, VA, US
4 days ago Requisition ID: 1033
Salary Range: $100,000.00 To $153,000.00 Annually
POSITION DESCRIPTION:
Pioneering Evolution is seeking a Cybersecurity Engineer to support the security and compliance posture of SyncPoint — a DoD financial system of record operating in a Department of Defense Impact Level 4 (IL4) environment. This role is responsible for supporting the pursuit and maintenance of an Authority to Operate (ATO), implementing and validating NIST SP 800-171 and CMMC Level 2 controls, and serving as the technical security authority for the program.
This is an oversight and hands‑on implementation role. The Cybersecurity Engineer will maintain the System Security Plan (SSP) and supporting compliance documentation, conduct gap assessments, implement technical controls, and work directly with developers, DevOps engineers, infrastructure teams, and program leadership to integrate security into system design and day-to-day operations, maintaining a continuously audit‑ready NIST SP 800-171 and CMMC Level 2 compliance posture. The ability to work across compliance frameworks, cloud infrastructure, and software development workflows — rather than relying solely on automated scanning tools — is essential to this position.
Key Responsibilities:
ATO Lifecycle Management
- Support the ATO lifecycle for SyncPoint, including contributing to and maintaining the System Security Plan (SSP), security assessment documentation, and Plan of Action and Milestones (POA&M) in coordination with the Director of Technology, Platforms, and Implementation.
- Maintain continuous ATO posture through proactive control monitoring, evidence collection, and timely remediation of findings.
- Serve as the technical point of contact for security assessors, authorizing officials, and compliance stakeholders throughout the ATO lifecycle.
- Coordinate security review and assessment activities across engineering, operations, and leadership teams.
NIST SP 800-171 and CMMC Level 2 Compliance
- Interpret and apply NIST SP 800-171 security requirements, translating them into specific technical and administrative controls implemented within the SyncPoint environment.
- Conduct security and compliance gap assessments, document deficiencies, develop remediation plans, and validate that controls have been appropriately implemented.
- Maintain and update the SSP, control implementation statements, policies, procedures, and supporting evidence artifacts on behalf of the Director of Technology, Platforms, and Implementation.
- Coordinate with the organization’s Managed Service Provider (MSP) to validate MSP-implemented controls, define the organizational/project boundary, and ensure control coverage is accurate and complete within the ATO boundary.
- Monitor DoD CMMC and NIST SP 800-171 program requirements and maintain the program’s ongoing compliance and assessment readiness.
Technical Security Implementation
- Implement and validate security controls across Linux and cloud infrastructure, including system hardening, configuration management, patching, and logging.
- Configure and maintain identity and access management (IAM) controls including RBAC, least-privilege access, privileged access management, and service identities across Azure and application tiers.
- Implement and validate network segmentation, firewall rules, private connectivity, VPN configurations, and network access controls appropriate for IL4 environments.
- Deploy and manage security monitoring, logging, alerting, and audit trail capabilities; investigate and respond to security findings and incidents.
- Support vulnerability management processes including scan configuration, finding triage, risk acceptance, and remediation tracking.
Cloud and Infrastructure Security
- Implement and validate cloud security controls within Microsoft Azure Government (and/or AWS GovCloud), including storage encryption, identity management, network security groups, private endpoints, and security posture management.
- Review and contribute to Infrastructure as Code (IaC) using Bicep or Terraform to ensure secure‑by‑default infrastructure provisioning.
- Support DevSecOps practices including repository security, secrets management, branch protections, and secure CI/CD pipeline configuration.
- Apply Managed Identity, RBAC/ABAC, and Zero Trust principles across cloud‑hosted workloads and services.
CUI Protection
- Implement and oversee secure handling, storage, transmission, and disposal of Controlled Unclassified Information (CUI) across all SyncPoint environments and processes.
- Ensure development and operational workflows do not expose CUI through logs, development tools, AI services, or unauthorized environments.
- Support data classification, labeling, and access‑control requirements consistent with CUI handling requirements.
Security Engineering Collaboration
- Work directly with software developers, infrastructure engineers, and the DevOps team to integrate security requirements into application design, infrastructure provisioning, and deployment processes.
- Provide actionable security requirements and guidance that engineers can implement — not just compliance checklist items.
- Use scripting and command‑line tools (Bash, PowerShell, Python, Azure CLI) for administration, evidence collection, and automated compliance checks.
- Investigate and interpret logs, system configurations, vulnerability reports, and security findings; communicate risk clearly to leadership.
Technical Environment: Compliance: NIST SP 800-171, CMMC Level 2, RMF, ATO, CUI
Cloud: Microsoft Azure Government, AWS GovCloud
IAM: Azure AD / Entra ID, RBAC, ABAC, Managed Identity, PAM
Infrastructure: Linux, Windows Server, Network Segmentation, VPN, Firewalls
IaC: Bicep, Terraform
Monitoring/SIEM: Microsoft Defender for Cloud, Microsoft Sentinel, Azure Monitor
CI/CD Security: Azure DevOps, Git, secrets management, branch protections
Scripting: Bash, PowerShell, Python, Azure CLI, AWS CLI
Documentation: SSP, POA&M, policies, procedures, control implementation statements
- ATO lifecycle support and RMF process expertise
- NIST SP 800-171 and CMMC Level 2 depth — both compliance and technical implementation
- Hands‑on security engineering across cloud, Linux, and application tiers
- CUI handling and DoD data protection requirements
- Clear, credible communication of risk and compliance status to leadership
- Practical problem‑solving orientation — builds solutions, not just findings reports
- Effective cross‑functional collaboration with engineering, DevOps, MSP partners, and program leadership
REQUIRED EXPERIENCE:
- Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or a related technical discipline, or equivalent professional experience.
- 5+ years of professional experience in cybersecurity, information assurance, or a closely related field.
- Demonstrated hands‑on experience implementing and assessing NIST SP 800-171 controls; familiarity with CMMC Level 2 requirements and assessment processes.
- Strong working knowledge of fundamental security principles: least privilege, Zero Trust, defense in depth, IAM, encryption, network segmentation, vulnerability management, and system hardening.
- Proficiency with Linux system administration including command‑line tools, permissions, services, logging, patching, and OS‑level security hardening.
- Strong networking fundamentals: IP addressing, subnetting, routing, firewalls, VPN/private connectivity, and network access controls.
- Working knowledge of cloud security within Microsoft Azure and/or AWS, including IAM, network security, storage encryption, logging, monitoring, and security posture management.
- Ability to produce and maintain SSPs, control implementation statements, POA&Ms, policies, procedures, and compliance evidence packages.
- Scripting proficiency in at least one of: Bash, PowerShell, Python, Azure CLI.
- Strong written and verbal communication skills; ability to explain technical security risk to leadership and translate compliance requirements into engineering tasks.
- Demonstrated ability to independently investigate technical security problems and develop practical solutions.
Required Certifications (One or More):
The following certifications are required, reflecting the ATO oversight responsibility and the DoD operating environment:
- CompTIA Security+ (DoD 8570/8140 IAT Level II baseline — minimum acceptable; required if no higher certification held)
- CISSP (Certified Information Systems Security Professional) — strongly preferred for candidates leading an ATO program
- CISM (Certified Information Security Manager) — acceptable alternative to CISSP for candidates with a compliance/governance focus
- CAP / CGRC (Certified Authorization Professional / Governance, Risk, and Compliance) — directly applicable to ATO and RMF activities; highly valued
- Microsoft Certified: Cloud and AI Security Engineer Associate (SC-500) — required or expected to be obtained within 6 months of hire given the Azure Government operating environment
Note: Candidates holding CISSP + CAP/CGRC or CISSP + SC-500 represent the strongest certification profile for this role. Candidates who hold a legacy AZ-500 certification (earned prior to its August 31, 2026 retirement) remain qualified, as the certification stays valid on their transcript until its individual renewal date.
DESIRED EXPERIENCE:
- Active experience working within DoD RMF (Risk Management Framework) processes, including ATO package preparation and assessment coordination.
- Demonstrated experience obtaining or maintaining an ATO for a DoD system.
- Experience with DoD IL4 or IL5 environments.
- Familiarity with DISA STIGs, SCAP tooling, and automated compliance scanning.
- Experience with Infrastructure as Code security review (Bicep, Terraform).
- Experience configuring and reviewing Azure Policy, Microsoft Defender for Cloud, Microsoft Sentinel, or equivalent security posture tools.
- Familiarity with PIEE, Navy ERP, or DoD financial system environments.
- CASP+ (CompTIA Advanced Security Practitioner) — DoD 8570 IAT Level III; valued for technical depth.
- CCSP (Certified Cloud Security Professional) — valued for cloud-native security expertise.
WHO WE ARE AND WHAT WE OFFER:
In addition to competitive salaries and opportunities for professional development and advancement, our employees enjoy a comprehensive range of benefits. To keep pace with the changing needs of our employees, we continually evaluate our benefit plans.
- Paid time off
- 10 paid holidays
- Medical insurance
- Vision insurance
- Legal assistance
- Company-paid life insurance and AD&D
- Company-paid long‑term and short‑term disability insurance
- ...Veteran-Owned Small Business (SDVOSB) delivering mission-focused cybersecurity and technology solutions for federal and commercial clients.... ...Technology, focusing on logging, observability, or SIEM engineering. ~2–5 years of hands-on experience operating and managing...SuggestedFull time
- ...Design, implement, and manage network and cybersecurity architectures to ensure confidentiality, integrity, availability, authentication, and non-repudiation of systems and data. Conduct security risk assessments, audits, and gap analyses of policies, standards...SuggestedPermanent employmentContract workLocal area
- ...Title: Cybersecurity Engineer Location: Richmond, VA (Hybrid) (Need Local candidates ) Duration: 12 Months Contract In-Person Interview No H1B, CPT, OPT LinkedIn Job Description The Cybersecurity Engineer develops and implements advanced...SuggestedContract workH1bLocal area
$86.8k - $198k
...PKI Engineer, Senior**The Opportunity:**You know that the user is the last frontier for cybersecurity. It’s where the perimeter is drawn, and securing identities is pivotal in the fight against cybercriminals. As a PKI specialist, you have the skills and experience to...SuggestedFull timeContract workPart timeWork at officeRemote work$225k - $300k
...We're looking to add a full-time, passionate Cybersecurity Engineer to our New York office to help protect our company's people, data, and infrastructure from the wilds of the internet.Our Cybersecurity Engineers work on firm-wide defenses, provide expertise and advice...SuggestedFull timeWork at office$225k - $300k
...Cybersecurity Engineer - Vulnerability Management We're looking for a Cybersecurity Engineer to help us mature our vulnerability management program. You'll join our Cybersecurity team, a skilled group of programmers and security experts dedicated to keeping the firm...$130.2k - $195.4k
...found a match in Workday, and we hope to be a match for you too.**About the Team**Security Automation & Integration Engineering (SecAIE) transforms cybersecurity operations by architecting intelligent automation that turns manual processes into scalable, decision-...Remote workFlexible hours- ...Akumen, Inc Washington, District of Columbia, United States Position Title: Senior Cybersecurity Engineer Akumen, Inc. delivers mission-focused technology, cybersecurity, and cloud solutions that enable federal agencies to modernize infrastructure, strengthen...Local area
$130k - $162k
...value chain isn’t limited by those around it. We design rocket engines and propulsion solutions. Our products and technologies... ...problems and empowering each other every day. As a Senior Cybersecurity Engineer (Level 3) within our Digital Operations team, you won...Permanent employmentFull timeTemporary workLocal area- ...Cybersecurity Engineer II Who We Are At Upbound Group, we are committed to elevating financial opportunity for all through innovative, inclusive, and technology-driven financial solutions that address the evolving needs and aspirations of consumers. The Company’...Permanent employmentLocal areaWork visaMonday to Friday
- ...turnkey real estate development, master planning, architecture, engineering, and construction firm that safely delivers clients across... ...Want You For Under the direction of the SOC Manager, the Sr. Cybersecurity Engineer is a senior technical role focused primarily on the...For contractorsWork experience placementFlexible hours
- # Cybersecurity EngineerAs the global leader in access solutions, ASSA ABLOY is committed to making the world a safer and more open place... ...Opening Solutions Americas team is hiring a **Cybersecurity Engineer** who will be responsible for implementing, operating, and maintaining...Full time
- ...Flow Control Group is seeking a motivated and technically skilled Cybersecurity Engineer to join our growing Information Security team. This role will be responsible for designing, implementing, administering, and continuously improving security technologies and processes...
- ...business value across PGA Tour departments. Working closely with internal stakeholders including product teams, engineering, data science and AI COE, cybersecurity, privacy, technology operations, and approved vendors. The Forward Deployed Engineer documents existing...Full time
$86.8k - $198k
...Ping Identity Engineer The Opportunity: You know that the user is the last frontier for cybersecurity. It’s where the perimeter is drawn, and securing identities is pivotal in the fight against cybercriminals. As an Identity and Access Management (IAM) specialist...Full timeContract workPart timeWork at officeLocal areaRemote work- ...-life experience in creating innovative solutions within the cybersecurity space Candidate will develop, support, tune and deploy security... ...Phoenix Cyber is a national provider of cybersecurity engineering services, operations services, sustainment services and managed...
$120k - $160k
...The Redesign Group is a global technology and cybersecurity Solution Provider leveraging design thinking, interdependent subject matter... ...environment is crucial. Job Description The Senior Cybersecurity Engineer is a hands‑on engineering role in our Managed Security...Temporary workRemote workFlexible hours$142.11k - $186.06k
...discovery, materials science, financial modeling, logistics, cybersecurity, and defense. IonQ’s advancements in quantum networking position... ...geophysical exploration, and telecommunications. Our team of engineers, scientists, software developers, and operations...Permanent employmentImmediate startFlexible hours$150k - $170k
...Description ABOUT US: Soliel LLC is an innovative, growing engineering company specializing in providing Cybersecurity, Agile Software Development, Data Management and Analysis, Cloud Engineering and Services, DevSecOps, and Systems Engineering services to the Department...Immediate startRemote workFlexible hours$175k - $195k
...Overview ActioNet is seeking an experienced Senior Systems Engineer to design, build, and validate the compute, storage, and... ...test, and customer acceptance. ~ Working experience with DoW cybersecurity compliance in practice, including Security Technical Implementation...Work experience placementInterim roleFlexible hours$102k - $166k
...the whole business depends on? Evolv is seeking a Systems Engineer to administer,operate, and continuously improve our core IT systems... ...and disaster recovery. Reporting to the Senior Director of Cybersecurity & Technology,you'llbe the reliable technical engine behind...Full timeLocal areaRemote workFlexible hours3 days per week$140k - $185k
...and technology initiatives by solving complex operational and engineering challenges. We are seeking a motivated, collaborative Senior... ...highly skilled technical professionals across engineering, cybersecurity, operations, and program teams. We encourage continuous learning...Full timeTemporary workWork at officeLocal areaRemote workFlexible hours$138k - $151k
...Back Sr. Systems Engineer Cloud/Infrastructure March Air Reserve Base , California Jul 13, 2026 Sr. Systems Engineer Riverside... ...~10+ years of experience in systems, network, or cybersecurity engineering supporting mission-critical environments ~ Experience...Temporary work$7.5k
...mission-critical contract providing systems architecture and engineering in a world-wide multi-level Enterprise IT environment! Your... ...Headquartered in Columbia, MD., RealmOne supplies advanced cybersecurity, data science, and software engineering services and products...Contract workWork experience placementImmediate startFlexible hours$140k - $146k
...solutions in software development and both defensive and proactive cybersecurity. Nighthawk offers an integrated, holistic cybersecurity... ...leadership and guidance to cross-functional teams, mentoring junior engineers, and fostering a culture of continuous learning and...Contract workWork at officeWorldwide$125k - $140k
...accommodation or an alternative application process. Senior Traffic Engineer 5 days ago Requisition ID: 1939 Econolite is an innovator... ...of connected and autonomous vehicles, smart cities, and cybersecurity. The Senior Traffic Engineer is responsible for planning,...Weekly payFull timeWork at officeFlexible hours$131.3k - $237.35k
...As a Senior Information Security Systems Engineer (ISSE) you will join a small team of security engineers providing Information Assurance... ...The Senior ISSE shall deliver and lead threat-informed cybersecurity products - cybersecurity risk assessments, architecture reviews...$115k - $135k
...and innovative Woman-Owned Small Business (WOSB) delivering IT engineering and critical mission support services to the public sector.... ...with DoD Security Technical Implementation Guides (STIGs) and cybersecurity requirements. Support vulnerability identification,...Full timeImmediate startFlexible hours$135.48k - $227.7k
...Operations Team, you will collaborate with a global team of engineers to monitor and respond to security events, lead security incidents... ...common security frameworks and standards, including NIST Cybersecurity Framework, ISO 27001, FedRAMP Total Rewards At Samsara...Part timeRemote workFlexible hoursShift work$97.5k - $138k
...days) to receive an alert: Title: Senior Process Automation Engineer At Freeport-McMoRan, we are committed to providing an... ...to Process Automation, and direct Industrial Control System cybersecurity practices. In this role, you lead and manage others by providing...Shift workDay shift
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity Engineer. Be the first to apply!
- remote cyber security Eastern, KY
- cyber security Eastern, KY
- cybersecurity Eastern, KY
- cybersecurity certificate Eastern, KY
- cybersecurity software engineer Eastern, KY
- cybersecurity administrator Eastern, KY
- senior cybersecurity engineer Eastern, KY
- IT cyber security Eastern, KY
- cybersecurity specialist Eastern, KY
- cybersecurity compliance

