Cybersecurity Engineer
Pioneering Evolution
POSITION DESCRIPTION: Pioneering Evolution is seeking a Cybersecurity Engineer to support the security and compliance posture of SyncPoint - a DoD financial system of record operating in a Department of Defense Impact Level 4 (IL4) environment. This role is responsible for supporting the pursuit and maintenance of an Authority to Operate (ATO), implementing and validating NIST SP 800-171 and CMMC Level 2 controls, and serving as the technical security authority for the program. This is an oversight and hands-on implementation role. The Cybersecurity Engineer will maintain the System Security Plan (SSP) and supporting compliance documentation, conduct gap assessments, implement technical controls, and work directly with developers, DevOps engineers, infrastructure teams, and program leadership to integrate security into system design and day-to-day operations, maintaining a continuously audit-ready NIST SP 800-171 and CMMC Level 2 compliance posture. The ability to work across compliance frameworks, cloud infrastructure, and software development workflows - rather than relying solely on automated scanning tools - is essential to this position. Key Responsibilities: ATO Lifecycle Management
Compliance: NIST SP 800-171, CMMC Level 2, RMF, ATO, CUI
Cloud: Microsoft Azure Government, AWS GovCloud
IAM: Azure AD / Entra ID, RBAC, ABAC, Managed Identity, PAM
Infrastructure: Linux, Windows Server, Network Segmentation, VPN, Firewalls
IaC: Bicep, Terraform
Monitoring/SIEM: Microsoft Defender for Cloud, Microsoft Sentinel, Azure Monitor
CI/CD Security: Azure DevOps, Git, secrets management, branch protections
Scripting: Bash, PowerShell, Python, Azure CLI, AWS CLI
Documentation: SSP, POA&M, policies, procedures, control implementation statements Key Competencies
- Support the ATO lifecycle for SyncPoint, including contributing to and maintaining the System Security Plan (SSP), security assessment documentation, and Plan of Action and Milestones (POA&M) in coordination with the Director of Technology, Platforms, and Implementation.
- Maintain continuous ATO posture through proactive control monitoring, evidence collection, and timely remediation of findings.
- Serve as the technical point of contact for security assessors, authorizing officials, and compliance stakeholders throughout the ATO lifecycle.
- Coordinate security review and assessment activities across engineering, operations, and leadership teams.
- Interpret and apply NIST SP 800-171 security requirements, translating them into specific technical and administrative controls implemented within the SyncPoint environment.
- Conduct security and compliance gap assessments, document deficiencies, develop remediation plans, and validate that controls have been appropriately implemented.
- Maintain and update the SSP, control implementation statements, policies, procedures, and supporting evidence artifacts on behalf of the Director of Technology, Platforms, and Implementation.
- Coordinate with the organization's Managed Service Provider (MSP) to validate MSP-implemented controls, define the organizational/project boundary, and ensure control coverage is accurate and complete within the ATO boundary.
- Monitor DoD CMMC and NIST SP 800-171 program requirements and maintain the program's ongoing compliance and assessment readiness.
- Implement and validate security controls across Linux and cloud infrastructure, including system hardening, configuration management, patching, and logging.
- Configure and maintain identity and access management (IAM) controls including RBAC, least-privilege access, privileged access management, and service identities across Azure and application tiers.
- Implement and validate network segmentation, firewall rules, private connectivity, VPN configurations, and network access controls appropriate for IL4 environments.
- Deploy and manage security monitoring, logging, alerting, and audit trail capabilities; investigate and respond to security findings and incidents.
- Support vulnerability management processes including scan configuration, finding triage, risk acceptance, and remediation tracking.
- Implement and validate cloud security controls within Microsoft Azure Government (and/or AWS GovCloud), including storage encryption, identity management, network security groups, private endpoints, and security posture management.
- Review and contribute to Infrastructure as Code (IaC) using Bicep or Terraform to ensure secure-by-default infrastructure provisioning.
- Support DevSecOps practices including repository security, secrets management, branch protections, and secure CI/CD pipeline configuration.
- Apply Managed Identity, RBAC/ABAC, and Zero Trust principles across cloud-hosted workloads and services.
- Implement and oversee secure handling, storage, transmission, and disposal of Controlled Unclassified Information (CUI) across all SyncPoint environments and processes.
- Ensure development and operational workflows do not expose CUI through logs, development tools, AI services, or unauthorized environments.
- Support data classification, labeling, and access-control requirements consistent with CUI handling requirements.
- Work directly with software developers, infrastructure engineers, and the DevOps team to integrate security requirements into application design, infrastructure provisioning, and deployment processes.
- Provide actionable security requirements and guidance that engineers can implement - not just compliance checklist items.
- Use scripting and command-line tools (Bash, PowerShell, Python, Azure CLI) for administration, evidence collection, and automated compliance checks.
- Investigate and interpret logs, system configurations, vulnerability reports, and security findings; communicate risk clearly to leadership.
Compliance: NIST SP 800-171, CMMC Level 2, RMF, ATO, CUI
Cloud: Microsoft Azure Government, AWS GovCloud
IAM: Azure AD / Entra ID, RBAC, ABAC, Managed Identity, PAM
Infrastructure: Linux, Windows Server, Network Segmentation, VPN, Firewalls
IaC: Bicep, Terraform
Monitoring/SIEM: Microsoft Defender for Cloud, Microsoft Sentinel, Azure Monitor
CI/CD Security: Azure DevOps, Git, secrets management, branch protections
Scripting: Bash, PowerShell, Python, Azure CLI, AWS CLI
Documentation: SSP, POA&M, policies, procedures, control implementation statements Key Competencies
- ATO lifecycle support and RMF process expertise
- NIST SP 800-171 and CMMC Level 2 depth - both compliance and technical implementation
- Hands-on security engineering across cloud, Linux, and application tiers
- CUI handling and DoD data protection requirements
- Clear, credible communication of risk and compliance status to leadership
- Practical problem-solving orientation - builds solutions, not just findings reports
- Effective cross-functional collaboration with engineering, DevOps, MSP partners, and program leadership
- Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or a related technical discipline, or equivalent professional experience.
- 5+ years of professional experience in cybersecurity, information assurance, or a closely related field.
- Demonstrated hands-on experience implementing and assessing NIST SP 800-171 controls; familiarity with CMMC Level 2 requirements and assessment processes.
- Strong working knowledge of fundamental security principles: least privilege, Zero Trust, defense in depth, IAM, encryption, network segmentation, vulnerability management, and system hardening.
- Proficiency with Linux system administration including command-line tools, permissions, services, logging, patching, and OS-level security hardening.
- Strong networking fundamentals: IP addressing, subnetting, routing, firewalls, VPN/private connectivity, and network access controls.
- Working knowledge of cloud security within Microsoft Azure and/or AWS, including IAM, network security, storage encryption, logging, monitoring, and security posture management.
- Ability to produce and maintain SSPs, control implementation statements, POA&Ms, policies, procedures, and compliance evidence packages.
- Scripting proficiency in at least one of: Bash, PowerShell, Python, Azure CLI.
- Strong written and verbal communication skills; ability to explain technical security risk to leadership and translate compliance requirements into engineering tasks.
- Demonstrated ability to independently investigate technical security problems and develop practical solutions.
- CompTIA Security+ (DoD 8570/8140 IAT Level II baseline - minimum acceptable; required if no higher certification held)
- CISSP (Certified Information Systems Security Professional) - strongly preferred for candidates leading an ATO program
- CISM (Certified Information Security Manager) - acceptable alternative to CISSP for candidates with a compliance/governance focus
- CAP / CGRC (Certified Authorization Professional / Governance, Risk, and Compliance) - directly applicable to ATO and RMF activities; highly valued
- Microsoft Certified: Cloud and AI Security Engineer Associate (SC-500) - required or expected to be obtained within 6 months of hire given the Azure Government operating environment
- Active experience working within DoD RMF (Risk Management Framework) processes, including ATO package preparation and assessment coordination.
- Demonstrated experience obtaining or maintaining an ATO for a DoD system.
- Experience with DoD IL4 or IL5 environments.
- Familiarity with DISA STIGs, SCAP tooling, and automated compliance scanning.
- Experience with Infrastructure as Code security review (Bicep, Terraform).
- Experience configuring and reviewing Azure Policy, Microsoft Defender for Cloud, Microsoft Sentinel, or equivalent security posture tools.
- Familiarity with PIEE, Navy ERP, or DoD financial system environments.
- CASP+ (CompTIA Advanced Security Practitioner) - DoD 8570 IAT Level III; valued for technical depth.
- CCSP (Certified Cloud Security Professional) - valued for cloud-native security expertise.
- Paid time off
- 10 paid holidays
- Medical insurance
- Dental insurance
- Vision insurance
- Legal assistance
- Company-paid life insurance and AD&D
- Company-paid long-term and short-term disability insurance
- Tuition reimbursement
- 401(k) plan with company contribution
- Continuing Education Opportunities
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Cybersecurity Engineer in Arlington, VA vacancy
- ...flexibility and support that you need to do your best work — Ardent is where your next mission begins. Ardent is seeking a Cybersecurity Engineer to join our team. This position is based in Washington, DC and may require a combination of on-site and remote...SuggestedFull timeLocal areaRemote workFlexible hours
- ...Description Cybersecurity Engineer About Essnova Solutions Essnova Solutions is a fast-growing federal contractor delivering innovative technology, cybersecurity, cloud, and digital transformation solutions to Federal Government customers. We are seeking a Cybersecurity...SuggestedFull timeFor contractors
$140k - $180k
...Job Title: Cybersecurity Engineer Location : Remote Clearance Required: Active Secret or Top-Secret Salary Range: $140K-$180K Based on Experience Application Deadline : June 1, 2026 Description : We are seeking a Cybersecurity Engineer to...SuggestedFull timeRemote work- GTSC seeks Cybersecurity Engineer – Zero Trust / RMF / SIEM \\\ for mid -August 2026 start. Commitment to start must be by 30 June in order to complete background checks required for this position. \ \\ \ Location \ : This is a local remote position in the metropolitan...SuggestedFull timeTemporary workLocal areaRemote workFlexible hours
$135k - $155k
...Job Description Job Description SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure and Operations, and Applications Development and Maintenance IT service provider headquartered in Dulles, Virginia with operations...SuggestedContract workWork experience placement3 days per week- ...Description Job Description Description: RMC is seeking an Engineer for a full-time hybrid position in Bremerton WA, San Diego CA... ...of services such as Risk Management, Mission Assurance, and Cybersecurity. Our team's well-being is paramount, and we reflect this...Full timeContract workTemporary workWork at officeLocal areaFlexible hours
$175k - $190k
...company and certified Woman-Owned Small Business (WOSB) providing engineering, analytical, and programmatic expertise to the Federal... ...performance. Come join our team! Mobius is seeking a Senior Cybersecurity Engineer. In this role, the Senior Cybersecurity Engineer...Full timeWork at officeRemote workFlexible hours2 days per week3 days per week$110k - $120k
...Job Title: Cybersecurity Engineer Clearance : Secret or Top-Secret (TS) Location : Pentagon - Arlington/Crystal City, VA Work Schedule: On-site, 5 days/week Salary Range: $110k-$120K Application Deadline: September 30, 2026 Description : The...Full timeContract workWork at office$155k - $180k
...Dark Wolf is seeking a Senior Cybersecurity Engineer to join a collaborative team to develop, manage, and maintain the security posture of cloud-based information systems with a focus on SIEM validation, continuous exposure management, and continuous Authorization...Full timeFor contractors- ...Description One Federal Solution provides cybersecurity technical leadership and engineering expertise across federal mission environments. We deliver strategic direction for cybersecurity, cloud engineering, Agile DevSecOps, AI/ML, and Zero Trust initiatives while...Full timeFor contractorsWork at office
- **CONTINGENT UPON CONTRACT AWARD** Overview: Job Title: Cybersecurity Engineer – Senior Location : Washington, DC (Due to the nature of the work and contract requirements, U.S. Citizenship is required. ) Description: C3EL is seeking a Senior...Full timeContract work
- ...the government create lasting impact in fields as diverse as cybersecurity, healthcare, aviation, defense, and enterprise transformation... ...SATCOM Department which is part of the MITRE Technology and Engineering Infrastructure, Networking, and Communications Division, has...Work experience placementInternshipLocal areaImmediate start
- ...the government create lasting impact in fields as diverse as cybersecurity, healthcare, aviation, defense, and enterprise transformation... ...mitigation, adversary hunting, adversary emulation, and detection engineering with a special focus on operational technology (OT). It is...Work experience placementInternshipLocal area3 days per week
- ...impacts our nation and improves lives. This is where your skills strengthen national security, cybersecurity, health, transportation, and citizen services. We’re a nonprofit engineering, applied research, and advanced technology organization working in the public interest....InternshipLocal area3 days per week
- ...Resilience Directorate, you will be part of a team of cyber security engineers applying the latest tools, techniques, and methods to cyber security and operational resilience challenges. The Senior Cybersecurity Engineer will work directly with leaders in government,...Full timeWork experience placementImmediate start
$198k - $273k
...are, you’re in the right place.Who We AreIn order to be the cybersecurity partner of choice, we must trailblaze the path and shape the... ...truly matters.Job SummaryYour CareerAs a Cortex Transformation Engineer, you are a critical part of the Global Transformation Practice...Full timeRemote workVisa sponsorshipWork visa- ...the government create lasting impact in fields as diverse as cybersecurity, healthcare, aviation, defense, and enterprise transformation... ...Zero‑Trust‑aligned ICAM architectures and reference designs.Engineer authentication, authorization, and federation solutions (e.g....InternshipLocal area
- DescriptionSAIC seeks a CyberArk Engineer Mid to support the Department of Transportation’s Cybersecurity mission by joining a dedicated team of cybersecurity professionals who collaborate, cooperate, and facilitate maintaining and enhancing the security posture of DOT...
$69.4k - $158k
Cybersecurity and RMF Engineer, MidThe Opportunity:Are you looking for an opportunity to share your experience in cybersecurity and systems engineering that will support the U.S. Air Force? As a systems security and network security engineer, you can identify the tools...Full timeContract workPart timeWork at officeLocal areaRemote work$140k - $190k
Job DescriptionEverforth ECS is seeking a Sr. TORQ/SOAR Engineer to join our team in Arlington, VA (Hybrid).This position is contingent... ...Security Services (MSSP) team at ECS, a leading provider of cybersecurity, cloud, AI, data, and enterprise transformation solutions....Contract work$112k - $179k
ResponsibilitiesPeraton is seeking to hire an experienced Cybersecurity Engineer for its Federal Strategic Cyber group. Location: Chandler, AZ or Washington DC.Roles and Responsibilities:The Cybersecurity Engineer supports a 24x7 Security Operations Center (SOC) by engineering...Contract workShift work- ...the government create lasting impact in fields as diverse as cybersecurity, healthcare, aviation, defense, and enterprise transformation... ...difference with us.SummaryMITRE is seeking a Spectrum Compatibility Engineer to support advanced analysis, modeling, and simulation of...Work experience placementInternshipLocal area
$126k - $200k
Amentum is seeking Cybersecurity Engineer to support our U.S. Department of Energy contract. Positions will be based in the Washington, D.C area.Work Schedule: 5 days, 8hrsEssential Responsibilities: Provide a wide range of Cyber Intelligence (CI) services to deliver timely...Full timeContract work- ...the government create lasting impact in fields as diverse as cybersecurity, healthcare, aviation, defense, and enterprise transformation... ...Experience (UX) department is seeking a Senior Human Factors Engineer (HFE) who is passionate about designing and developing user-centered...Work experience placementInternshipLocal area3 days per week
- Incident Response Engineer-JourneymanIntermittent Telework: Arlington, VATS/SCI RequiredPay Range: $125K - $142KJob Description: The Incident Response Engineer Journeyman is a mid‑level cybersecurity professional responsible for detecting, investigating, and remediating...Remote work
$166k - $202k
As a Sr. Cybersecurity Engineer II, you’ll design and develop technical architecture components enabling application teams to integrate with zero trust authentication and authorization services. You will work closely with application developers, security architects, and...Full timeLocal area$5,000 per month
...are not U.S. citizens are not eligible for this role. Imagine One Technology & Management, Ltd. is seeking four (4) Senior Cybersecurity Engineers with specific experience working with Submarine-Launched Ballistic Missiles (SLBMs). These positions are contingent upon award...- Computer Technologies Consultants (CTC) is seeking a Cybersecurity Engineer to support the Congressional Budget Office (CBO) in Washington, DC. With offices in Washington DC and San Diego, CA, CTC is a leading technology company providing lifecycle IT, data analytics,...Full timeContract workFor contractorsWork at officeLocal area
- ...the government create lasting impact in fields as diverse as cybersecurity, healthcare, aviation, defense, and enterprise transformation... ...mitigation, adversary hunting, adversary emulation, and detection engineering with a special focus on operational technology (OT). It is...InternshipLocal area3 days per week
- SummaryAll Native Group, a division of Ho Chunk, Incorporated, is seeking an exceptional Cybersecurity Engineer to design, implement, and maintain enterprise security controls that enforce Zero Trust principles across the Congressional Budget Office's (CBO) cloud, network...Permanent employmentFull timeContract workWork at officeLocal areaFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity Engineer. Be the first to apply!
Related searches
- IT cyber security Arlington, VA
- cyber security intern Arlington, VA
- cybersecurity technical writer Arlington, VA
- cybersecurity certificate Arlington, VA
- cybersecurity grc Arlington, VA
- cybersecurity Arlington, VA
- remote cyber security Arlington, VA
- cyber security technician Arlington, VA
- cybersecurity administrator Arlington, VA
- senior cybersecurity engineer Arlington, VA


