Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cyber Security Engineer (Vulnerability Management & DevSecOps) DoS CSS

Full-time

OneZero Solutions

We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. OneZero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance. Additional details are available on our website: Position Title: Cyber Security EngineerLocation: Remote; must reside within the National Capital Region (NCR).Work Schedule: Full-time, 40 hours per week. Must be available during Department core hours of 9:00 a.m. – 3:00 p.m. ET, Monday – Friday, and flex working hours as needed to meet CST day-to-day and emergent requirements. No work is performed on Federal holidays or during Government closures. Participates in a rotating on-call schedule supporting 24x7x365 availability of the vulnerability and compliance scanning platforms.Employment Type: Full-Time, Exempt (W-2), contingent upon Call Order awardClearance: SecretPosition SummaryThe Cyber Security Engineer supports daily operation of the Tenable and Wiz vulnerability and compliance scanning platforms and serves as the program's DevSecOps security engineer. The engineer deploys agents, executes and schedules scans, triages and distributes results to ISSOs, and works with development teams to ensure static analysis, dependency, container image, and infrastructure-as-code security checks are implemented in CI/CD/CM pipelines and captured as authorization evidence.Key ResponsibilitiesOperate Tenable andWiz dayto day: scan execution and scheduling, Nessus Agent deployment and health, asset onboarding, grouping and tagging per CA configuration standards, and quality review of results.Distribute vulnerability and compliance scan results to ISSOs within 5 business days of scan completion; produce remediation tracking reports and metrics; supportiPostapplication groupings.Participate in the on-call rotation and support platform backups, patching, and troubleshooting under direction of the Cyber Security Engineer III.Triage vulnerability, KEV, CVE, and STIG scan results; assist ISSOs in prioritizing critical and high findings to Department and BOD timelines.Ensure applicable pipeline securitycontrols (SAST, dependency scanning, container image scanning, and infrastructure-as-codechecks) are implemented in DevSecOps CI/CD/CM pipelines; document the controls for the SSP and capture scan reports in the Evidence Index (RMF Step 3).Analyze code and pipeline findings for security weaknesses and verify that mitigation strategies are validated and sustained across the system lifecycle.Perform risk identification and IT governance assessments throughout the CI/CD/CM pipeline; brief ISSOs on pipeline risks.Support hardened-build verification for development and production systems and ad-hoc scanning requests.Support agent, data ingest and sharing, and pipeline integration efforts.Maintain scanning SOPs and runbooks; provide Tenable/Wiz evidence for control demonstrations during RMF Step 4.Required QualificationsFive (5)+ years of cybersecurity or systems engineering experience, including two (2)+ years operating Tenable, Wiz, or a comparable enterprise vulnerability management platform.Hands-on experience with CI/CD tooling (GitLab CI, Jenkins, Azure DevOps, or GitHub Actions) and at least one SAST/SCA or container scanning tool (e.g., SonarQube, Fortify, Snyk, Trivy, Anchore, Prisma).Scripting proficiency (Python, PowerShell, or Bash) and comfort with REST APIs.Active, final SECRET security clearance; U.S. citizenship.DoD 8140/8570 IAT Level II baseline certification (e.g., Security+ CE, CySA+, GSEC) or ability to obtain within 6 months.Working knowledge of NIST SP 800-53 Rev. 5 vulnerability and configuration management controls (RA-5, SI-2, CM-6, SA-11).Preferred QualificationsTenable or Wiz certification; Certified DevSecOps Professional or equivalent.Experience with Kubernetes/containers, Terraform, and cloud (AWS/Azure) security.Department of State or other federal civilian experience; iPost familiarity.STIG/SCAP experience and DISA STIG Viewer proficiency.Technical SkillsTenable (tenable.sc/Nessus/Agents) and Wiz operations; scan scheduling and results analysis.CI/CD security tooling: SAST, SCA/dependency scanning, container image scanning, IaC scanning (e.g., Checkov, tfsec).Linux/Windows fundamentals, Git, Python/PowerShell/Bash, REST APIs.NIST SP 800-53 Rev. 5, SP 800-218 (SSDF), CISA KEV, STIG/CIS benchmarks.EducationBachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field, or an additional four (4) years of directly relevant experience in lieu of degree.Remote/Hybrid/On-site and any other relevant work-environment requirementRemote. Duties are performed remotely; the selected candidate must reside within the National Capital Region (NCR). The Government does not furnish equipment; OneZero provides the laptop and collaboration tools. Position requires an OpenNet account, DoS PIV badge, multifactor authentication, and adherence to DoS SBU/CUI handling requirements. Local travel within the National Capital Region; minimal other travel.Position Status:New Position, contingent upon Call Order awardOneZero Solutions LLC is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.

Job Posted by ApplicantPro

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Cyber Security Engineer (Vulnerability Management & DevSecOps) DoS CSS in Washington DC vacancy
  •  ...a broad range of cyber mission areas. OneZero...  ...Title: Cyber Security Engineer – Senior /...  ...availability of the vulnerability and compliance scanning...  ...key management activities, and produces...  ...security checks in DevSecOps pipelines and ensure...  ...OpenNet account, DoS PIV badge,... 
    CSS
    Full time
    Local area
    Remote work
    Monday to Friday
    Flexible hours

    OneZero Solutions

    Washington DC
    2 days ago
  •  ...a broad range of cyber mission areas. OneZero...  ...Title: Cyber Security EngineerLocation:...  ...availability of the vulnerability and compliance scanning...  ...Cyber Security Engineer III is the...  ...user access and role management, plugin and feed updates...  ...OpenNet account, DoS PIV badge,... 
    CSS
    Full time
    Local area
    Remote work
    Monday to Friday
    Flexible hours

    OneZero Solutions

    Washington DC
    2 days ago
  •  ...across a broad range of cyber mission areas....  ...direction for the vulnerability management and cloud engineers; and interfaces daily...  ...Systems Security Manager (ISSM), Authorizing...  ...Tenable, Wiz/cloud, and DevSecOps engineers.Identify...  ...OpenNet account, DoS PIV badge, multifactor... 
    CSS
    Full time
    For contractors
    Local area
    Remote work
    Monday to Friday
    Flexible hours

    OneZero Solutions

    Washington DC
    3 days ago
  •  ...a broad range of cyber mission areas. OneZero...  ...SME – Information Security AnalystLocation:...  ...30 days.Review vulnerability, KEV, CVE, and STIG...  ...citizenship.Experience managing POA&Ms and...  ...FedRAMP inheritance, DevSecOps pipeline controls,...  ...OpenNet account, DoS PIV badge, multifactor... 
    CSS
    Full time
    For contractors
    Local area
    Remote work
    Monday to Friday
    Flexible hours

    OneZero Solutions

    Washington DC
    2 days ago
  • $110k - $230k

    Staff Security Engineer At GEICO, we offer a rewarding career where your ambitions are met...  ...strategy, architecture, and execution of Vulnerability Management across a complex, hybrid technology...  ...integrating security into CI/CD and DevSecOps practices. Working knowledge and... 
    Suggested
    Hourly pay
    Work experience placement
    Local area

    GEICO

    Bethesda, MD
    3 days ago
  •  ...seeking a highly skilled Senior Vulnerability Assessment Analyst to...  ...cybersecurity and vulnerability management activities within a federal...  ...testing concepts, and security assessment tools. The Senior...  ...closely with cybersecurity engineers, system administrators, ISSOs... 
    Contract work

    RIVIDIUM

    Washington DC
    12 days ago
  •  ...Storage Cybersecurity Engineer / Cybersecurity Architect...  ...own our enterprise cyber strategy and hands-on...  ...Operational Technology, Asset Management, EPC, Legal, External...  ..., and HR to embed security into both project...  ...company. Own threat & vulnerability management: Baseline,... 
    Remote job
    Full time
    Flexible hours

    Thinkbac Consulting

    Washington DC
    more than 2 months ago
  • Cybersecurity Vulnerability Analyst (Incident Manager III) Description Supporting our prime...  ...on FCEB and CIKR security postures Conduct prevalence...  ...analysis summaries, and other cyber intelligence reports...  ...Computer Science, Computer Engineering, Computer Information Systems... 
    For contractors

    kozmetickesluzby.vecnakraska.sk - Jobboard

    Arlington, VA
    1 day ago
  • $110k - $130k

    Associate / IT Security Vulnerability Specialist (0036) OCT Consulting is a management and technology consulting firm that supports Federal Government clients. We provide...  .... Articulate risk and impact to product, engineering and other business leaders with the ability to... 
    Temporary work
    3 days per week

    OCT CONSULTING LLC

    Suitland, MD
    3 days ago
  • $104k - $166k

    Responsibilities The Vulnerability Management Analyst will support the Federal Aviation Administration...  ..., ensuring compliance with federal security requirements, and contributing to a...  ...Collaborate with FAA system owners, network engineers, developers, and operations teams to... 
    Contract work
    Local area
    Remote work
    Shift work

    Peraton

    Bethesda, MD
    3 days ago
  • $90k - $155k

     ...company. We’re a community of innovators, engineers, analysts and business professionals...  ...to tackle the most complex national security challenges. For more than 20 years we...  ...to join our team. ABSC is seeking a Vulnerability Management Analyst to join our team supporting... 
    Contract work
    Remote work
    Flexible hours

    absc-us

    Arlington, VA
    2 days ago
  •  ...Job Description Job Description Job Title: Security Engineer - Vulnerability Management Location: Washington, DC 20590 (onsite) Type: Contract...  ..., reporting, and risk assessment processes to present cyber-related risks effectively. Troubleshoot issues associated... 
    Contract work
    Local area

    System One

    Washington DC
    a month ago
  • $86.8k - $198k

     ...7 Enterprise Cybersecurity Vulnerability Analyst, Senior The Opportunity...  ...facing vulnerabilities and security misconfigurations across the...  ...serve as a vulnerability management resource supporting the company...  ...cybersecurity teams in a Cyber Fusion Center (CFC) environment... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Mc Lean, VA
    3 days ago
  • Job Description AAC is seeking Senior Security Analyst focusing on Vulnerability Management to join our security compliance team. In this role, you...  ...Requires bachelor's degree in computer science, cyber security, engineering, or a related technical field. Additional... 
    Work experience placement
    3 days per week

    American Addiction Centers

    Bethesda, MD
    1 day ago
  •  ...across a broad range of cyber mission areas. OneZero full...  ...and Senior Information Security Analysts in operating the Risk Management Framework and continuous...  ...ISSO validation.Review vulnerability and compliance scan...  ...requires an OpenNet account, DoS PIV badge, multifactor... 
    CSS
    Full time
    Local area
    Remote work
    Monday to Friday
    Flexible hours

    OneZero Solutions

    Washington DC
    2 days ago
  •  ...across a broad range of cyber mission areas. OneZero...  ...: Senior Information Security AnalystLocation:...  ...more than 30 days.Review vulnerability, KEV, CVE, and STIG results...  ..., POA&M lifecycle management.Reading Tenable/Nessus...  ...requires an OpenNet account, DoS PIV badge, multifactor... 
    CSS
    Full time
    Contract work
    For contractors
    Work at office
    Local area
    Remote work
    Monday to Friday
    Flexible hours

    OneZero Solutions

    Washington DC
    2 days ago
  •  ...design and frontend engineering role for someone who...  ...TypeScript, and Tailwind CSS . Work directly with...  ...constraints, security, and delivery timelines...  ...applications, workflow management, or large-scale data platforms...  ...working in Agile, DevSecOps, platform engineering,... 
    CSS

    NALEJ

    Arlington, VA
    17 days ago
  •  ...Specialist to support the day-to-day management, measurement, and...  ...to support the reliability, security, and performance of Shatterproof...  ...security, platform updates, vulnerability remediation, backup processes...  ...Working knowledge of HTML and CSS; familiarity with JavaScript... 
    CSS
    Full time

    Shatterproof

    Washington DC
    17 days ago
  •  ...enthusiastic team of developers and engineers in an Agile environment to...  ...and tasks using workflows - manage data flows from the customer...  ...languages like HTML/CSS, JavaScript, and data models...  ...Experience with CI/CD integrations, DevSecOps and security-in-the-pipeline, and code... 
    CSS
    Remote work

    Nüvitek

    Arlington, VA
    10 days ago
  • $120k - $260k

     ...highly experienced Senior Staff Security Engineer to lead the strategy and technical execution of Vulnerability Management and Offensive Security...  ...controls into CI/CD pipelines and DevSecOps workflows. Education :...  ...in computer science, Cyber Security, or equivalent education... 
    Hourly pay
    Work experience placement
    Local area

    GEICO

    Bethesda, MD
    3 days ago
  • $130k - $150k

     ...Job Title: Cyber Security Engineer Location: Ft Meade, MD/Hybrid Clearance...  ..., application teams, DevSecOps engineers, and operations...  ...compliance, identify and remediate vulnerabilities, support continuous...  ...FISMA, RMF, vulnerability management, continuous monitoring, and... 
    Full time
    Flexible hours

    SHR Consulting Group, LLC

    Alexandria, VA
    5 days ago
  • $145k - $165k

     ...Senior Cybersecurity Engineer Role Summary The Senior...  ...environment remains secure, compliant, and...  ...incident response, risk management, and continuous improvement...  ...systems. Conduct vulnerability assessments,...  ...Trust Architecture and DevSecOps practices. Preferred... 
    Full time
    Local area

    Howard University Hospital

    Washington DC
    3 days ago
  • $90k - $120k

     ...Description Job Title: Senior Cyber Security Engineer Location: Washington,...  ...We specialize in FX risk management and international payments...  ...through Secure Score, vulnerability management, compliance reporting...  ...or Python automation, and DevSecOps methodologies. ~ Strong... 
    Full time
    Summer work
    Work at office
    Local area
    Worldwide
    Monday to Friday

    Monex USA

    Washington DC
    25 days ago
  • $140k - $145k

     ...looking for a Software Engineer - Team Lead to support...  ...modernization, and sustainment of secure applications across DoD...  ..., CI/CD pipelines, and DevSecOps practices, ensuring...  ...Design, implement, and manage automated build, test,...  ..., JavaScript, (X)HTML, CSS, Knockout. Azure,... 
    CSS
    Full time
    Part time
    For contractors
    Remote work

    Akima, LLC

    Alexandria, VA
    1 day ago
  • $135k - $155k

     ...Methods Web Developer Security EngineerSpry...  ...cybersecurity, and program management solutions...  ...solutions across cyber operations,...  ...Developer Security Engineer protects mission-...  ...software development, vulnerability remediation,...  ...software development, DevSecOps automation, and... 
    Full time
    Contract work
    Worldwide

    Spry Methods

    Washington DC
    3 days ago
  • $154.05k - $278.48k

     ...exciting opportunity for Cyber Security Engineer—Technical Lead in our Intel...  ...SIGINT), and Cryptographic Key Management. At Leidos, we offer...  ...Technical Leads throughout a DevSecOps life cycle both on policy...  ...and do not introduce new vulnerabilities.Conduct routine vulnerability... 
    Full time
    Immediate start
    Flexible hours

    Leidos

    Bethesda, MD
    2 days ago
  •  ...Provide project and product oversight while managing application development schedules based...  ...issues to maintain the performance and security of web applications. •Stay up-to-date...  ...development technologies. •Proficiency in HTML, CSS, JavaScript, and other relevant... 
    CSS

    Bow Wave LLC

    Washington DC
    12 days ago
  • A leading cybersecurity consultancy is seeking a Cybersecurity Vulnerability Analyst based in Arlington, VA. The role requires an active Top Secret Security Clearance and 5+ years of experience, focusing on vulnerability analysis for federal clients. Candidates must exhibit... 

    Node.Digital LLC

    Arlington, VA
    2 days ago
  • Arete Associates in Falls Church, VA is seeking a Vulnerability Management Analyst to own the end-to-end remediation cycle from scanning to verification across desktops, servers, and networks. The role requires hands-on patching, risk-based prioritization, and coordination... 

    Arete Associates

    Falls Church, VA
    5 days ago
  •  ...cybersecurity, data analytics, strategic communications, event management, training, and program management. With over 15 years of proven...  ...frameworks like React, Angular, or Ember Proficiency in HTML, CSS/SASS, and Bootstrap Experience designing unit, integration,... 
    CSS
    Remote job
    Hourly pay
    Full time
    Flexible hours

    Viderity Inc.

    Washington DC
    more than 2 months ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cyber Security Engineer (Vulnerability Management & DevSecOps) DoS CSS. Be the first to apply!