Cyber Security Engineer (Vulnerability Management & DevSecOps) DoS CSS
Full-time
OneZero Solutions
We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. OneZero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance. Additional details are available on our website: Position Title: Cyber Security EngineerLocation: Remote; must reside within the National Capital Region (NCR).Work Schedule: Full-time, 40 hours per week. Must be available during Department core hours of 9:00 a.m. – 3:00 p.m. ET, Monday – Friday, and flex working hours as needed to meet CST day-to-day and emergent requirements. No work is performed on Federal holidays or during Government closures. Participates in a rotating on-call schedule supporting 24x7x365 availability of the vulnerability and compliance scanning platforms.Employment Type: Full-Time, Exempt (W-2), contingent upon Call Order awardClearance: SecretPosition SummaryThe Cyber Security Engineer supports daily operation of the Tenable and Wiz vulnerability and compliance scanning platforms and serves as the program's DevSecOps security engineer. The engineer deploys agents, executes and schedules scans, triages and distributes results to ISSOs, and works with development teams to ensure static analysis, dependency, container image, and infrastructure-as-code security checks are implemented in CI/CD/CM pipelines and captured as authorization evidence.Key ResponsibilitiesOperate Tenable andWiz dayto day: scan execution and scheduling, Nessus Agent deployment and health, asset onboarding, grouping and tagging per CA configuration standards, and quality review of results.Distribute vulnerability and compliance scan results to ISSOs within 5 business days of scan completion; produce remediation tracking reports and metrics; supportiPostapplication groupings.Participate in the on-call rotation and support platform backups, patching, and troubleshooting under direction of the Cyber Security Engineer III.Triage vulnerability, KEV, CVE, and STIG scan results; assist ISSOs in prioritizing critical and high findings to Department and BOD timelines.Ensure applicable pipeline securitycontrols (SAST, dependency scanning, container image scanning, and infrastructure-as-codechecks) are implemented in DevSecOps CI/CD/CM pipelines; document the controls for the SSP and capture scan reports in the Evidence Index (RMF Step 3).Analyze code and pipeline findings for security weaknesses and verify that mitigation strategies are validated and sustained across the system lifecycle.Perform risk identification and IT governance assessments throughout the CI/CD/CM pipeline; brief ISSOs on pipeline risks.Support hardened-build verification for development and production systems and ad-hoc scanning requests.Support agent, data ingest and sharing, and pipeline integration efforts.Maintain scanning SOPs and runbooks; provide Tenable/Wiz evidence for control demonstrations during RMF Step 4.Required QualificationsFive (5)+ years of cybersecurity or systems engineering experience, including two (2)+ years operating Tenable, Wiz, or a comparable enterprise vulnerability management platform.Hands-on experience with CI/CD tooling (GitLab CI, Jenkins, Azure DevOps, or GitHub Actions) and at least one SAST/SCA or container scanning tool (e.g., SonarQube, Fortify, Snyk, Trivy, Anchore, Prisma).Scripting proficiency (Python, PowerShell, or Bash) and comfort with REST APIs.Active, final SECRET security clearance; U.S. citizenship.DoD 8140/8570 IAT Level II baseline certification (e.g., Security+ CE, CySA+, GSEC) or ability to obtain within 6 months.Working knowledge of NIST SP 800-53 Rev. 5 vulnerability and configuration management controls (RA-5, SI-2, CM-6, SA-11).Preferred QualificationsTenable or Wiz certification; Certified DevSecOps Professional or equivalent.Experience with Kubernetes/containers, Terraform, and cloud (AWS/Azure) security.Department of State or other federal civilian experience; iPost familiarity.STIG/SCAP experience and DISA STIG Viewer proficiency.Technical SkillsTenable (tenable.sc/Nessus/Agents) and Wiz operations; scan scheduling and results analysis.CI/CD security tooling: SAST, SCA/dependency scanning, container image scanning, IaC scanning (e.g., Checkov, tfsec).Linux/Windows fundamentals, Git, Python/PowerShell/Bash, REST APIs.NIST SP 800-53 Rev. 5, SP 800-218 (SSDF), CISA KEV, STIG/CIS benchmarks.EducationBachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field, or an additional four (4) years of directly relevant experience in lieu of degree.Remote/Hybrid/On-site and any other relevant work-environment requirementRemote. Duties are performed remotely; the selected candidate must reside within the National Capital Region (NCR). The Government does not furnish equipment; OneZero provides the laptop and collaboration tools. Position requires an OpenNet account, DoS PIV badge, multifactor authentication, and adherence to DoS SBU/CUI handling requirements. Local travel within the National Capital Region; minimal other travel.Position Status:New Position, contingent upon Call Order awardOneZero Solutions LLC is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.
Job Posted by ApplicantPro
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Cyber Security Engineer (Vulnerability Management & DevSecOps) DoS CSS in Washington DC vacancy
- ...a broad range of cyber mission areas. OneZero... ...Title: Cyber Security Engineer – Senior /... ...availability of the vulnerability and compliance scanning... ...key management activities, and produces... ...security checks in DevSecOps pipelines and ensure... ...OpenNet account, DoS PIV badge,...CSSFull timeLocal areaRemote workMonday to FridayFlexible hours
- ...a broad range of cyber mission areas. OneZero... ...Title: Cyber Security EngineerLocation:... ...availability of the vulnerability and compliance scanning... ...Cyber Security Engineer III is the... ...user access and role management, plugin and feed updates... ...OpenNet account, DoS PIV badge,...CSSFull timeLocal areaRemote workMonday to FridayFlexible hours
- ...across a broad range of cyber mission areas.... ...direction for the vulnerability management and cloud engineers; and interfaces daily... ...Systems Security Manager (ISSM), Authorizing... ...Tenable, Wiz/cloud, and DevSecOps engineers.Identify... ...OpenNet account, DoS PIV badge, multifactor...CSSFull timeFor contractorsLocal areaRemote workMonday to FridayFlexible hours
- ...a broad range of cyber mission areas. OneZero... ...SME – Information Security AnalystLocation:... ...30 days.Review vulnerability, KEV, CVE, and STIG... ...citizenship.Experience managing POA&Ms and... ...FedRAMP inheritance, DevSecOps pipeline controls,... ...OpenNet account, DoS PIV badge, multifactor...CSSFull timeFor contractorsLocal areaRemote workMonday to FridayFlexible hours
$110k - $230k
Staff Security Engineer At GEICO, we offer a rewarding career where your ambitions are met... ...strategy, architecture, and execution of Vulnerability Management across a complex, hybrid technology... ...integrating security into CI/CD and DevSecOps practices. Working knowledge and...SuggestedHourly payWork experience placementLocal area- ...seeking a highly skilled Senior Vulnerability Assessment Analyst to... ...cybersecurity and vulnerability management activities within a federal... ...testing concepts, and security assessment tools. The Senior... ...closely with cybersecurity engineers, system administrators, ISSOs...Contract work
- ...Storage Cybersecurity Engineer / Cybersecurity Architect... ...own our enterprise cyber strategy and hands-on... ...Operational Technology, Asset Management, EPC, Legal, External... ..., and HR to embed security into both project... ...company. Own threat & vulnerability management: Baseline,...Remote jobFull timeFlexible hours
- Cybersecurity Vulnerability Analyst (Incident Manager III) Description Supporting our prime... ...on FCEB and CIKR security postures Conduct prevalence... ...analysis summaries, and other cyber intelligence reports... ...Computer Science, Computer Engineering, Computer Information Systems...For contractors
$110k - $130k
Associate / IT Security Vulnerability Specialist (0036) OCT Consulting is a management and technology consulting firm that supports Federal Government clients. We provide... .... Articulate risk and impact to product, engineering and other business leaders with the ability to...Temporary work3 days per week$104k - $166k
Responsibilities The Vulnerability Management Analyst will support the Federal Aviation Administration... ..., ensuring compliance with federal security requirements, and contributing to a... ...Collaborate with FAA system owners, network engineers, developers, and operations teams to...Contract workLocal areaRemote workShift work$90k - $155k
...company. We’re a community of innovators, engineers, analysts and business professionals... ...to tackle the most complex national security challenges. For more than 20 years we... ...to join our team. ABSC is seeking a Vulnerability Management Analyst to join our team supporting...Contract workRemote workFlexible hours- ...Job Description Job Description Job Title: Security Engineer - Vulnerability Management Location: Washington, DC 20590 (onsite) Type: Contract... ..., reporting, and risk assessment processes to present cyber-related risks effectively. Troubleshoot issues associated...Contract workLocal area
$86.8k - $198k
...7 Enterprise Cybersecurity Vulnerability Analyst, Senior The Opportunity... ...facing vulnerabilities and security misconfigurations across the... ...serve as a vulnerability management resource supporting the company... ...cybersecurity teams in a Cyber Fusion Center (CFC) environment...Full timeContract workPart timeWork at officeLocal areaRemote work- Job Description AAC is seeking Senior Security Analyst focusing on Vulnerability Management to join our security compliance team. In this role, you... ...Requires bachelor's degree in computer science, cyber security, engineering, or a related technical field. Additional...Work experience placement3 days per week
- ...across a broad range of cyber mission areas. OneZero full... ...and Senior Information Security Analysts in operating the Risk Management Framework and continuous... ...ISSO validation.Review vulnerability and compliance scan... ...requires an OpenNet account, DoS PIV badge, multifactor...CSSFull timeLocal areaRemote workMonday to FridayFlexible hours
- ...across a broad range of cyber mission areas. OneZero... ...: Senior Information Security AnalystLocation:... ...more than 30 days.Review vulnerability, KEV, CVE, and STIG results... ..., POA&M lifecycle management.Reading Tenable/Nessus... ...requires an OpenNet account, DoS PIV badge, multifactor...CSSFull timeContract workFor contractorsWork at officeLocal areaRemote workMonday to FridayFlexible hours
- ...design and frontend engineering role for someone who... ...TypeScript, and Tailwind CSS . Work directly with... ...constraints, security, and delivery timelines... ...applications, workflow management, or large-scale data platforms... ...working in Agile, DevSecOps, platform engineering,...CSS
- ...Specialist to support the day-to-day management, measurement, and... ...to support the reliability, security, and performance of Shatterproof... ...security, platform updates, vulnerability remediation, backup processes... ...Working knowledge of HTML and CSS; familiarity with JavaScript...CSSFull time
- ...enthusiastic team of developers and engineers in an Agile environment to... ...and tasks using workflows - manage data flows from the customer... ...languages like HTML/CSS, JavaScript, and data models... ...Experience with CI/CD integrations, DevSecOps and security-in-the-pipeline, and code...CSSRemote work
$120k - $260k
...highly experienced Senior Staff Security Engineer to lead the strategy and technical execution of Vulnerability Management and Offensive Security... ...controls into CI/CD pipelines and DevSecOps workflows. Education :... ...in computer science, Cyber Security, or equivalent education...Hourly payWork experience placementLocal area$130k - $150k
...Job Title: Cyber Security Engineer Location: Ft Meade, MD/Hybrid Clearance... ..., application teams, DevSecOps engineers, and operations... ...compliance, identify and remediate vulnerabilities, support continuous... ...FISMA, RMF, vulnerability management, continuous monitoring, and...Full timeFlexible hours$145k - $165k
...Senior Cybersecurity Engineer Role Summary The Senior... ...environment remains secure, compliant, and... ...incident response, risk management, and continuous improvement... ...systems. Conduct vulnerability assessments,... ...Trust Architecture and DevSecOps practices. Preferred...Full timeLocal area$90k - $120k
...Description Job Title: Senior Cyber Security Engineer Location: Washington,... ...We specialize in FX risk management and international payments... ...through Secure Score, vulnerability management, compliance reporting... ...or Python automation, and DevSecOps methodologies. ~ Strong...Full timeSummer workWork at officeLocal areaWorldwideMonday to Friday$140k - $145k
...looking for a Software Engineer - Team Lead to support... ...modernization, and sustainment of secure applications across DoD... ..., CI/CD pipelines, and DevSecOps practices, ensuring... ...Design, implement, and manage automated build, test,... ..., JavaScript, (X)HTML, CSS, Knockout. Azure,...CSSFull timePart timeFor contractorsRemote work$135k - $155k
...Methods Web Developer Security EngineerSpry... ...cybersecurity, and program management solutions... ...solutions across cyber operations,... ...Developer Security Engineer protects mission-... ...software development, vulnerability remediation,... ...software development, DevSecOps automation, and...Full timeContract workWorldwide$154.05k - $278.48k
...exciting opportunity for Cyber Security Engineer—Technical Lead in our Intel... ...SIGINT), and Cryptographic Key Management. At Leidos, we offer... ...Technical Leads throughout a DevSecOps life cycle both on policy... ...and do not introduce new vulnerabilities.Conduct routine vulnerability...Full timeImmediate startFlexible hours- ...Provide project and product oversight while managing application development schedules based... ...issues to maintain the performance and security of web applications. •Stay up-to-date... ...development technologies. •Proficiency in HTML, CSS, JavaScript, and other relevant...CSS
- A leading cybersecurity consultancy is seeking a Cybersecurity Vulnerability Analyst based in Arlington, VA. The role requires an active Top Secret Security Clearance and 5+ years of experience, focusing on vulnerability analysis for federal clients. Candidates must exhibit...
- Arete Associates in Falls Church, VA is seeking a Vulnerability Management Analyst to own the end-to-end remediation cycle from scanning to verification across desktops, servers, and networks. The role requires hands-on patching, risk-based prioritization, and coordination...
- ...cybersecurity, data analytics, strategic communications, event management, training, and program management. With over 15 years of proven... ...frameworks like React, Angular, or Ember Proficiency in HTML, CSS/SASS, and Bootstrap Experience designing unit, integration,...CSSRemote jobHourly payFull timeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Security Engineer (Vulnerability Management & DevSecOps) DoS CSS. Be the first to apply!


