Cybersecurity Engineer
Ashburn, VA
Contracted
Mid Level
About the Role
We are seeking a Cybersecurity Engineer to provide engineering, operational, and advisory support to secure, sustain, and enhance the enterprise cybersecurity environment. In this role, you will design, implement, and maintain enterprise security controls that enforce Zero Trust principles, including identity-centric access, least privilege enforcement, and continuous monitoring. You will ensure that all security technologies—across cloud platforms, identity services, endpoints, and networks—are properly configured, hardened, and continuously monitored in accordance with federal security standards (NIST SP 800-53 and NIST SP 800-207) and industry best practices.
Key Responsibilities
- Security Architecture & Compliance: Implement and maintain enterprise security controls aligned with NIST SP 800-53 (AC, CM, SC, AU, IR, and SI families). Enforce Zero Trust Architecture principles (NIST SP 800-207) across cloud, network, and endpoint environments.
- Identity & Access Management (IAM): Design and manage least-privilege access controls, including Role-Based Access Control (RBAC), Privileged Access Management (PAM), and Multi-Factor Authentication (MFA). Secure authentication and integration with enterprise identity providers.
- Threat Detection & Incident Response: Monitor, analyze, and respond to security events using enterprise tools (SIEM, EDR/XDR). Support incident triage, containment, forensic data collection, reporting, and Root Cause Analysis (RCA).
- Vulnerability & Risk Management: Conduct continuous security monitoring and vulnerability assessments in alignment with the NIST Risk Management Framework (RMF). Coordinate patch management and mitigate vulnerabilities across systems, infrastructure, and applications.
- Cloud & Enterprise SecOps: Secure hybrid and cloud environments (e.g., AWS, Azure), including configuring security services, network protections, and workload security. Implement segmentation to limit lateral movement. Harden systems and disable unnecessary services using secure configuration baselines.
- Monitoring & Logging: Configure and maintain centralized logging, continuous monitoring, and audit capabilities. Ensure integration with enterprise SIEM tools and adherence to log retention policies.
- Change Management & Documentation: Develop, implement, and update cybersecurity Standard Operating Procedures (SOPs). Ensure all security changes follow formal change management processes and maintain accurate system configurations, baselines, and asset inventories for audit readiness.
- Collaboration: Serve as a technical resource for advanced security-related service desk tickets and collaborate with network, cloud, and application teams to resolve complex challenges.
Required Technical Qualifications
- Frameworks & Standards: Deep understanding and practical experience with federal cybersecurity frameworks, specifically NIST SP 800-53, NIST SP 800-207 (Zero Trust), and NIST RMF.
- Security Tooling: Hands-on experience operating enterprise security platforms, including SIEM and EDR/XDR solutions.
- Cloud Security: Proven experience securing public cloud and hybrid environments, specifically AWS and Azure.
- IAM & Access Controls: Expertise in configuring and managing RBAC, PAM, and MFA solutions.
- Operations & Remediation: Strong background in vulnerability management, patch coordination, system hardening, and incident response.
- Process & Compliance: Experience participating in formal change management, conducting security impact analyses, and authoring technical SOPs.
Apply for this position
Required*