Support DOMEX Technology Platform contract task orders by designing, developing, and implementing secure systems across on-premises infrastructure while integrating security across the system lifecycle.
Responsibilities
- Support secure architecture, design, and implementation of DoD systems in line with DoDI , NIST SP 800-53 , and other DoD security guidance.
- Lead integration of RMF activities into the SDLC , including selection, implementation, and validation of security controls.
- Develop and maintain SSPs , SARs , risk assessments, and POA&Ms .
- Apply STIGs and validate compliance using SCAP , STIG Viewer , and ACAS .
- Maintain vulnerability scanning infrastructure, analyze vulnerabilities, and support mitigation or risk acceptance decisions.
- Support system authorization, incident response, forensics analysis, and security automation efforts.
Requirements
- Active TS/SCI with ability to obtain a CI Polygraph .
- Bachelor’s degree and minimum 6 years of experience in the category field; 3 additional years of experience may substitute for the bachelor’s degree.
- At least one DoD -M IASAE Level II certification: CISSP , CISSP-ISSAP , CISSP-ISSEP , CSSLP , or CASP+ CE .
- Developer experience preferred in at least one scripting or programming language.
- Experience reviewing cybersecurity vulnerabilities for risk and relevance, and building mitigation or remediation plans across systems, network, application, and database vulnerabilities.
- Ability to architect, design, troubleshoot, maintain, and deploy vulnerability scanning solutions such as OWASP , Fortify , SonarQube , and Tenable .
- Experience with XACTA , eMASS , or similar tools.
- Strong understanding of Microsoft Windows and Linux/UNIX operating systems.
- Experience with middleware and web technologies, databases, TCP/IP networking, and CI/CD platforms.
- Familiarity with NIST 800-171 , NIST 800-172 , NIST SSDF , CMMC , and CNSSI 1253 .
- Experience supporting DoD/IC systems through the RMF+ process.
Technologies
- DoDI
- NIST SP 800-53
- RMF, RMF+
- SDLC
- STIGs
- SCAP, STIG Viewer, ACAS
- OWASP, Fortify, SonarQube, Tenable
- XACTA, eMASS
- Microsoft Windows, Linux/UNIX
- TCP/IP, CI/CD
- NIST 800-171, NIST 800-172, NIST SSDF
- CMMC, CNSSI 1253
- CISSP, CISSP-ISSAP, CISSP-ISSEP, CSSLP, CASP+ CE
Preferred Qualifications
- Software development experience with Python , Java , or React .
- Experience successfully achieving ATO under RMF+ .
- Experience with big data applications.
- Experience with GitLab , Jira , and Confluence .
- Experience in Agile environments.
- Experience with OIDC or OAuth2 .
- Experience with Kubernetes , Rancher , Strimzi , Cloudera , Active Directory , and scripting languages such as Bash , Python , or PowerShell .
Required Education and Experience Equivalency
- High School Diploma/GED with 9 years of experience.
- Associate’s Degree with 9 years of experience.
- Bachelor’s Degree with 6 years of experience.
- Master’s Degree with 6 years of experience.
- PhD with 6 years of experience.
Benefits
- 100% company-paid medical premiums for employees and eligible dependents (CareFirst, Kaiser, UnitedHealthcare options including PPO, POS, HMO, and HSA-compatible plans).
- 100% company-paid dental premiums for employees and eligible dependents.
- 100% company-paid vision premiums for employees and eligible dependents.
- 100% company-paid premiums for short-term disability.
- 100% company-paid premiums for long-term disability.
- 100% company-paid premiums for accidental death & dismemberment (AD&D).
- 100% company-paid premiums for life insurance up to $200,000 .
- 401(k) with immediate vesting: 4% company match plus 4% non-elective company contribution (8% total).
- 401(k) pre‑tax and Roth options.
- Up to 20 days flexible paid time off (PTO).
- 11 paid floating holidays.
- Flexible work schedules, including flex time and compressed work periods (contract and project‑dependent).
- Employee referral bonuses up to $10,000 per hired referral.
- Additional bonus opportunities for exceptional performance and contributions to business development and company growth (role‑dependent).
Compensation
- Competitive fixed salary or hourly pay (based on experience, skills, location, and internal equity).
- Employee referral bonuses up to $10,000 per hired referral.
- Additional bonus opportunities for exceptional performance and contributions to business development and company growth (role‑dependent).
Cyber Security Engineer 3 in bethesda at Unknown Company
This position is listed as contract and onsite.