Cyber Security Engineer
Job Description
At LufCo, you will contribute to national security by enabling secure software integration within a DevSecOps framework for Army programs. This onsite role in Aberdeen, MD fosters collaboration between mission support and information assurance and provides a clear path for professional growth within a team of skilled engineers.
Benefits
- Impactful work supporting critical national security initiatives
- Access to cutting edge technology and security practices
- Clear opportunities for career growth and professional development
- Collaborative environment with experienced engineers
- Comprehensive benefits package
- Competitive pay
- Paid time off
- 401K contribution and employer match
- Medical, dental, and vision coverage
Compensation
Salary range: USD 85,000 to 130,000 per year.
Responsibilities
- Lead the DoD Risk Management Framework RMF process for Army programs, including maintaining the System Security Plan (SSP) and sustaining Authority to Operate (ATO) across the lifecycle
- Apply security controls by implementing STIGs on Linux and Windows to harden systems and ensure compliance
- Support continuous accreditation as part of a DevSecOps team, leveraging concepts such as IAVMs and Net-worthiness to maintain ongoing compliance
- Manage RMF packages within eMASS and assist security efforts in cloud environments
- Bridge cybersecurity with engineering by collaborating with software engineers and understanding CI/CD pipelines to securely integrate security into development
- Provide foundational system administration support to troubleshoot security issues in Linux and Windows environments
Requirements
- Active Secret clearance required, with ability to obtain TS/SCI with polygraph; US citizenship is required
- Bachelor's degree in a technical discipline
- 3+ years of experience as a cyber security engineer or in a role with related responsibilities
- Experience managing or supporting DoD RMF efforts
- Experience managing or supporting the System Security Plan and the Authority to Operate throughout the lifecycle
- Experience or familiarity with RMF documentation processes
- Knowledge of Cybersecurity concepts, Information Assurance Vulnerability Management (IAVM), Airworthiness, Safety, and Net-worthiness
- Experience applying RMF packages in the eMASS utility
- Experience applying STIG controls in Linux and Windows environments
- Understanding of cloud environments and related tools and workflows
- Familiarity with software engineering CI/CD pipelines
- Understanding authentication and authorization architectures and tool suites
- Basic system administration experience in Linux and Windows
Technologies
- RMF, eMASS, STIGs
- Linux, Windows
- CI/CD pipelines
- Cloud environments
Physical Requirements
- Ability to travel as required
- Standard office environment with occasional visits to client sites, labs, or field environments