Cybersecurity Engineer
Job Description
This remote cybersecurity engineering role centers on implementing, validating, and maintaining security controls for a complex, mission-critical cloud platform hosted in AWS GovCloud. The position integrates security into the DevSecOps workflow, enforces Zero Trust Architecture, and ensures ongoing compliance with NIST, FISMA, FIPS, HIPAA, and VA requirements across diverse environments and authorization boundaries.
Overview
The role focuses on shaping and sustaining robust security practices across all platform environments, guiding secure development, deployment, and operation within a federal or enterprise cloud context.
Responsibilities
- Apply and sustain NIST security controls per the approved baseline across every platform environment.
- Incorporate SAST, DAST, SCA, container scanning, and Infrastructure as Code scanning into CI/CD workflows.
- Remediate vulnerabilities within government-defined timelines identified through scanning activities.
- Enforce secure coding standards and approved dependency management across all development activities.
- Implement and maintain Zero Trust Architecture principles and least-privilege access across all platform components and tenant boundaries.
- Configure and manage container security, including image signing, vulnerability scanning, runtime protection, and registry security.
- Operate centralized secrets management with automated rotation for production secrets where automation is supported.
- Support zero-trust and least-privilege practices in pipeline and deployment configurations.
- Validate security control effectiveness through automated testing, configuration validation, and periodic assessments.
- Assist with penetration testing, red team activities, and independent security assessments as required.
- Implement and maintain encryption in transit and at rest across data flows, storage, and backups using FIPS 140-3 validated modules.
- Configure per-region KMS keys for multi-region deployments to ensure compartmentalization of data confidentiality.
- Support cybersecurity incident response activities in coordination with VA security operations, including forensic analysis, root cause determination, and corrective action planning.
- Establish and maintain firewall configurations, security group definitions, and network access controls per VA security policies.
- Support continuous monitoring activities, including configuration validation, security event correlation, and anomaly detection.
- Ensure all platform components comply with VA Critical Security Controls and are authorized before connecting to the VA network.
- Support FICAM requirements including PIV-based authentication, automated provisioning, and Identity/Authenticator/Federation Assurance Level compliance.
- Contribute to security documentation such as Security Impact Assessments, Information System Vulnerability Management Plans, Security Assessment Plans, and Security Assessment Reports.
- Participate in security audits and assessments, providing technical evidence, documentation, and remediation support.
- Engage in Agile and SAFe ceremonies, including sprint planning, backlog refinement, demos, and retrospectives.
Qualifications and Requirements
- Proven cybersecurity engineering experience for complex, mission-critical cloud platforms in federal or enterprise environments.
- Hands-on experience implementing security controls in AWS cloud environments, including EKS, IAM, KMS, security groups, VPC security, and encryption services.
- Experience integrating SAST, DAST, SCA, and container scanning tools into CI/CD pipelines.
- Deep knowledge of Zero Trust Architecture principles and practical implementation.
- Experience with container security, including image scanning, runtime protection, and Kubernetes security policies.
- Hands-on experience with secrets management tools such as AWS Secrets Manager, HashiCorp Vault, and Kubernetes secrets.
- Knowledge of FIPS 140-3 cryptographic requirements and their cloud-based implementations.
- Experience implementing and validating NIST SP 800-53 Rev. 5 security controls.
- Familiarity with penetration testing, red team methodologies, and vulnerability remediation practices.
- Experience with incident response, including forensic analysis, evidence collection, and corrective action development.
- Knowledge of federal identity and access management requirements including FICAM, PIV, and multi-factor authentication.
- Experience with firewall configuration, network security, and secure external connections in federal cloud environments.
- Knowledge of HIPAA, Privacy Act, FISMA, and federal data protection requirements.
- Experience working in Agile or SAFe environments with sprint-based delivery cadences.
- CISSP, CEH, GIAC, or equivalent cybersecurity certification required.
- AWS Security Specialty or equivalent cloud security certification is preferred.
- Certified Kubernetes Security Specialist (CKS) or equivalent certification is preferred.
- Educational background: Bachelor's Degree required with a minimum of 5 years in cybersecurity engineering, including at least 2 years implementing security controls for cloud-native platforms in federal or enterprise IT environments. An Associate's Degree with at least 7 years of experience and 3 years implementing cloud-native security controls in similar settings is also acceptable.
Technologies
- AWS GovCloud
- AWS EKS, AWS IAM, AWS KMS
- AWS Secrets Manager
- HashiCorp Vault
- Kubernetes and Kubernetes secrets
- SAST, DAST, SCA
- Infrastructure as Code scanning
- SNOWCAM, TRM, BPE
- FIPS 140-3
- PIV-based authentication
Benefits
- Experience with Department of Veterans Affairs security programs
- Active Personal Identity Verification (PIV) card
- Familiarity with VA Critical Security Controls and VA Handbook 6500 security requirements
- Experience implementing security controls across multi-tenant authorization boundaries
- Proficiency with VA-specific tools and governance processes including SNOWCAM, TRM, and BPE
Compensation
Up to USD 150,000 per year
Experience
Minimum experience: 5 years in cybersecurity engineering. This includes at least 2 years implementing security controls for cloud-native platforms within federal or enterprise IT environments.
Work Location
Remote