Cybersecurity Engineer
Data Security
Facilities Management
Information Security
InfoSec
Management
Project Management
Risk Governance
Risk Management
Rmf
Security
Security Clearance
Security Compliance
Security Engineer
Security Engineering
Security Operations
Security Operations Center
Security Standards
Security Testing
Solution Architecture
Job Description
Support CBP OTOC and ISS OTOC build-out work through cybersecurity engineering, risk management, and RMF/ATO lifecycle support for complex OT and mission systems.
Responsibilities
- Provide cybersecurity engineering support for integration, deployment, authorization, and sustainment of complex OTOC operational technology and mission systems.
- Translate mission, operational, and system requirements into cybersecurity requirements and secure system architectures.
- Review system designs, architectures, configurations, interfaces, and dependencies to identify cybersecurity risks, vulnerabilities, and attack surfaces.
- Embed cybersecurity requirements into system design, development, testing, integration, deployment, and sustainment activities.
- Advise on cybersecurity for applications, data platforms, tactical communications systems, mission networks, and authorized effectors.
- Coordinate with cross-functional engineering teams to resolve cybersecurity issues while maintaining mission performance, availability, interoperability, and operational requirements.
- Perform vulnerability identification, analysis, prioritization, remediation support, and tracking across applications, infrastructure, networks, and operational technology environments.
- Assess vulnerabilities in the context of architecture, mission impact, threat exposure, and operational risk.
- Analyze security findings and communicate clear, actionable risk information to system owners, engineers, and program leadership.
- Propose risk mitigation strategies and support implementation of security controls and corrective actions.
- Track security deficiencies and remediation activities to resolution, ensuring risks are mitigated, accepted, or otherwise managed.
- Support cybersecurity incident activities including identification, analysis, investigation, containment, remediation, and recovery affecting mission systems and OT environments.
- Collaborate with cybersecurity operations, engineering, and program teams to evaluate technical and operational incident impact and execute corrective actions.
- Support post-incident analysis and lessons learned, applying findings to vulnerability management, security controls, system architecture, and risk mitigation.
- Support incident response exercises, technical investigations, and recovery efforts as required.
- Participate in Risk Management Framework (RMF) activities across the system lifecycle, including security categorization, control implementation, assessment, remediation, and continuous monitoring.
- Support development, maintenance, and execution of Authorization to Operate (ATO) activities and related authorization artifacts.
- Develop and maintain cybersecurity documentation such as risk assessments, security plans, POA&Ms, control assessments, vulnerability assessments, and ATO documentation.
- Support cybersecurity assessments, audits, inspections, and technical reviews related to system authorization and operational deployment.
- Support continuous monitoring and ongoing authorization activities to maintain security, compliance, operational viability, and supportability.
- Serve as a technical cybersecurity advisor to systems engineering, software, infrastructure, operations, cybersecurity, and program leadership teams.
- Provide cybersecurity expertise from requirements and architecture through integration, authorization, deployment, and sustainment.
- Incorporate cybersecurity considerations into technical and operational decision-making with engineering and program teams.
- Stay current with applicable cybersecurity standards, RMF requirements, vulnerability management practices, emerging threats, and mission/OT-relevant cybersecurity technologies.
- Apply evolving cybersecurity practices and threat information to support risk-informed security decisions and system protection.
Requirements
- Current DHS Suitability or the ability to obtain and maintain suitability.
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Systems Engineering, or a related technical discipline; equivalent directly relevant professional experience may be substituted.
- 5+ years of experience in cybersecurity engineering, information security, systems engineering, vulnerability management, or a closely related field.
- Experience supporting mission-critical environments with high availability, real-time communications, operational constraints, or other demanding performance requirements.
- Experience with cybersecurity engineering, vulnerability management, risk assessment, and security architecture across complex systems, applications, infrastructure, networks, or OT environments.
- Experience supporting cybersecurity incident response: incident analysis, investigation, containment, remediation, recovery, and post-incident activities.
- Experience applying FISMA, NIST cybersecurity guidance, and RMF to government information systems.
- Experience supporting the security assessment and authorization/ATO lifecycle, including security control implementation, assessment, remediation, authorization, and continuous monitoring.
- Experience developing and maintaining System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), Security Assessment Reports (SARs), control implementation statements, authorization evidence, system inventories, network diagrams, and data-flow diagrams.
- Ability to analyze technical vulnerabilities and security findings, determine operational and mission impact, and develop risk-based remediation/mitigation strategies.
- Experience translating mission and operational requirements into cybersecurity requirements and practical security controls.
- Experience working with system owners, engineers, authorizing officials, security leadership, program managers, and senior government stakeholders to resolve risks and support authorization decisions.
- Ability to communicate complex cybersecurity risks and technical findings to technical and non-technical audiences.
Technologies
- RMF
- Authorization to Operate (ATO)
- FISMA
- NIST
- System Security Plans (SSPs)
- Plans of Action and Milestones (POA&Ms)
- Security Assessment Reports (SARs)
Preferred Qualifications
- Cybersecurity certification such as CISSP, CISM, Security+, GSEC, or equivalent (equivalent demonstrated experience may be considered where permitted).
- Experience with government security authorization, RMF, vulnerability management, and continuous monitoring platforms/tools.
- Familiarity with security operations and monitoring technologies including SIEM, EDR/XDR, IDS/IPS, threat intelligence, security analytics, and incident response platforms.
- Familiarity with Zero Trust architecture and identity-centric security, including IAM, PAM, endpoint security, threat detection, and access control.
- Experience supporting incident response exercises, tabletop exercises, after-action reviews, and remediation activities.
- Experience with cloud security and hybrid infrastructure (AWS, Azure, or other government-authorized cloud environments).
- Experience integrating cybersecurity into DevSecOps, software development, CI/CD, or automated security testing environments.
- Experience assessing software, hardware, third-party, and supply-chain cybersecurity risks.
- Experience supporting FISMA reporting, federal cybersecurity assessments, agency cybersecurity policies, governance processes, and compliance activities.
- Experience developing or reviewing security architectures, system boundaries, system interconnections, attack surfaces, threat models, and cybersecurity requirements.
Location
- Ashburn, VA (onsite)
Travel Requirement
- Less than 10%
Security Clearance
- Must possess existing DHS EOD or DHS Suitability
- Successful completion of a background screening/check/investigation will/may be required as a condition of hire.
Compensation
- Salary range: USD 120,000 - 160,000 per yearly
- Salary negotiations based on geographic location, prior experience, relevant skills, education, and certifications; range reflective across Sherpa 6 locations, years of experience, and skill levels.
Benefits
- Medical coverage for you and your family
- Dental and vision benefits
- Health and wellness benefits
- Generous retirement savings plan
- Generous PTO policy
- Sherpa 6 will make reasonable accommodations in compliance with the Americans with Disabilities Act 1990.
- Sherpa 6 is an equal access/opportunity/affirmative action employer and does not discriminate based on race, color, national origin, sex, religion, age, disability, sexual orientation, gender identity, veteran status, height, weight, or marital status.