EngineerJobs.io
← Back to all jobs

Job Description

Support CBP OTOC and ISS OTOC build-out work through cybersecurity engineering, risk management, and RMF/ATO lifecycle support for complex OT and mission systems.

Responsibilities

  • Provide cybersecurity engineering support for integration, deployment, authorization, and sustainment of complex OTOC operational technology and mission systems.
  • Translate mission, operational, and system requirements into cybersecurity requirements and secure system architectures.
  • Review system designs, architectures, configurations, interfaces, and dependencies to identify cybersecurity risks, vulnerabilities, and attack surfaces.
  • Embed cybersecurity requirements into system design, development, testing, integration, deployment, and sustainment activities.
  • Advise on cybersecurity for applications, data platforms, tactical communications systems, mission networks, and authorized effectors.
  • Coordinate with cross-functional engineering teams to resolve cybersecurity issues while maintaining mission performance, availability, interoperability, and operational requirements.
  • Perform vulnerability identification, analysis, prioritization, remediation support, and tracking across applications, infrastructure, networks, and operational technology environments.
  • Assess vulnerabilities in the context of architecture, mission impact, threat exposure, and operational risk.
  • Analyze security findings and communicate clear, actionable risk information to system owners, engineers, and program leadership.
  • Propose risk mitigation strategies and support implementation of security controls and corrective actions.
  • Track security deficiencies and remediation activities to resolution, ensuring risks are mitigated, accepted, or otherwise managed.
  • Support cybersecurity incident activities including identification, analysis, investigation, containment, remediation, and recovery affecting mission systems and OT environments.
  • Collaborate with cybersecurity operations, engineering, and program teams to evaluate technical and operational incident impact and execute corrective actions.
  • Support post-incident analysis and lessons learned, applying findings to vulnerability management, security controls, system architecture, and risk mitigation.
  • Support incident response exercises, technical investigations, and recovery efforts as required.
  • Participate in Risk Management Framework (RMF) activities across the system lifecycle, including security categorization, control implementation, assessment, remediation, and continuous monitoring.
  • Support development, maintenance, and execution of Authorization to Operate (ATO) activities and related authorization artifacts.
  • Develop and maintain cybersecurity documentation such as risk assessments, security plans, POA&Ms, control assessments, vulnerability assessments, and ATO documentation.
  • Support cybersecurity assessments, audits, inspections, and technical reviews related to system authorization and operational deployment.
  • Support continuous monitoring and ongoing authorization activities to maintain security, compliance, operational viability, and supportability.
  • Serve as a technical cybersecurity advisor to systems engineering, software, infrastructure, operations, cybersecurity, and program leadership teams.
  • Provide cybersecurity expertise from requirements and architecture through integration, authorization, deployment, and sustainment.
  • Incorporate cybersecurity considerations into technical and operational decision-making with engineering and program teams.
  • Stay current with applicable cybersecurity standards, RMF requirements, vulnerability management practices, emerging threats, and mission/OT-relevant cybersecurity technologies.
  • Apply evolving cybersecurity practices and threat information to support risk-informed security decisions and system protection.

Requirements

  • Current DHS Suitability or the ability to obtain and maintain suitability.
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Systems Engineering, or a related technical discipline; equivalent directly relevant professional experience may be substituted.
  • 5+ years of experience in cybersecurity engineering, information security, systems engineering, vulnerability management, or a closely related field.
  • Experience supporting mission-critical environments with high availability, real-time communications, operational constraints, or other demanding performance requirements.
  • Experience with cybersecurity engineering, vulnerability management, risk assessment, and security architecture across complex systems, applications, infrastructure, networks, or OT environments.
  • Experience supporting cybersecurity incident response: incident analysis, investigation, containment, remediation, recovery, and post-incident activities.
  • Experience applying FISMA, NIST cybersecurity guidance, and RMF to government information systems.
  • Experience supporting the security assessment and authorization/ATO lifecycle, including security control implementation, assessment, remediation, authorization, and continuous monitoring.
  • Experience developing and maintaining System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), Security Assessment Reports (SARs), control implementation statements, authorization evidence, system inventories, network diagrams, and data-flow diagrams.
  • Ability to analyze technical vulnerabilities and security findings, determine operational and mission impact, and develop risk-based remediation/mitigation strategies.
  • Experience translating mission and operational requirements into cybersecurity requirements and practical security controls.
  • Experience working with system owners, engineers, authorizing officials, security leadership, program managers, and senior government stakeholders to resolve risks and support authorization decisions.
  • Ability to communicate complex cybersecurity risks and technical findings to technical and non-technical audiences.

Technologies

  • RMF
  • Authorization to Operate (ATO)
  • FISMA
  • NIST
  • System Security Plans (SSPs)
  • Plans of Action and Milestones (POA&Ms)
  • Security Assessment Reports (SARs)

Preferred Qualifications

  • Cybersecurity certification such as CISSP, CISM, Security+, GSEC, or equivalent (equivalent demonstrated experience may be considered where permitted).
  • Experience with government security authorization, RMF, vulnerability management, and continuous monitoring platforms/tools.
  • Familiarity with security operations and monitoring technologies including SIEM, EDR/XDR, IDS/IPS, threat intelligence, security analytics, and incident response platforms.
  • Familiarity with Zero Trust architecture and identity-centric security, including IAM, PAM, endpoint security, threat detection, and access control.
  • Experience supporting incident response exercises, tabletop exercises, after-action reviews, and remediation activities.
  • Experience with cloud security and hybrid infrastructure (AWS, Azure, or other government-authorized cloud environments).
  • Experience integrating cybersecurity into DevSecOps, software development, CI/CD, or automated security testing environments.
  • Experience assessing software, hardware, third-party, and supply-chain cybersecurity risks.
  • Experience supporting FISMA reporting, federal cybersecurity assessments, agency cybersecurity policies, governance processes, and compliance activities.
  • Experience developing or reviewing security architectures, system boundaries, system interconnections, attack surfaces, threat models, and cybersecurity requirements.

Location

  • Ashburn, VA (onsite)

Travel Requirement

  • Less than 10%

Security Clearance

  • Must possess existing DHS EOD or DHS Suitability
  • Successful completion of a background screening/check/investigation will/may be required as a condition of hire.

Compensation

  • Salary range: USD 120,000 - 160,000 per yearly
  • Salary negotiations based on geographic location, prior experience, relevant skills, education, and certifications; range reflective across Sherpa 6 locations, years of experience, and skill levels.

Benefits

  • Medical coverage for you and your family
  • Dental and vision benefits
  • Health and wellness benefits
  • Generous retirement savings plan
  • Generous PTO policy
  • Sherpa 6 will make reasonable accommodations in compliance with the Americans with Disabilities Act 1990.
  • Sherpa 6 is an equal access/opportunity/affirmative action employer and does not discriminate based on race, color, national origin, sex, religion, age, disability, sexual orientation, gender identity, veteran status, height, weight, or marital status.

Similar Jobs