Cybersecurity Engineer II
Job Description
DirectViz Solutions (DVS) is seeking a Cybersecurity Engineer II to support Department of the Navy cybersecurity compliance efforts. The role will focus on system hardening, vulnerability management, continuous monitoring support, and system authorization activities, including DoD-mandated scanning and STIG compliance checks. This onsite position is based in Virginia Beach, VA.
What you’ll do
- Perform system hardening aligned to applicable DoD and Navy cybersecurity requirements.
- Run DoD-mandated vulnerability assessments using ACAS.
- Conduct SCAP scans and execute automated STIG compliance checks.
- Implement and assess DISA STIG requirements across relevant environments.
- Review quarterly STIG releases and evaluate system and operational impacts.
- Support ATO audits, Annual Security Reviews, and activities related to continuous monitoring.
- Analyze ACAS, SCAP, and STIG findings and develop or update POA&M entries.
- Track cybersecurity vulnerabilities through remediation to closure.
- Remediate vulnerability findings, including applying vendor patches on Linux and Windows operating systems.
- Apply Security Management policy guidance and directives to cybersecurity activities.
- Support day-to-day cybersecurity operations and maintenance of network, server, and hardware resources.
- Administer, secure, patch, and troubleshoot Red Hat Enterprise Linux (RHEL) 8, 9, and 10 in line with approved configuration baselines and cybersecurity requirements.
- Maintain Assess Only authorization and accreditation packages, including evidence, assessment artifacts, control documentation, findings, and package updates to support an accurate authorization posture.
- Plan, coordinate, implement, and verify infrastructure patching and network device IOS upgrades, documenting changes and validating remediation while assessing operational impact.
- Apply, assess, document, and remediate applicable DISA STIG requirements across network systems, network devices, servers, and endpoint configurations.
- Coordinate with technical and cybersecurity stakeholders to address compliance findings and maintain system security posture.
Requirements
- Bachelor’s degree in Cybersecurity, Cyber Operations, Cyber Engineering, Information Systems, Information Technology, Computer/Electrical/Electronics Engineering, Software Engineering, Computer Science, Mathematics (concentration in Computer Science), or an equivalent discipline.
- 5 years of full-time professional experience performing system hardening.
- OR High school diploma/GED plus ten years of experience.
- Demonstrated experience implementing STIGs, performing ACAS vulnerability assessments, applying Security Management policy guidance/directives, and remediating vulnerabilities including vendor patches on Linux and Windows.
- Hands-on experience administering, hardening, patching, and troubleshooting RHEL 8 and RHEL 9; RHEL 10 experience is required or must be current enough to support transition and sustainment activities.
- Experience maintaining Assess Only authorization and accreditation packages and supporting cybersecurity assessment and authorization documentation throughout the lifecycle.
- Working knowledge of infrastructure patch management and network device IOS management, including planning, validation, rollback considerations, and documentation.
- Experience applying and assessing DISA STIGs across network systems/devices and server/endpoint configurations, including documentation and remediation of findings.
- Certifications: IAT Level II (one of the following): CCNA Security, CySA+, GICSP, GSEC, Security+CE, CND, or SSCP.
- SECRET clearance required.
Technologies
- ACAS
- SCAP
- DISA STIG
- POA&M
- Red Hat Enterprise Linux (RHEL) 8
- Red Hat Enterprise Linux (RHEL) 9
- Red Hat Enterprise Linux (RHEL) 10
- IOS
- Linux
- Windows
Compensation and benefits
- Salary: USD 95,000 - 115,000 per year
- Competitive compensation
- Comprehensive medical benefits
- 401(k) match
- Generous PTO accrual
- Professional development reimbursement
- Corporate-funded technology certifications
- Robust employee recognition and appreciation programs
Physical and mental qualifications
- Maintain focus and awareness throughout scheduled working hours.
- Perform tasks requiring prolonged periods of sitting or standing at a desk, using a computer, mouse, and keyboard.
- Lift and move objects weighing up to 15 pounds as needed.
- Exhibit excellent verbal and written communication skills with a strong command of English.
- Work independently and collaborate effectively as part of a team.
- Quickly learn and retain routine tasks and processes.
- Demonstrate strong organizational skills, attention to detail, business correspondence proficiency, and self-management capabilities.
- Perform essential functions satisfactorily; reasonable accommodation will be provided upon request for employees with disabilities.
- Accept and adapt to additional responsibilities or changes to assigned duties as determined by DirectViz Solutions (DVS).
Location: VA Beach/Dam Neck (onsite)
Clearance: Secret (required)