Loading jobs…
Loading jobs…
SMX
The Cyber Security Engineer will provide security engineering, compliance, and risk management support for cloud-based systems aligned with NIST SP 800-53, FedRAMP, and DoD IL4–6
Requirements
. The role will advise partners and customers navigating government security
while supporting authorization, audit readiness, and continuous monitoring activities. A key focus will be improving compliance efficiency through GRC platforms, APIs, scripts, cloud-native services, and automation for evidence collection, control validation, documentation, reporting, and remediation tracking. This position is remote supporting a Herndon, VA based team.
Essential Skills • Provide cybersecurity engineering and compliance support for FedRAMP and DoD-authorized cloud environments, including IL4–6.
, authorization strategies, control implementation, and audit readiness. • Develop, review, and maintain authorization documentation, including SSPs, SAPs, SARs, POA&Ms, FedRAMP appendices, policies, and supporting evidence. • Support system authorization and reauthorization activities across FedRAMP/RMF, including gap assessments, control validation, evidence development, and remediation planning.
• Leverage GRC platforms, APIs, scripts, and automation to streamline compliance workflows, evidence collection, documentation updates, control testing, and reporting. • Develop repeatable and auditable processes that reduce manual compliance effort and improve the accuracy and consistency of authorization artifacts. • Collaborate with cloud engineering and DevOps teams to design, implement, and validate security controls across AWS, Azure, and hybrid environments.
• Review system changes and significant change requests to assess security impact, identify documentation updates, and maintain authorization boundaries. • Coordinate with system owners, engineers, 3PAOs, Authorizing Officials, and government stakeholders to address findings and support authorization outcomes. • Support continuous monitoring, vulnerability management, POA&M updates, remediation tracking, and recurring compliance deliverables.
• Evaluate security tooling and data sources to identify opportunities for automated control validation and compliance reporting.
and translate them into practical technical and operational actions. Required Skills & Experience • Strong analytical, documentation, and problem-solving skills with a focus on secure and compliant outcomes. • Excellent communication and stakeholder-management skills, including the ability to advise partners, customers, engineers, and government stakeholders.
into practical technical controls and operational processes. S. citizenship with the ability to obtain and maintain a Secret or higher security clearance.
• Bachelor’s degree in Information Security, Cybersecurity, Computer Science, or a related field, or equivalent practical experience. • Five or more years of cybersecurity experience, including at least three years supporting federal cloud security engineering, information assurance, RMF, or ISSO functions. • Knowledge of NIST SP 800-53 Rev.
5, FedRAMP Moderate and High, DoD IL4–6 overlays, RMF, and related federal compliance frameworks. • Experience developing and maintaining SSPs, POA&Ms, SARs, policies, control evidence, and other authorization artifacts. • Experience supporting authorization planning, gap assessments, audit readiness, control implementation, and remediation activities.
• Hands-on experience with AWS, Azure, or hybrid cloud environments, including IAM, encryption, logging, configuration management, and security monitoring. • Experience using GRC platforms, APIs, scripting, or automation to improve compliance and security workflows.