> Markdown version of [/jobs/ext/1217417-cybersecurity-engineer](https://www.wearedevelopers.com/jobs/ext/1217417-cybersecurity-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Engineer - **Company:** All In Solutions, LLC - **Location:** United States (Remote available) - **Experience:** Experienced - **Salary:** $150,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Access Network, Agile Methodology, Amazon Web Services, Software System Penetration Testing, User Authentication, Automation of Tests, Cloud Computing Security, Cyber Security, Information Systems, Multi-Factor Authentication, Federal Information Processing Standards (FIPS), Identity and Access Management, IT Management, Key Management, Network Security, Scrum Methodology, Red Team (Cyber Security), Zero Trust Network Access, Data Streaming, Software Vulnerability Management, Cloud Platform System, Amazon Virtual Private Cloud (VPC), Kubernetes, Tenable Nessus, Hashicorp, Firewall Services Module, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** July 9, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=c4731364e6e60aba ## About the Role * Demonstrated experience in cybersecurity engineering for complex, mission-critical cloud platforms in Federal or enterprise environments * Hands-on experience implementing security controls in AWS cloud environments including EKS, IAM, KMS, security groups, VPC security, and encryption services * Experience integrating SAST, DAST, SCA, and container scanning tools into CI/CD pipelines * Deep knowledge of Zero Trust Architecture principles and implementation practices * Experience with container security including image scanning, runtime protection, and Kubernetes security policies * Hands-on experience with secrets management tools (AWS Secrets Manager, HashiCorp Vault, Kubernetes secrets) * Knowledge of FIPS 140-3 cryptographic requirements and their implementation in cloud environments * Experience with NIST SP 800-53 Rev. 5 security controls implementation and validation * Familiarity with penetration testing, red team methodologies, and vulnerability remediation practices * Experience with incident response including forensic analysis, evidence collection, and corrective action development * Knowledge of Federal identity and access management requirements including FICAM, PIV, and multi-factor authentication * Experience with firewall configuration, network security, and secure external connections in Federal cloud environments * Knowledge of HIPAA, Privacy Act, FISMA, and Federal data protection requirements * Experience working in Agile or SAFe environments with sprint-based delivery cadences * CISSP, CEH, GIAC, or equivalent cybersecurity certification required * AWS Security Specialty or equivalent cloud security certification preferred * Certified Kubernetes Security Specialist (CKS) or equivalent certification preferred * Bachelor's Degree from an accredited academic institution with a minimum of 5 years of experience in cybersecurity engineering, with at least 2 years implementing security controls for cloud-native platforms in Federal or enterprise IT environments * OR * Associate's Degree from an accredited academic institution with a minimum of 7 years of experience in cybersecurity engineering, with at least 3 years implementing security controls for cloud-native platforms in Federal or enterprise IT environments * Plus: * Department of Veterans Affairs (VA) experience * Active Personal Identity Verification (PIV) card * Experience with VA Critical Security Controls and VA Handbook 6500 security requirements * Experience implementing security controls across multi-tenant authorization boundaries * Experience with VA-specific security tools and governance processes including SNOWCAM, TRM, and BPE, * cybersecurity engineering: 5 years (Required) ## Description * Implement and maintain required NIST security controls in accordance with the approved baseline across all platform environments * Integrate Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), container scanning, and Infrastructure as Code scanning into CI/CD pipelines * Ensure vulnerabilities identified through scanning are remediated within Government-defined timelines * Enforce secure coding standards and approved dependency management practices across all platform development activities * Implement and maintain Zero Trust Architecture principles and least-privilege access controls across all platform components and tenant boundaries * Configure and manage container security including image signing, vulnerability scanning, runtime protection, and registry security * Implement and operate centralized secrets management ensuring automated rotation for 100% of production secrets where automation is supported * Support zero-trust and least-privilege principles in pipeline and deployment configurations * Validate security control effectiveness through automated testing, configuration validation, and periodic assessments * Support penetration testing, red team activities, and independent security assessments as required * Implement and maintain encryption in transit and at rest across all platform data flows, storage, and backup assets using FIPS 140-3 validated cryptographic modules * Configure and manage independent per-region KMS keys for multi-region deployments ensuring a compromise in one region does not affect data confidentiality in the other * Support cybersecurity incident response activities in coordination with VA security operations including forensic analysis, root cause determination, and corrective action planning * Implement and maintain firewall configurations, security group definitions, and network access controls in accordance with VA security policies * Support continuous monitoring activities including configuration validation, security event correlation, and anomaly detection * Ensure all platform components comply with VA Critical Security Controls and are authorized for use prior to connection to the VA network * Support FICAM requirements including PIV-based authentication, automated provisioning, and Identity/Authenticator/Federation Assurance Level compliance * Contribute to security documentation including Security Impact Assessments, Information System Vulnerability Management Plans, Security Assessment Plans, and Security Assessment Reports * Participate in security audits and assessments providing technical evidence, documentation, and remediation support * Participate in Agile and SAFe ceremonies including sprint planning, backlog refinement, demos, and retrospectives ## Related Videos - [Securing Secrets in the GitOps era](https://www.wearedevelopers.com/videos/546-securing-secrets-in-the-gitops-era) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Securing secrets in the GitOps Era](https://www.wearedevelopers.com/videos/852-securing-secrets-in-the-gitops-era) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Learning Kubernetes made easy with KubeCampus](https://www.wearedevelopers.com/magazine/348-learning-kubernetes-made-easy-with-kubecampus) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)