Cybersecurity Engineer

All Native Group
Washington, DC, United States
28 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Shift work

Tech stack

Amazon Web Services User Authentication Microsoft Azure Cloud Computing Cloud Computing Security CompTIA Security+ Cyber Security Identity and Access Management Role-Based Access Control Zero Trust Network Access Security Information and Event Management Software Vulnerability Management
+4 more
Data Logging Cloud Platform System Information Technology Vulnerability Analysis

Job description

All Native Group, a division of Ho Chunk, Incorporated, is seeking an exceptional Cybersecurity Engineer to design, implement, and maintain enterprise security controls that enforce Zero Trust principles across the Congressional Budget Office’s (CBO) cloud, network, and endpoint environments. The engineer strengthens CBO’s security posture and detection and response capabilities, supporting Incident Response remediation and alignment with NIST SP 800-53 and NIST SP 800-207., * Support the implementation, operation, and optimization of enterprise security platforms across cloud, on-premises, and hybrid environments.

  • Implement and maintain security controls aligned with NIST SP 800-53 (AC, CM, SC, AU, IR, and SI families) and NIST SP 800-207 Zero Trust Architecture.
  • Design and maintain least-privilege access controls including RBAC, PAM, and MFA across enterprise systems and applications.
  • Configure and manage IAM solutions with secure authentication, authorization, and enterprise identity provider integration.
  • Configure and maintain centralized logging, monitoring, and audit capabilities integrated with enterprise SIEM tools.
  • Monitor, analyze, and respond to security events using SIEM and EDR/XDR; support triage, containment, investigation, and remediation.
  • Conduct continuous monitoring, vulnerability assessments, and risk analysis; coordinate remediation aligned with the NIST RMF.
  • Harden systems, applications, and cloud environments (AWS, Azure) using secure configuration baselines.
  • Ensure security changes follow formal change management with documentation and security impact analysis.
  • Develop and maintain cybersecurity SOPs, configuration records, and asset inventories; perform root cause analysis for security incidents.
  • Support continuous, real-time (24/7) security monitoring and collaborate across network, cloud, and application teams, This position involves executive oversight of multiple program portfolios and senior management teams.

Requirements

  • Strong enterprise security engineering across cloud, network, and endpoint.
  • Hands-on SIEM and EDR/XDR operations and incident response.
  • IAM, PAM, and Zero Trust implementation skills.
  • Vulnerability management and RMF-aligned risk analysis.
  • Clear documentation and cross-team collaboration., * Minimum of 5 years of professional cybersecurity engineering experience in enterprise environments.
  • Demonstrated experience with SIEM and EDR/XDR platforms and incident response.
  • Experience implementing NIST SP 800-53 and NIST SP 800-207 controls.
  • Cloud security experience with AWS and/or Azure., Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent professional experience., * CompTIA Security+ required; one of CISSP, GIAC (e.g., GCIH/GCIA), or Certified Ethical Hacker (CEH) strongly preferred.

Certifications (or their equivalent prior certifications) should have been maintained for a minimum of 5 years. Expired certifications or certifications never used professionally will not be considered, Must be a U.S. citizen or permanent resident. Position requires a Public Trust Tier 2 clearance. Selected candidate must obtain favorable FBI criminal history and fingerprint checks conducted through the U.S. Capitol Police prior to starting work, and pass a background check to access the CBO network.

About the company

All Native Group is a Drug Free Workplace. It is our policy that all new hires must successfully complete a pre-employment drug screen as a condition of employment. In addition, all employees are subject to random drug screens throughout the term of their employment with All Native Group., All Native Group is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. However, preference may be extended to persons of Indian descent in accordance with applicable laws.

About Ho-Chunk, Inc. & All Native Group

Ho-Chunk, Inc. is an award-winning economic development corporation of the Winnebago Tribe of Nebraska. Our mission is to provide long-term economic development for the Winnebago Tribe and job opportunities for Tribal members.

All Native Group is a network of small businesses that support the critical missions of various U.S. Government customers. Our capabilities include telecommunications, health, logistics, specialized training, professional services, and IT solutions. Since earning our first federal contract in 2004, we have continued to grow and diversify our services while maintaining a strong commitment to excellence. As a tribally owned organization, All Native Group operates multiple subsidiary businesses, providing clients with the advantages of working with a small business while leveraging the resources and expertise of a larger, established company. Our work is guided by our core NATIVE values:

  • Native American Owned & Proud - Serving the Winnebago Tribe of Nebraska.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · WWC Europe 2026

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

1:06 min

Outline of free tools for Microsoft Azure

Radu Vunvulea Radu Vunvulea · WWC 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:56 min

Discovering incidents using logs, metrics, and traces

Nele Uhlemann · WWC 2023

Videos

See all

Related articles

See all