> Markdown version of [/jobs/ext/1364133-senior-cybersecurity-engineer-specialist](https://www.wearedevelopers.com/jobs/ext/1364133-senior-cybersecurity-engineer-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SENIOR CYBERSECURITY ENGINEER SPECIALIST - **Company:** Concurrent Technologies Corporation - **Location:** Johnstown, PA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Amazon Web Services, Apple Mac Systems, Microsoft Azure, Microsoft Online Services, Business Systems, Command-Line Interface, Cloud Computing, Cloud Computing Security, Code Review, CompTIA Security+, Cyber Security, Computer Networks, Continuous Integration, Data Governance, Information Leak Prevention, Data Security, Linux, DevOps, Multi-Factor Authentication, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Microsoft Security Essentials, Microsoft Software, Windows PowerShell, Systems Development Life Cycle, Azure Active Directory, Cloud Services, Secure Coding, Software Engineering, Software Vulnerability Management, EndPointSecurity, Generative AI, Microsoft InTune, Azure Security Center, Information Technology, Cybercrime, CIS Benchmarks, Operating System Security, SentinelOne Expertise, Devsecops, Static Application Security Testing, Dynamic Application Security Testing - **Published:** July 21, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9044204/senior-cybersecurity-engineer-specialist ## About the Role Concurrent Technologies Corporation (CTC), an independent, nonprofit applied scientific research and development organization, is seeking a Senior Cybersecurity Engineer to join its internal Information Technology team. This senior-level role is responsible for strengthening and advancing the organization's cybersecurity posture by providing technical leadership across enterprise security initiatives, cloud technologies, identity and access management, endpoint protection, vulnerability management, and data security. You will work closely with cross-functional teams to develop innovative security solutions that protect critical business systems while enabling CTC's mission to deliver advanced technology solutions for government and industry. The ideal candidate is an experienced cybersecurity professional with a strong background in Microsoft security technologies, Azure Government, Microsoft 365, and enterprise security operations. This individual will serve as a trusted technical expert, driving security improvements, evaluating emerging threats and technologies, and helping shape cybersecurity strategy through automation, secure architecture, and modern security best practices. Success in this role requires strong analytical and problem-solving skills, a collaborative mindset, and the ability to communicate complex technical concepts to both technical and non-technical stakeholders while supporting compliance with government and industry cybersecurity standards., * Education: Bachelor's or Master's degree in Cybersecurity, Computer Science, Information Technology, or a related field. * Experience: 4-6 years of hands-on experience in a Cyber Security analyst or related IT or cyber engineer role. * Ability to obtain and maintain Secret government security clearance. * Demonstrated experience with Microsoft M365, Azure, or AWS cloud security components (e.g. Defender for Identy and Endpoint, Purview, Intune, Azure, EntraID) * Demonstrated ability to script and use command line interfaces with PowerShell, Python, or similar language. * Solid grasp of networking, operating system security (Windows-centric), and cloud security fundamentals. * Excellent verbal and written communication skills with the ability to explain and document technical information for a non-technical audience. * Proven ability to approach complex problems with a structured, analytical, and inquisitive mindset. * Relevant certifications such as CISSP, CISM, Security+, Microsoft SC-200/SC-300/AZ-500, or CEH. * Experience operating in AzureGov or other government/regulated cloud environments. * Familiarity with DevSecOps practices and secure CI/CD pipeline tooling (SAST/DAST/SCA). * Experience with Linux, macOS, and Windows in a heterogeneous network environment. * Understanding of security frameworks such as NIST 800-171 or 800-53, NIST Cybersecurity Framework, and CIS Controls. * Knowledge of CMMC, FedRAMP, or NIST compliance requirements. * Experience assessing security risks associated with AI/generative AI technologies. * Background in incident response and threat hunting. ## Description * General Security Operations - Participate in incident response activities, continuous monitoring, and the development of security standards and procedures in collaboration with internal cyber, IT, development, and data security teams. * Vulnerability & Threat Management - Perform threat hunting by analyzing threat feeds from various government and commercial sources and leveraging Rapid7 Insight VM and Microsoft Cloud tools to scan, prioritize, and remediate vulnerabilities across on-premises and cloud assets. * Endpoint & Device Security - Administer endpoint security systems (Microsoft Defender for Endpoint, SentinelOne, Intune, EntraID, Azure) for threat detection, investigation, and automated response across enterprise devices with a focus on compliance policies, configuration profiles, and conditional access enforcement. * Identity Security - Support and harden Microsoft Entra ID configurations, including conditional access, multi-factor authentication, privileged identity management, and identity governance. * Cloud Security - Apply, monitor, and enforce security best practices across AzureGov cloud services and Microsoft 365, ensuring alignment with government compliance frameworks (e.g., FedRAMP, NIST 800-171, CMMC as applicable). * Data Protection - Configure and manage Microsoft Purview data loss prevention (DLP), insider risk management and support compliance and eDiscovery initiatives, ensuring data governance policies are enforced across the M365 environment. * Secure Software Development & Automation - Collaborate with development and DevOps teams to embed security into the software development lifecycle (SDLC), including secure coding practices, code review, and dependency scanning. * AI-Related Security - Evaluate security considerations associated with the adoption of AI and generative AI tools, including data leakage, prompt injection, model misuse, and shadow AI risks while contributing to the development of AI usage guardrails and monitoring practices aligned with emerging federal AI security guidance. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)