> Markdown version of [/jobs/ext/1596699-cyber-security-engineer-5462](https://www.wearedevelopers.com/jobs/ext/1596699-cyber-security-engineer-5462). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Engineer (5462) - **Company:** SMX, LLC - **Location:** Frankfort, KY, United States - **Experience:** Experienced - **Salary:** $103,100.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cloud Engineering, Configuration Management, Cyber Security, DevOps, Identity and Access Management, Python (Programming Language), Windows PowerShell, Systems Integration, Software Vulnerability Management, Policy as Code, Data Logging, Scripting, SARS Software Products, HybridCloud, Information Technology, Nessus, RSA Archer Platform, Restful APIs, Prisma Cloud Platform, Splunk, Devsecops, Serverless Computing, Plan of Action and Milestones - **Published:** July 23, 2026 - **Apply:** https://www.techcareers.com/job.asp?id=3330053515&tx=JJ2115FFK&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role * Strong analytical, documentation, and problem-solving skills with a focus on secure and compliant outcomes. * Excellent communication and stakeholder-management skills, including the ability to advise partners, customers, engineers, and government stakeholders. * Ability to translate federal security requirements into practical technical controls and operational processes. * U.S. citizenship with the ability to obtain and maintain a Secret or higher security clearance. * Bachelor's degree in Information Security, Cybersecurity, Computer Science, or a related field, or equivalent practical experience. * Five or more years of cybersecurity experience, including at least three years supporting federal cloud security engineering, information assurance, RMF, or ISSO functions. * Knowledge of NIST SP 800-53 Rev. 5, FedRAMP Moderate and High, DoD IL4-6 overlays, RMF, and related federal compliance frameworks. * Experience developing and maintaining SSPs, POA&Ms, SARs, policies, control evidence, and other authorization artifacts. * Experience supporting authorization planning, gap assessments, audit readiness, control implementation, and remediation activities. * Hands-on experience with AWS, Azure, or hybrid cloud environments, including IAM, encryption, logging, configuration management, and security monitoring. * Experience using GRC platforms, APIs, scripting, or automation to improve compliance and security workflows. * Familiarity with tools such as eMASS, Paramify, Nessus/Tenable, Splunk, Prisma Cloud, or comparable solutions. Desired Skills & Experience * Experience supporting FedRAMP, DoD, DISA, or federal agency ATO activities. * CISSP, CGRC/CAP, CISM, Security+, or similar cybersecurity certification. * Experience developing automation with Python, PowerShell, REST APIs, infrastructure-as-code, or cloud-native services. * Experience integrating vulnerability, configuration, and cloud-security data into GRC (Paramify) and POA&M workflows. * Familiarity with DevSecOps pipelines, automated security testing, policy-as-code, and continuous control validation. * Knowledge of FISMA, the Privacy Act, and agency-specific security requirements. ## Description * Provide cybersecurity engineering and compliance support for FedRAMP and DoD-authorized cloud environments, including IL4-6. * Advise partners and customers on federal and DoD security requirements, authorization strategies, control implementation, and audit readiness. * Develop, review, and maintain authorization documentation, including SSPs, SAPs, SARs, POA&Ms, FedRAMP appendices, policies, and supporting evidence. * Support system authorization and reauthorization activities across FedRAMP/RMF, including gap assessments, control validation, evidence development, and remediation planning. * Leverage GRC platforms, APIs, scripts, and automation to streamline compliance workflows, evidence collection, documentation updates, control testing, and reporting. * Develop repeatable and auditable processes that reduce manual compliance effort and improve the accuracy and consistency of authorization artifacts. * Collaborate with cloud engineering and DevOps teams to design, implement, and validate security controls across AWS, Azure, and hybrid environments. * Review system changes and significant change requests to assess security impact, identify documentation updates, and maintain authorization boundaries. * Coordinate with system owners, engineers, 3PAOs, Authorizing Officials, and government stakeholders to address findings and support authorization outcomes. * Support continuous monitoring, vulnerability management, POA&M updates, remediation tracking, and recurring compliance deliverables. * Evaluate security tooling and data sources to identify opportunities for automated control validation and compliance reporting. * Track evolving federal cybersecurity requirements and translate them into practical technical and operational actions. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)