Principal Cyber Systems Engineer

Caribou Thunder
Colorado Springs, CO, United States
15 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
0 years minimum
Compensation
$90,000.0 - $112,000.0
Working hours
Regular working hours

Tech stack

Access Control List Agile Methodology Software System Penetration Testing Systems Engineering Confluence JIRA Collaborative Software Cyber Security Computer Networks System Configuration Linux Network Address Translation
+26 more
Elasticsearch Information Security Management Subnetting Python (Programming Language) Linux System Administration Microsoft Office Scrum Methodology Systems Development Life Cycle Red Hat Enterprise Linux Ansible Security Content Automation Protocol Security Information and Event Management Transmission Control Protocol (TCP) Virtual Local Area Networks VMware Virtualization Software Vulnerability Management SARS Software Products Firewalls (Computer Science) GWAPT Containerization Atlassian Tools Tenable Nessus Nessus National Industrial Security Program Operating Manual (NISPOM) Plan of Action and Milestones Vulnerability Analysis

Job description

Protect mission-critical defense systems by supporting cybersecurity engineering, Risk Management Framework (RMF) compliance, and continuous monitoring activities across classified environments. Join a collaborative engineering team responsible for securing next-generation defense systems through vulnerability assessments, security compliance, system hardening, and Assessment & Authorization (A&A) activities that enable mission success.

  • Perform cybersecurity assessments of classified systems and networks to identify configuration drift, security vulnerabilities, and compliance deficiencies.
  • Conduct compliance audits using tools such as STIG Viewer, Evaluate-STIG, STIG Manager, SCAP, SCC, and related assessment utilities.
  • Develop, update, and maintain cybersecurity documentation including Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), Plan of Actions & Milestones (POA&M), and RMF body-of-evidence artifacts.
  • Support the full Risk Management Framework (RMF) lifecycle by preparing Assessment & Authorization (A&A) documentation and maintaining system accreditation packages within eMASS.
  • Coordinate with government customers, System Program Office (SPO) personnel, Information System Security Managers (ISSMs), and engineering teams to resolve cybersecurity findings and maintain authorization status.
  • Perform vulnerability assessments using ACAS, Nessus, Tenable.sc, and related security assessment tools to identify and remediate cybersecurity risks.
  • Validate security controls and verify compliance with DoD cybersecurity requirements, including NIST, DoDI, AFI, and NISPOM guidance.
  • Apply Security Technical Implementation Guides (STIGs) to harden Linux-based systems and verify secure system configurations.
  • Analyze cybersecurity findings, recommend risk mitigation strategies, and support implementation of corrective actions across engineering teams.
  • Collaborate with software developers, systems engineers, and infrastructure teams to integrate cybersecurity requirements throughout the system development lifecycle.
  • Support continuous monitoring activities through recurring security assessments, audits, inspections, and compliance reviews.
  • Research emerging cybersecurity technologies, evaluate new security tools, and recommend enhancements that improve overall system security posture.
  • Support domestic and international travel (up to 25%) to assist with cybersecurity assessments, program reviews, and customer mission support.

Requirements

  • Bachelor’s degree in a STEM (Science, Technology, Engineering, or Mathematics) discipline and 2 years of related professional experience; OR
  • Master’s degree with 0 years of related professional experience.

  • Bachelor’s degree in a STEM discipline and 5 years of related professional experience; OR
  • Master’s degree and 3 years of related professional experience; OR
  • PhD and 1 year of related professional experience.

Both Levels Require:

  • Active in-scope DoD Secret security clearance required at time of application.
  • Current DoD 8570 IAT Level II certification (Security+ CE, SSCP, GSEC, CCNA Security, or equivalent).
  • Experience applying DoD cybersecurity policies and standards including DoDI 8500.01, NIST SP 800-53, and NIST SP 800-115.
  • Working knowledge of the Risk Management Framework (RMF) lifecycle, including security requirements development, security control assessments, vulnerability analysis, and Assessment & Authorization activities.
  • Experience developing cybersecurity documentation and RMF artifacts supporting system accreditation.
  • Experience performing vulnerability and compliance assessments using ACAS, Nessus, Tenable.sc, or equivalent scanning tools.
  • Experience administering Linux systems in secure environments.
  • Experience implementing and validating Security Technical Implementation Guides (STIGs).
  • Strong technical writing, documentation, and analytical skills.
  • Proficiency with Microsoft Office Suite.
  • Ability to work onsite under a 9/80 schedule.
  • Ability to travel up to 25% (CONUS and OCONUS).

  • Active DoD Top Secret security clearance.
  • Penetration testing certifications such as OSCP, OSCE, GPEN, GWAPT, or GXPN.
  • Experience implementing or administering Security Information and Event Management (SIEM) and centralized log aggregation platforms.
  • Experience conducting cybersecurity assessments of Red Hat Enterprise Linux (RHEL) environments.
  • Strong understanding of networking concepts including:
  • TCP/IP networking
  • Subnetting
  • Firewalls
  • Network Address Translation (NAT)
  • Access Control Lists (ACLs)
  • VLANs
  • Advanced experience using ACAS, Nessus, and Tenable.sc for enterprise vulnerability management.
  • Experience implementing automated STIG compliance using Evaluate-STIG, STIG Manager, SCC, Xylok, Ansible, Python, or similar automation tools.
  • Experience supporting Agile development methodologies including Scrum, Kanban, or SAFe.
  • Experience using Jira, Confluence, or other Atlassian collaboration tools.
  • Experience supporting VMware virtualization and containerized environments.
  • Experience managing RMF packages within eMASS and supporting Authority to Operate (ATO) activities.
  • Experience with the Elastic Stack (ELK) for security monitoring and analytics.
  • Experience supporting Cross Domain Solutions (CDS), including coordination with CDSE and NCDSMO.
  • Current DoD 8570 IAT Level III certification (CISSP or equivalent).

Benefits & conditions

  • Premium Health, Dental & Vision Insurance
  • 401(k) with 6% Company Match
  • Flexible PTO & Work Schedule
  • Education & Certification Reimbursement
  • Support for Military Leave
  • Work-Life Balance & Traditional Family Values

About the company

Caribou Thunder is a HUBZone-certified small business providing advanced technical and engineering services to the U.S. Department of War and its mission partners.

35+ states and 20+ countries.

We’ve delivered trusted solutions for over two decades-strengthening national readiness across missions on land, undersea, in the air, and throughout LEO, MEO, GEO, and deep space.

  • Employee Advocacy
  • Mission Proven
  • Global Reach
  • Skilled Teams
  • Modern Tools
  • Empowering Culture

Our engineers and innovators ensure capability from sea floor to space frontier-delivering on time, maintaining compliance, and performing with precision in high-consequence environments.

We specialize in Engineering Services, Cybersecurity, Software Development, Modeling & Simulation, Digital Engineering, Artificial Intelligence, and Secure Mission Systems-disciplines powering the nation’s most complex technical missions.

Our people are the heart of Caribou Thunder. We invest in their growth, flexibility, and well-being-knowing their success drives ours.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:39 min

Experiencing core Linux capabilities for DevOps administration

Michael Cade · LIVE

5:47 min

Integrating user stories and test automation via Jira tools

Christoph Ruggenthaler · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

Videos

See all

Related articles

See all