> Markdown version of [/jobs/ext/1610729-principal-cyber-systems-engineer](https://www.wearedevelopers.com/jobs/ext/1610729-principal-cyber-systems-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Cyber Systems Engineer - **Company:** Caribou Thunder - **Location:** Colorado Springs, CO, United States - **Experience:** Expert - **Salary:** $90,000.0 - $112,000.0 - **Contract:** Permanent contract - **Skills:** Access Control List, Agile Methodology, Software System Penetration Testing, Systems Engineering, Confluence, JIRA, Collaborative Software, Cyber Security, Computer Networks, System Configuration, Linux, Network Address Translation, Elasticsearch, Information Security Management, Subnetting, Python (Programming Language), Linux System Administration, Microsoft Office, Scrum Methodology, Systems Development Life Cycle, Red Hat Enterprise Linux, Ansible, Security Content Automation Protocol, Security Information and Event Management, Transmission Control Protocol (TCP), Virtual Local Area Networks, VMware Virtualization, Software Vulnerability Management, SARS Software Products, Firewalls (Computer Science), GWAPT, Containerization, Atlassian Tools, Tenable Nessus, Nessus, National Industrial Security Program Operating Manual (NISPOM), Plan of Action and Milestones, Vulnerability Analysis - **Published:** July 27, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9059695/principal-cyber-systems-engineer ## About the Role * Bachelor's degree in a STEM (Science, Technology, Engineering, or Mathematics) discipline and 2 years of related professional experience; OR * Master's degree with 0 years of related professional experience. * Bachelor's degree in a STEM discipline and 5 years of related professional experience; OR * Master's degree and 3 years of related professional experience; OR * PhD and 1 year of related professional experience. Both Levels Require: * Active in-scope DoD Secret security clearance required at time of application. * Current DoD 8570 IAT Level II certification (Security+ CE, SSCP, GSEC, CCNA Security, or equivalent). * Experience applying DoD cybersecurity policies and standards including DoDI 8500.01, NIST SP 800-53, and NIST SP 800-115. * Working knowledge of the Risk Management Framework (RMF) lifecycle, including security requirements development, security control assessments, vulnerability analysis, and Assessment & Authorization activities. * Experience developing cybersecurity documentation and RMF artifacts supporting system accreditation. * Experience performing vulnerability and compliance assessments using ACAS, Nessus, Tenable.sc, or equivalent scanning tools. * Experience administering Linux systems in secure environments. * Experience implementing and validating Security Technical Implementation Guides (STIGs). * Strong technical writing, documentation, and analytical skills. * Proficiency with Microsoft Office Suite. * Ability to work onsite under a 9/80 schedule. * Ability to travel up to 25% (CONUS and OCONUS). * Active DoD Top Secret security clearance. * Penetration testing certifications such as OSCP, OSCE, GPEN, GWAPT, or GXPN. * Experience implementing or administering Security Information and Event Management (SIEM) and centralized log aggregation platforms. * Experience conducting cybersecurity assessments of Red Hat Enterprise Linux (RHEL) environments. * Strong understanding of networking concepts including: + TCP/IP networking + Subnetting + Firewalls + Network Address Translation (NAT) + Access Control Lists (ACLs) + VLANs * Advanced experience using ACAS, Nessus, and Tenable.sc for enterprise vulnerability management. * Experience implementing automated STIG compliance using Evaluate-STIG, STIG Manager, SCC, Xylok, Ansible, Python, or similar automation tools. * Experience supporting Agile development methodologies including Scrum, Kanban, or SAFe. * Experience using Jira, Confluence, or other Atlassian collaboration tools. * Experience supporting VMware virtualization and containerized environments. * Experience managing RMF packages within eMASS and supporting Authority to Operate (ATO) activities. * Experience with the Elastic Stack (ELK) for security monitoring and analytics. * Experience supporting Cross Domain Solutions (CDS), including coordination with CDSE and NCDSMO. * Current DoD 8570 IAT Level III certification (CISSP or equivalent). ## Description Protect mission-critical defense systems by supporting cybersecurity engineering, Risk Management Framework (RMF) compliance, and continuous monitoring activities across classified environments. Join a collaborative engineering team responsible for securing next-generation defense systems through vulnerability assessments, security compliance, system hardening, and Assessment & Authorization (A&A) activities that enable mission success. * Perform cybersecurity assessments of classified systems and networks to identify configuration drift, security vulnerabilities, and compliance deficiencies. * Conduct compliance audits using tools such as STIG Viewer, Evaluate-STIG, STIG Manager, SCAP, SCC, and related assessment utilities. * Develop, update, and maintain cybersecurity documentation including Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), Plan of Actions & Milestones (POA&M), and RMF body-of-evidence artifacts. * Support the full Risk Management Framework (RMF) lifecycle by preparing Assessment & Authorization (A&A) documentation and maintaining system accreditation packages within eMASS. * Coordinate with government customers, System Program Office (SPO) personnel, Information System Security Managers (ISSMs), and engineering teams to resolve cybersecurity findings and maintain authorization status. * Perform vulnerability assessments using ACAS, Nessus, Tenable.sc, and related security assessment tools to identify and remediate cybersecurity risks. * Validate security controls and verify compliance with DoD cybersecurity requirements, including NIST, DoDI, AFI, and NISPOM guidance. * Apply Security Technical Implementation Guides (STIGs) to harden Linux-based systems and verify secure system configurations. * Analyze cybersecurity findings, recommend risk mitigation strategies, and support implementation of corrective actions across engineering teams. * Collaborate with software developers, systems engineers, and infrastructure teams to integrate cybersecurity requirements throughout the system development lifecycle. * Support continuous monitoring activities through recurring security assessments, audits, inspections, and compliance reviews. * Research emerging cybersecurity technologies, evaluate new security tools, and recommend enhancements that improve overall system security posture. * Support domestic and international travel (up to 25%) to assist with cybersecurity assessments, program reviews, and customer mission support. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Integrate your Cognitive Assistant with 3rd-party DBs and software](https://www.wearedevelopers.com/videos/249-integrate-your-cognitive-assistant-with-3rd-party-dbs-and-software) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)