> Markdown version of [/jobs/ext/1718453-cyber-security-engineer-ii](https://www.wearedevelopers.com/jobs/ext/1718453-cyber-security-engineer-ii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Engineer II - **Company:** cFocus Software Incorporated - **Location:** United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Application Firewall, User Authentication, Microsoft Azure, Cloud Computing, Cloud Computing Security, CompTIA Security+, Cyber Security, Information Systems, Databases, Linux, Identity and Access Management, Networking Hardware, Intrusion Detection Systems, Network Security, Network Segmentation, Systems Development Life Cycle, Cloud Services, Zero Trust Network Access, Software Vulnerability Management, SSL Certificate Management, Cloud Platform System, Firewalls (Computer Science), Information Technology, Malware Detection, CIS Benchmarks, ArcSight Event Correlation, Cyber Warfare, Vulnerability Analysis - **Published:** July 1, 2026 - **Apply:** http://cfocussoftware.applytojob.com/apply/jobs/details/pLzIPRwOGd ## About the Role * Public Trust Clearance * B.S. Computer Science, Information Technology, or a related field * 3+ years of experience implementing enterprise cybersecurity technologies. * Experience supporting Federal cybersecurity programs. * Experience engineering enterprise security solutions across Windows, Linux, cloud, and hybrid environments. * Experience implementing NIST cybersecurity controls and Federal security requirements. * Active CISSP, CCSP, Security+, CEH, GSEC, GCIH, or AWS Certified Security - Specialty ## Description cFocus Software seeks a Cyber Security Engineer II to join our program supporting the National Institutes of Health (NIH). This position is fully remote. This position requires a Public Trust or the ability to obtain a public trust clearance., * Engineer, deploy, configure, and maintain enterprise cybersecurity technologies supporting NIH information systems. * Support security monitoring and operational cyber defense activities across on-premises, hybrid, and cloud environments. * Administer endpoint security, endpoint detection and response (EDR), anti-malware, and host-based security solutions. * Implement secure configurations and system hardening in accordance with NIST, HHS, and NIH security standards. * Configure and maintain enterprise identity and access management (IAM) security technologies. * Support implementation and enforcement of Zero Trust Architecture (ZTA) principles. * Assist with enterprise log management, security monitoring, and event correlation capabilities. * Perform technical security assessments of servers, workstations, cloud resources, databases, and applications. * Coordinate with system administrators and application owners to implement security controls and corrective actions. * Support enterprise cybersecurity modernization initiatives. * Perform enterprise vulnerability assessments using approved vulnerability scanning platforms. * Analyze vulnerability scan results and prioritize remediation activities based on risk. * Coordinate vulnerability remediation with system administrators, application teams, and infrastructure personnel. * Verify remediation activities through follow-up validation testing. * Perform security configuration reviews against DISA STIGs, CIS Benchmarks, and NIH security baselines. * Monitor compliance with organizational vulnerability remediation timelines. * Develop remediation recommendations for operating systems, applications, databases, network devices, and cloud services. * Support development of Plans of Action & Milestones (POA&Ms) related to identified vulnerabilities. * Conduct risk analysis associated with newly discovered vulnerabilities and emerging threats. * Develop vulnerability metrics and executive reporting supporting enterprise cybersecurity risk management. * Design, engineer, implement, and maintain enterprise security architectures supporting NIH mission systems. * Engineer secure cloud environments within Microsoft Azure, Microsoft 365, AWS, and hybrid infrastructures. * Support implementation of network security technologies including firewalls, IDS/IPS, web application firewalls, secure gateways, and network segmentation. * Implement secure authentication, encryption, privileged access management, and certificate management solutions. * Engineer secure infrastructure supporting NIST Risk Management Framework (RMF) security controls. * Evaluate emerging cybersecurity technologies and recommend improvements to enterprise security architecture. * Support secure system lifecycle engineering activities throughout system development and modernization efforts. * Participate in technical architecture reviews and security design assessments. * Develop engineering documentation, implementation guides, standard operating procedures, and technical diagrams. * Support implementation of Cybersecurity Supply Chain Risk Management (C-SCRM) controls where applicable. ## Related Videos - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)