> Markdown version of [/jobs/ext/1808988-cybersecurity-engineer](https://www.wearedevelopers.com/jobs/ext/1808988-cybersecurity-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Engineer - **Company:** Credence Management Solutions, LLC - **Location:** McLean, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Data as a Services, Identity and Access Management, IT Management, Cloud Platform System, Information Technology - **Published:** July 17, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9039318/cybersecurity-engineer ## About the Role * Eight (8) years of relevant C&A experience * Risk Management Framework (RMF) and NIST C&A experience. * DOD cybersecurity experience accreditation * Experience in assessing security controls and conducting authorization reviews for large, complex organizations particularly in cloud environments. * Experienced in the general tenets supporting the overall DOD implementation of its authorization process, to include supporting cybersecurity policy, procedures, and processes. * Experience with FedRAMP-Approved Impact Level 5 (IL5) GovCloud environments * Knowledgeable in IT Governance and Compliance * DoD Approved 8570 Baseline Certification: Category IAM Level I * Must be a US Citizen and with the ability to obtain a Defense Secret Clearance * Active Clearance is preferred ## Description Credence has an immediate need for a Cybersecurity Engineer to serve as a Subject Matter Expert (SME) in cybersecurity, focusing on the authorization of information systems and compliance with associated policies and procedures. The role provides security engineering support for planning, design, development, testing, and integration of information systems. They ensure the platform meets DAAS and all applicable DoD requirements for deployment and operation within a FedRAMP-Approved Impact Level 5 (IL5) GovCloud environment and support continuous audit readiness. Responsibilities include, but are not limited to the duties listed below, as outlined in the contract statement of work: * Support the overall DoD implementation of its authorization process, including cybersecurity policy and procedures. * Authorize information systems or serve as a SME for systems undergoing authorization. * Assess and apply NIST 800-53 security controls to large organizations' IT infrastructure. * Determine severity values for identified vulnerabilities and their implications on system authorization. * Brief senior management on the progress or results of information systems undergoing authorization. * Work collaboratively with Government ISSM/COR/PMO to achieve an authorization to operate (ATO), then monitor and sustain an ATO. * Gather Audit artifacts for annual DLA Audit reviews ## Related Videos - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [From SaaS to Space: The Defensible Value VCs Are Looking For](https://www.wearedevelopers.com/videos/100104-from-saas-to-space-the-defensible-value-vcs-are-looking-for) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)