> Markdown version of [/jobs/ext/1826043-cybersecurity-engineer](https://www.wearedevelopers.com/jobs/ext/1826043-cybersecurity-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Engineer - **Company:** Chenega Corporation - **Location:** Albuquerque, NM, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Xacta, Agile Methodology, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Data Integration, DevOps, Federal Information Processing Standards (FIPS), Information Security Management, Software Engineering, Data Processing, Cloud Platform System, Information Technology, Data Analytics, Plan of Action and Milestones, Static Application Security Testing, Vulnerability Analysis, Web Api - **Published:** July 3, 2026 - **Apply:** https://dejobs.org/x/x/0823B5BFA54D42AEA577C35CC805DF51/job/ ## About the Role * Bachelors degree in Cybersecurity, IT, Computer Science, or a combination of education and experience. * 8+ Years Federal Cybersecurity Experience with direct NIST RMF experience on FIPS Moderate or higher impact systems * Experience with a federal GRC tool, primarily Xacta, eMass, or equivalent. * Demonstrated experience in service as or supporting an ISSO role that includes ATO maintenance, POA&M management, and continuous monitoring of a federal system. * Background check. * Must be able to obtain a Public Trust * Must be a US citizen, * CISSP and CISM certified * Experience with FedRAMP authorized cloud environments and cloud security control inheritance * Successfully pass background and drug screening Knowledge, Skills, and Abilities: * Knowledge supporting an ATO through platform migration or a major system upgrade * Familiarity with DOI OCIO IT Baseline Compliance Contract Guidelines * Familiarity with static application security testing tools * Understanding of NIST SP 800-160 Systems security engineering principles * Familiar with Software Development Lifecycles and administering security controls along the delivery roadmap. * Knowledge or previous experience using MS Azure DevOps * Strong organizational skills with demonstrated ability to handle multiple projects and details simultaneously. * Excellent communication skills (written, verbal, presentations). * Excellent organization, analytical, planning, and scheduling skills. * Ability to resolve highly complex problems. * Self-starter who can work with a large and diverse team of business, management, and IT individuals. * Ability to obtain an IA drivers license, which will allow operation of a government vehicle. ## Description Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you looking for a career where professional development is embedded in your employers core culture? If so, Chenega Military, Intelligence & Operations Support (MIOS) could be the place for you! Join our team of professionals who support large-scale government operations by leveraging cutting-edge technology and take your career to the next level! At Cyberstar, we aim to analyze and boost human and business performance through the implementation of business process redesign and information technology (IT) modernization to include data analytics and cloud computing. We offer an alternate solution to improving the quality and effectiveness of business operations. In an ever-changing economy, Cyberstar helps companies better read and understand their market data through the synchronization of process innovation, human dynamics, analysis, and the integration of data technology capabilities, to ensure functional optimization in their business., Cyberstar is seeking a Cybersecurity Engineer to serve as the embedded Information System Security Officer (ISSO) for a federal IT contract supporting FIPS 199 Moderate-impact system handling CUI and PII across multiple federal bureaus. Specific tasks will be focused on immediate and high-priority requirements necessary to maintain the current Authorization to Operate (ATO), in accordance with the NIST Risk Management Framework and NIST Special Publication 800-53 (as revised, but currently at revision 5) at the Federal Information Processing Standard (FIPS) 199 Moderate Level., * Serve as the embedded ISSO, maintaining the systems ongoing Authorization to Operate (ATO) without lapse through platform migration and cloud transition. * Validate and maintain security baseline in the agencys GRC tool, resolving discrepancies between documented and implemented controls in coordination with the Government ISSO * Deliver a formal Security Gap Analysis within 60 days and annually thereafter, conducted against the NIST SP 800-53 Rev. 5 Moderate Baseline using SP 800-53 methodology. * Develop and update the Plan of Action and Milestones (POA&Ms), each with defined timelines, responsible parties, potential cost estimates, and verification criteria. Able to integrate into the Agile sprint backlog for prioritization alongside functional work. * Conduct and manage continuous vulnerability scanning, triage findings against the NIST SP 800-53B Moderate baseline, and track remediation within directed patch timelines. * Validate security controls in target environments before any production cutover. Confirm ATO status before migration cutovers. * Review and accept quarterly cybersecurity packages and the annual Security Gap Analysis as joint acceptance with the Government stakeholders. * Support Security Assessments and Authorization activities, coordinate OEM to Government POA&M resolution, and maintain the Information Security Continuous Monitoring strategy per NIST 800-37 Rev.2. * Apply engineering level controls at external integration boundaries including encrypted transfer, authenticated API calls, validated data formats, and anomaly detection. * Other duties as assigned. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Web APIs you might not know about](https://www.wearedevelopers.com/videos/281-web-apis-you-might-not-know-about) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Project Fugu: Extending the web](https://www.wearedevelopers.com/videos/832-project-fugu-extending-the-web) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)