Cyber Engineer

Northramp LLC
Washington, DC, United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Amazon Web Services Microsoft Azure Bash Shell Software as a Service Cloud Computing Cloud Computing Security CompTIA Security+ Cyber Security Linux DevOps Infrastructure as a Service (IaaS)
+23 more
Identity and Access Management Python (Programming Language) Key Management Platform as a Service (PAAS) Windows PowerShell Cloud Services Security Information and Event Management Software Vulnerability Management Scripting Google Cloud Cloud Platform System Multi-Cloud GWAPT Containerization Information Technology Prisma Cloud Platform Splunk Serverless Computing Qualys Security Orchestration, Automation & Response Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

Northramp is seeking a Cyber Engineer to join the team supporting the client’s Cloud BPA Bridge program - a mission-critical effort to consolidate, modernize, and operate client’s enterprise cloud services across IaaS, PaaS, and SaaS environments under FedRAMP High authorization.

You will serve as a hands-on cybersecurity practitioner embedded within the client’s cloud operations and delivery teams. The role spans vulnerability management, security engineering, continuous monitoring, and compliance support across multi-cloud environments operating under FedRAMP High, FISMA High, and DHS 4300A requirements.

This role is part of Northramp’s integrated delivery model, where engineers and advisors work as one team to bring sound judgment, disciplined execution, and deep federal experience to high-stakes modernization programs., * Perform continuous vulnerability scanning, analysis, and remediation tracking across cloud-hosted infrastructure and applications using tools such as Tenable.io, Prisma Cloud, or equivalent.

  • Apply and validate STIG configurations across operating systems, cloud services, and containerized workloads; develop and maintain hardening scripts and automation.
  • Support the Plan of Action and Milestones (POA&M) process - tracking open findings, validating remediations, and preparing reporting for program leadership and government stakeholders.
  • Implement and maintain security controls aligned to NIST 800-53 Rev 5, FedRAMP High baselines, and DHS 4300A; support ATO documentation and continuous authorization activities.
  • Integrate security tooling into CI/CD pipelines - SAST, DAST, container image scanning, SBOM generation, and secrets detection.
  • Configure and maintain SIEM integrations (Splunk or equivalent), including log source onboarding, alert tuning, and incident triage support.
  • Support Cloud Security Posture Management (CSPM) operations - misconfiguration detection, remediation, and drift prevention across AWS, Azure, and GCP.
  • Conduct threat modeling and security architecture reviews for new cloud services and application deployments.
  • Participate in incident response activities: containment, evidence collection, root cause analysis, and after-action reporting.
  • Collaborate with Cloud Systems Engineers, Network Engineers, and DevOps teams to embed security into infrastructure and delivery workflows.

Requirements

Do you have experience in Windows?, Do you have a Bachelor’s degree?, You have done real security engineering in federal cloud environments, you know what NIST 800-53 controls look like in practice (not just on paper), and you can move between writing a STIG remediation script and supporting an ATO review without missing a beat. You treat security as an engineering problem and you are most comfortable when you’re closest to the work., * 3 to 6 years of progressive, hands-on experience in cybersecurity engineering with a focus on cloud environments.

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Assurance, or a related field. Relevant experience may substitute.
  • Solid understanding of NIST 800-53, FedRAMP, FISMA, and STIG frameworks and their application in cloud environments.
  • Hands-on experience with vulnerability management tools (Tenable.io, Qualys, Prisma Cloud, or equivalent).
  • Practical experience with STIG implementation and hardening automation across Linux, Windows, and cloud-native services.
  • Working knowledge of SIEM platforms (Splunk preferred) - log onboarding, SPL queries, alert configuration.
  • Familiarity with cloud-native security services across AWS (Security Hub, GuardDuty, Config), Azure (Defender for Cloud), and/or GCP (Security Command Center).
  • Understanding of IAM, secrets management, and encryption key management in cloud environments.
  • Experience supporting ATO processes: control documentation, evidence collection, and POA&M management.
  • Scripting proficiency in Python, Bash, or PowerShell for security automation and remediation tasks.
  • U.S. Citizenship and the ability to obtain and maintain a DHS suitability / Public Trust clearance., * CompTIA Security+ (required at hire), CASP+, or CISSP.
  • Cloud security certifications: AWS Security Specialty, Microsoft SC-200/SC-300, CCSP, or equivalent.
  • Certified Ethical Hacker (CEH) or GIAC certifications (GCIH, GCED, or GWAPT).
  • DHS, or other federal cybersecurity program experience.
  • Active Public Trust or higher clearance.

Clearance

DHS suitability and a Public Trust background investigation are required for this role. Active Public Trust or higher clearance is preferred. Selected applicants will be subject to a security investigation and may need to meet eligibility requirements for access to controlled or classified information.

Benefits & conditions

Pulled from the full job description

  • AD&D insurance
  • 401(k)
  • Health insurance
  • Paid time off
  • Vision insurance
  • Dental insurance
  • Family leave, * Health Care Plan (Medical, Dental & Vision)
  • Retirement Plan (401k, IRA)
  • Life Insurance (Basic, Voluntary & AD&D)
  • Paid Time Off (Vacation, Sick & Public Holidays)
  • Family Leave (Maternity, Paternity)
  • Short Term & Long Term Disability
  • Training & Development
  • Work From Home
  • Wellness Resources
  • Employee Bonus Programs

About the company

Northramp is a federal consulting firm that helps agencies modernize and operate mission-critical systems with sound judgment, disciplined execution, and deep federal experience. We specialize in high-stakes digital transformation in highly regulated environments where failure is not an option. Our integrated delivery model brings engineers and advisors together as one team, combining technical depth with an operator’s mindset to move organizations from strategy to execution with confidence.

We hold high standards because our clients’ missions demand it, and we support our people in meeting them. Northramp is where you are challenged, trusted, and supported - a place for people who take pride in their work, value clarity and follow-through, and want to make a meaningful impact through technology.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

2:39 min

Experiencing core Linux capabilities for DevOps administration

Michael Cade · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

58 sec

Securing uncontaminated AI training data and mandating Linux authentication

Chris Heilmann +1 · LIVE

Videos

See all

Related articles

See all