> Markdown version of [/jobs/ext/1920333-cybersecurity-engineer](https://www.wearedevelopers.com/jobs/ext/1920333-cybersecurity-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # CyberSecurity Engineer - **Company:** Spatial Front Inc. - **Location:** Arlington, VA, United States - **Experience:** Expert - **Salary:** $120,000.0 - $150,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Audit Trail, Bash Shell, Cloud Engineering, Capability Maturity Model Integration, CompTIA Security+, Cyber Security, System Configuration, Identity and Access Management, Information Systems Security Architecture Professional, Python (Programming Language), Linux Servers, Windows PowerShell, Role-Based Access Control, Security Content Automation Protocol, User Provisioning Software, Software Vulnerability Management, Scripting, SC Clearance, Information Technology, Patch Management, Splunk, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=bc15a8061f3e7d21 ## About the Role * Clearance: Must be a U.S. Citizen with an active Secret Clearance (or ability to obtain/pass a federal background investigation). * Education & Experience: Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent operational experience) + 5+ years of dedicated cybersecurity engineering experience. * Certifications: Active CompTIA Security+ (IAT Level II compliant). * Hands-On Scale Experience: + Proven experience conducting ACAS scans and vulnerability analysis across large environments (900+ servers). + Direct experience applying and evaluating DISA STIGs at enterprise scale. + Deep working knowledge of DoD RMF processes and direct experience navigating eMASS. + Strong proficiency in writing, managing, and closing out POA&Ms., * Identity & Access Management: Hands-on experience with Identity, Credential, and Access Management (ICAM), including user provisioning, role-based access control (RBAC), and access review tracking. * Log Management & Auditing: Practical experience analyzing audit logs, building dashboards, and configuring security alerts using Splunk and Audit Vault systems. * Advanced Certifications: CISSP (Certified Information Systems Security Professional), CISM, or CASP+. * Experience with automated vulnerability/patch management tooling and scripting (e.g., PowerShell, Python, or Bash)., * Clearance: Must be a U.S. Citizen with an active Secret security clearance or the ability to obtain one. ## Description Spatial Front, Inc. (SFI), a two-time USA Today Top Workplaces awardee and Washington Top Workplaces honoree, is a fast-growing federal technology solutions provider. We bring together innovative technologies, industry best practices, and top-notch talent to address our federal clients' most critical mission needs. As an ISO 9001, 20000, 27001, and CMMI Level 3 certified organization, SFI delivers high-impact cybersecurity, enterprise IT, and cloud engineering across the public sector. At SFI, you will work alongside subject matter experts in an open, collaborative environment dedicated to continuous learning and technical excellence., Spatial Front is seeking a Cybersecurity Engineer to support and secure mission-critical infrastructure across a large enterprise environment comprising 900+ servers. In this role, you will lead hands-on vulnerability management, security compliance, and Risk Management Framework (RMF) authorization processes. You will serve as a technical expert responsible for continuous scanning, STIG application, POAM tracking, and remediation strategies to safeguard our federal client's assets., * Vulnerability Assessment & Mitigation: Perform automated and credentialed enterprise vulnerability scans across 900+ Windows/Linux server assets using Assured Compliance Assessment Solution (ACAS / Tenable.sc). Analyze raw scan results, evaluate true/false positives, prioritize risk, and coordinate patch/remediation workflows with systems administrators. * Compliance & Hardening: Execute end-to-end Security Technical Implementation Guide (STIG) application and evaluation across large-scale server infrastructures. Validate compliance utilizing DISA STIG Viewer and automated benchmarks (SCAP Content). * RMF & Authorization Artifacts: Lead and support Risk Management Framework (RMF) Steps 1 through 6 lifecycle activities. Prepare, maintain, and upload standard compliance artifacts into Enterprise Mission Assurance Support Service (eMASS) to maintain continuous Authority to Operate (ATO) posture. * POA&M Management: Author, manage, and track Plans of Action and Milestones (POA&Ms) for open vulnerabilities and non-compliant controls. Work with stakeholders to define mitigation strategies, root cause analyses, and realistic completion milestones. * Security Reporting & Ops: Drive continuous monitoring strategies, presenting vulnerability and compliance metrics to agency leadership and federal stakeholders. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [MCP doesn’t suck — your agent does](https://www.wearedevelopers.com/videos/100202-mcp-doesn-t-suck-your-agent-does) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)