Cybersecurity Engineer III
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
NIS is seeking an experienced Cybersecurity Engineer III to serve as Key Personnel supporting a Department of Defense Command, Control, Communications, Computers, and Intelligence (C4I) program. This senior-level engineer will provide cybersecurity engineering across the system lifecycle, translating mission and security requirements into secure architecture, RMF evidence, hardening decisions, remediation plans, and authorization-ready artifacts. Success requires strong technical judgment, disciplined documentation, and effective collaboration with government and contractor teams., * Design, implement, and maintain secure system architectures for mission-critical C4I environments.
- Perform cybersecurity engineering across planning, design, development, integration, testing, deployment, operations, and sustainment activities.
- Support Risk Management Framework (RMF) activities, including control implementation, assessment support, authorization evidence, and continuous monitoring.
- Analyze security requirements, system interfaces, data flows, and proposed changes to identify risk and recommend practical mitigations.
- Conduct or support security assessments, review vulnerability findings, prioritize remediation, and verify corrective actions.
- Apply and validate secure configuration guidance, including applicable DISA Security Technical Implementation Guides (STIGs).
- Develop and maintain cybersecurity artifacts, including security plans, control narratives, risk assessments, diagrams, test evidence, and Plans of Action and Milestones (POA&Ms).
- Support technical reviews, configuration and change control, security testing, authorization milestones, and clear communication of risks and recommended actions.
Requirements
Education: Bachelor’s degree in Cybersecurity, Computer Engineering, Electrical Engineering, Electronics Engineering, Mathematics with a concentration in Computer Science, or equivalent. Certification: Current DoD 8570/8140-compliant certification meeting IAM Level II, IAT Level II, or IASAE Level II requirements. Experience: Minimum of 10 years of professional cybersecurity engineering experience. DoD C4I Experience: At least 4 years supporting DoD C4I systems., * Hands-on RMF experience.
- Experience implementing and validating DISA STIGs.
- Experience with ACAS, SCAP, eMASS, or HBSS.
- Experience supporting NAVWAR or other Navy programs.
Benefits & conditions
For eligible employees, NIS offers medical, dental, and vision insurance; life and disability insurance; a 401(k) plan with employer match; paid holidays; paid time off; commuter benefits; an employee assistance program; educational reimbursement; and pet insurance. Eligibility and offerings may vary based on employment classification and plan terms.
Salary range $100,000 to $175,000 annually The salary range is a general guideline. We consider several factors when determining base salary offers, including the position’s scope and responsibilities, the candidate’s experience, education, and skills, and current market conditions.
About the company
Nationwide IT Services (NIS) is a mission-driven IT and management consulting company serving government customers. Founded in 2006, NIS delivers cybersecurity, enterprise IT, cloud, digital services, DevSecOps, AI, data analytics, and mission support solutions. NIS is a Service-Disabled Veteran-Owned Small Business committed to innovative, value-added solutions delivered with integrity and a people-first culture that invests in professional growth and service.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.clearancejobs.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
Best Paying Jobs in Technology
Understanding and Mitigating Common Web Vulnerabilities
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.