Cyber Engineer

RSCY Consultants, LLC
Herndon, VA, United States
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Compensation
$140,000.0 - $170,000.0
Working hours
Regular working hours

Tech stack

Xacta Microsoft Windows Amazon Web Services Systems Engineering Bash Shell Cloud Computing Configuration Management Cyber Security Databases Query Languages Linux Identity and Access Management
+18 more
Information Security Management Information Technology Audit Python (Programming Language) Log Analysis Windows Servers Oracle (Applications) Windows PowerShell Red Hat Enterprise Linux Security Content Automation Protocol SQL Databases VMware VSphere Data Logging Scripting IT General Controls (ITGC) Software Security Nessus Splunk Vulnerability Analysis

Job description

Currently seeking a Cyber Engineer to support an Intel Community (IC) customer in the Herndon, Virginia area.

The Cyber Engineer provides mid-level operational support for enterprise information systems within classified environments. This role is execution-focused and emphasizes privileged system administration, security tool operations, log analysis, scripting, and audit evidence production. Supports ongoing Authorization to Operate (ATO) activities by maintaining system security posture, generating technical artifacts, and implementing approved security controls under the direction of Information System Security Officers (ISSOs), System Engineers, and audit leads or FISCAM audit SMEs.

This position requires hands-on experience administering Windows and Linux systems, executing Splunk queries, developing operational scripts, and supporting compliance activities through accurate and timely evidence generation.

Duties and responsibilities may include, but not limited to, the following:

Support all FISCAM audit related activities. Develop, maintain, and optimize Splunk searches, dashboards, and alerts to support, Security monitoring, audit evidence collection, and operational troubleshooting. Write and refine Search Processing Language (SPL) queries to extract, correlate, and validate log data across multiple data sources. Ensure log sources are properly onboarded, retained, and aligned with audit and compliance requirements. Develop and maintain scripts (e.g., PowerShell, Bash, Python, SQL) to automate data collection for audits, validate system configurations, and support continuous monitoring activities. Assist with automating evidence generation for recurring FISCAM, RMF, and internal audits. Provide technical support to Audit SMEs and ISSOs by producing, validating, and explaining system-level artifacts required for FISCAM audits and RMF assessments. Support documentation and validation of technical controls related to logging and monitoring, configuration management, access control, system integrity. Assist in responding to audit findings, including root cause analysis and technical remediation. Work closely with ISSOs, ISSEs, auditors, and operations teams to ensure systems are both secure and operationally effective. Translate technical system behavior into clear, defensible explanations for auditors and assessors. Participate in engineering reviews, change control boards, and security assessments as needed.

Requirements

Bachelor’s degree in an area relevant to the position and 8+ years of relevant experience; Master’s degree in an area to the position and 6+ years of relevant experience; or 4+ additional years of experience in lieu of a degree. TS/SCI with polygraph clearance adjudication or ability to obtain SCI and pass a poly Hold active Security+, CISSP, CISA, or equivalent certifications (DoD 8570 IAM 2 equivalent) One (1) year of experience with IC Community Experience in systems engineering or system administration in enterprise environments. Hands-on experience with Splunk (searches, dashboards, or administration). Experience using scripting or query languages (PowerShell, Bash, Python, SQL). Familiarity with RMF, ATO processes, and audit support in federal environments. Ability to operate with privileged system access in classified environments. Proven experience with Linux/RedHat 8 or higher, Windows Server 2019 or higher and/or Networking Appliances in Virtualized/Cloud platforms (vSphere or AWS) Proven experience with Oracle 19C or higher or SQL 2019 or higher database systems Proven experience with DISA Security Technical Implementation Guide (STIG) implementation and Security Content Automation Protocol (SCAP) tool usage Hands-on experience performing Systems Security tasks including: Security Information and Event Monitoring (Splunk); Endpoint security (HBSS); Compliance and vulnerability scanning (ACAS / Nessus) Demonstrated experience with creating and validating evidence for NIST security controls. Experience using and maintaining records in Xacta

Desired Qualifications:

Skilled in implementing mitigation strategies and how to resolve problems, and to re-test/ re-evaluate systems Experience with IT general controls (ITGC), Financial Information System Control Audit Manual (FISCAM), and National Institute of Standards and Technology Special Publication (NIST) 800-53v4 Experience with performing Security Control Assessment in compliance with NIST SP 800- 37, NIST SP 800-53, NIST SP 800-53A, and other NIST 800 guide series IT audit advisory experience Experience with effective policy, instruction, and development for Federal or DoD Information Security Programs Experience with risk analysis and assessment determinations incorporating system/mission owner, and unique operational constraints Possess a working knowledge of administering servers, system and application security threats and vulnerabilities.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all