> Markdown version of [/jobs/ext/206631-senior-cybersecurity-engineer](https://www.wearedevelopers.com/jobs/ext/206631-senior-cybersecurity-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cybersecurity Engineer - **Company:** Evolver Inc. - **Location:** Reston, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Cyber Security, Python (Programming Language), Systems Development Life Cycle, Data Streaming, Systems Architecture, Software Vulnerability Management, Policy as Code, Data Logging, Scripting, Splunk, Devsecops - **Published:** May 22, 2026 - **Apply:** https://jobs.localjobnetwork.com/job/detail/87247252/Senior-Cybersecurity-Engineer ## About the Role * Bachelor's degree and 5 years of related experience. * 5 years of experience supporting compliance or cybersecurity reporting (e.g., FISMA, RMF) required. * 5 years of experience implementing and validating NIST SP 800-53 controls within systems * 3 years of experience supporting RMF and ATO processes (hands-on with control implementation, not just documentation) * 2 years of experience with continuous monitoring strategies and tools (e.g., Splunk, Elastic, Tenable, CDM) * 2 years of experience working with system architectures, data flows, and security integration points * 1 years of experience with RMF artifacts (SSP, SAR, POA&M) and how they map to system implementations * Must be able to obtain DHS Suitability(EOD) and have active Secret or above clearance, * Strong communication and collaboration skills to engage both technical and non-technical stakeholders. * Ability to communicate clearly and effectively via written and verbal communication in both formal and informal situations. * Ability to clearly communicate complex technical concepts to technical and non-technical POCs. * Experience enabling or supporting cATO / ongoing authorization models * Scripting or automation experience (Python, APIs, infrastructure-as-code) * Experience with DevSecOps / CI/CD pipeline security integration * Understanding of policy-as-code / compliance automation approaches * Experience in DHS CDM environments * Excellent organizational skills and attention to detail. * Strong analytical, critical thinking, and problem-solving skills. ## Description Evolver is seeking a Senior Cybersecurity Engineer to engineer, implement, and validate security controls within system architectures, while enabling continuous monitoring and automated authorization (ATO) aligned to RMF. This role focuses on embedding NIST-based security controls directly into system design and operations, ensuring systems remain in a continuous state of compliance and authorization through automated validation, telemetry, and engineering-driven evidence generation. What You'll Do * Integrate security controls (NIST SP 800-53) into system architectures, applications, and infrastructure as part of the SDLC * Engineer and implement technical control solutions (identity, logging, vulnerability management, configuration enforcement) * Perform control implementation and validation, ensuring controls are operating as intended within the system * Support RMF lifecycle activities (categorization, control selection, implementation, assessment, and authorization) with a strong engineering focus * Design and implement continuous monitoring (ConMon) capabilities that validate control effectiveness using system telemetry * Enable automated ATO (cATO) by integrating control checks, telemetry, and validation results into ongoing authorization decisions * Develop machine-testable control assertions and automate validation using scripts, APIs, and security tools * Generate and maintain RMF artifacts (SSP, SAR, POA&M) through automated data collection and system outputs * Conduct security engineering analysis of system data flows, architectures, and dependencies to identify risks and control gaps * Implement and validate compensating controls where standard controls cannot be fully applied * Support audit readiness and assessments by ensuring traceable, reproducible control evidence * Collaborate with system owners, developers, and ISSOs to ensure security is built into system changes and deployments ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)