> Markdown version of [/jobs/ext/2189373-senior-cybersecurity-integration-engineer](https://www.wearedevelopers.com/jobs/ext/2189373-senior-cybersecurity-integration-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cybersecurity Integration Engineer - **Company:** Basecamp Consulting & Solutions LLC - **Location:** Reston, VA, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Xacta, Microsoft Access, Application Programming Interfaces (APIs), Application Layers, CentOS, Software as a Service, Cyber Security, Information Systems, Domain Name System (DNS), Identity and Access Management, Linux System Administration, OAuth, Open Web Application Security, Ping (Networking Utility), Public Key Infrastructure, Red Hat Enterprise Linux, Openid Connect, JSON Web Token, Security Assertion Markup Language (SAML), Web Application Security, Security Content Automation Protocol, Shell Script, Security Information and Event Management, Software Vulnerability Management, Information Security Management System, Load Balancing, Software Security, Rate Limiting, Siteminder, Information Technology, Enterprise Integration, Api Design, Api Gateway, Splunk, Plan of Action and Milestones - **Published:** August 22, 2026 - **Apply:** https://www.wayup.com/i-j-Senior-Cybersecurity-Integration-Engineer-Basecamp-Consulting-Solutions-LLC-934725057065936/ ## About the Role Active MBI, current and transferable as of your start date U.S. citizenship, as required for Customer contractor staff Eight years of hands-on cybersecurity or integration engineering on enterprise API gateway, IAM, or boundary security platforms in production, including three years in a Federal FISMA environment Production ownership of an enterprise API gateway or comparable platform: policy authoring, upgrades, certificate lifecycle, environment promotion, and production support Depth in API and web security protocols: OAuth 2.0, OpenID Connect, JWT validation, SAML 2.0 federation, mutual TLS, PKI, and the OWASP API Security Top 10 Experience integrating services across network and security boundaries, coordinating changes with separate firewall, proxy, and identity teams Authorship of a System Security Plan for a Federal system, writing control narratives from actual configuration and documenting inherited, hybrid, and tailored controls Experience carrying a system or major component through RMF to a signed ATO, then sustaining it under continuous monitoring Command of FISMA and NIST 800-37, 800-53 Rev 5, 800-53A, and 800-137 End-to-end vulnerability management: scanning, validating false positives, remediating, retesting, and documenting closure Linux administration on RHEL or CentOS, shell scripting, and SIEM log integration such as Splunk Technical writing strong enough that control narratives hold up under assessor review Bachelor's degree in Engineering, Computer Science, Cybersecurity, or Information Systems, or equivalent hands-on experience PREFERRED QUALIFICATIONS An active professional security certification such as CISSP, CISA, CISM, CAP or CGRC, GIAC, or Security+ Time as an ISSO or ISSM, or directly supporting one, on a FISMA-reportable system Hands-on authoring inside a GRC or RMF tool of record such as eMASS, Xacta, or CSAM An active vendor certification on the program's gateway platform, or willingness to earn it within 90 days; training provided Prior support to a Federal financial or tax administration program Experience with configuration-as-code, separated control and data planes, and API-driven gateway administration Depth in a federation platform such as Ping Federate, Ping Access, or CA SiteMinder Flexible work from home options available. ## Description POSITION OVERVIEW The Senior Cybersecurity Integration Engineer secures and integrates the Customer's enterprise API gateway, drives it through the Risk Management Framework to a signed Authority to Operate (ATO), and keeps it authorized. The role pairs hands-on security engineering at the API boundary with ownership of the System Security Plan and the continuous monitoring that sustains it. Requires an active Moderate Background Investigation (MBI) at start. RESPONSIBILITIES Design and enforce API security policy - authentication, authorization, token validation, rate limiting, payload validation, threat protection Manage TLS, mutual TLS, and certificate and key lifecycle across all environments and trust relationships Onboard applications, vendors, and SaaS services, coordinating firewall, proxy, DNS, and load balancer changes with owning teams Integrate the gateway with enterprise identity and federation services Harden gateway and hosts to STIG/SCAP and feed security telemetry to the enterprise SIEM Promote configuration through the Customer's environments under Government change control Author and maintain the SSP and control narratives against NIST 800-53 Rev 5, covering boundary, inventory, inheritance, and tailoring Run the RMF package to ATO: evidence, assessor walkthroughs, finding resolution Sustain ConMon: recurring scans, false positive validation, remediation and retest, POA&M closure, deviation requests, monthly reporting Perform security impact analysis on changes and troubleshoot across gateway, network, identity, and application layers ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)