Cybersecurity / RMF Engineer

Integral Consulting Services
Fort Meade, MD, United States
4 days ago
Apply on www.jofdav.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Compensation
$110,000.0 - $140,000.0
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) Agile Methodology Cyber Security Integrated Development Environments Fortify (Software) Security Content Automation Protocol Software Engineering Kubernetes Devsecops Plan of Action and Milestones Static Application Security Testing Dynamic Application Security Testing

Job description

Integral Federal is seeking a Cybersecurity / RMF Engineer to provide hands-on cybersecurity and RMF support to the JPES/JCRM Agile/DevSecOps team. The engineer works closely with developers, DevSecOps personnel, cloud/infrastructure engineers, testers, and the IA Lead to identify, remediate, validate, and document security findings throughout the software lifecycle., * Support RMF and continuous-monitoring activities.

  • Perform and analyze ACAS, STIG, SCAP, and application-security assessments.
  • Analyze vulnerabilities and security findings.
  • Maintain POA&M and eMASS evidence.
  • Work directly with developers and technical teams to remediate findings.
  • Validate remediation and finding closure.
  • Support SSP/control evidence and assessment readiness.
  • Support release-security reviews.
  • Integrate security findings into Agile/DevSecOps workflows.
  • Support ATO sustainment and cybersecurity taskings.

Requirements

  • BA/ BS in an engineering discipline. Additional four years of experience in lieu of degree is acceptable.
  • 4+ years cybersecurity/RMF experience.
  • DoD RMF and NIST 800-53 experience.
  • STIG and vulnerability-assessment experience.
  • POA&M and security-evidence experience.
  • Ability to work effectively with software developers, DevSecOps engineers, and system administrators.
  • U.S. citizenship and required Secret eligibility

Preferred:

  • DISA experience.
  • eMASS.
  • ACAS/SCAP.
  • Fortify, SAST/DAST, or other application-security tools.
  • Java/software-development environment experience.
  • Kubernetes/container or classified-cloud familiarity.

Benefits & conditions

Salary range: $110,000-$140,000

This position is in the proposal stage. The above salary range represents a general guideline. Integral Federal considers a number of factors when determining base salary offers, such as the scope and responsibilities of the position and the candidate’s experience, education, skills, and current market conditions.

Depending on the position, employees may be eligible for overtime, shift differential, and/or discretionary bonuses in addition to base pay., We offer a comprehensive total rewards package including paid parental leave and immediate vesting in our 401(k). Give us a try and become part of a curated group of professionals at Integral Federal!

Our package also includes:

· Medical, Dental & Vision Insurance

· Flexible Spending Accounts

· Short-Term and Long-Term Disability Insurance

· Life Insurance

· Paid Time Off & Holidays

· Earned Bonuses & Awards

· Professional Training Reimbursement

· Paid Parking

· Employee Assistance Program, $110,000.00

About the company

Integral partners with federal defense, intelligence, and civilian leaders to tackle their most important challenges and deliver positive outcomes. Since our founding in 1998, we have helped clients leverage existing and emerging technologies to transform their enterprises, empower growth, drive innovation, and build sustainable success. The forward-leaning solutions we deliver are tailored to each mission with a focus on keeping our nation safe and secure.

Integral is headquartered in McLean, VA and serves clients throughout the country.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.jofdav.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

2:28 min

Understanding Kubernetes architecture and core cluster components

Marc Nimmerrichter · World Congress 2022

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all