Principal Cybersecurity Engineer

CSI Engineering LLC
Ogden, UT, United States
6 days ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$124,800.0 - $145,600.0
Working hours
Regular working hours

Tech stack

Artificial Intelligence Amazon Web Services Microsoft Azure Cloud Computing Security Static Program Analysis Cyber Security Multi-Factor Authentication Dynamic Program Analysis Hardware Security Module Identity and Access Management Information Technology Operations Information Systems Security Architecture Professional
+22 more
Information Systems Security Engineering Professional Python (Programming Language) Network Security Machine Learning OAuth Open Source Technology Public Key Infrastructure Windows PowerShell Zero Trust Network Access Security Assertion Markup Language (SAML) Security Information and Event Management Systems Integration Cyber Threat Analysis HybridCloud Information Technology Nessus Terraform Splunk Qualys Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

Principal Cybersecurity EngineerFuture OpportunityCSEngineering is seeking a Principal Cybersecurity Engineer to join our growing team! This role will support cybersecurity and information security initiatives within a federal government environment, contributing to mission-critical operations. The ideal candidate will bring extensive experience in information security, cybersecurity engineering, risk management, secure architecture, and the implementation of cybersecurity controls within complex environments.JOB RESPONSIBILITIESFulfill the Information Systems Security Engineering (ISSE) responsibilities defined in DoD Instructions 8500.01 and 8510.01, AFI 17-101 Risk Management Framework (RMF) for Air Force Information Technology (IT), and the DoD Program Manager’s Guidebook for Integrating the Cybersecurity Risk Management Framework (RMF) into the System Acquisition Lifecycle.Coordinate closely with Information Systems Security Managers (ISSMs) to ensure compliance with DoD Instructions 8500.01 and 8510.01, AFI 17-101 Risk Management Framework (RMF) for Air Force Information Technology (IT), and the DoD Program Manager’s Guidebook for Integrating the Cybersecurity Risk Management Framework (RMF) into the System Acquisition Lifecycle.Support efforts to integrate cybersecurity throughout the lifecycle of IT systems, including the development and review of cybersecurity-related artifacts such as System Security Plans, Cybersecurity Strategies, Cybersecurity Impact Assessments, policies, plans, and procedures.Continually assess activities and controls to secure information. Assess gaps in security and identify solutions to mitigate risk, including business processes, technical controls, and policy improvements.Assist in the development of security policies, plans, and procedures to meet government regulations and industry best practices.Develop security impact analyses.Review technical assessments.Use automated tools to analyze system security control compliance.Collaborate, Are you interested in being part of an innovative team that supports Westinghouse’s mission to provide clean energy solutions? At WECTEC Staffing Services, a wholly-owned subsidiar…

  • 1 day ago, Are you interested in being part of an innovative team that supports Westinghouse’s mission to provide clean energy solutions? At WECTEC Staffing Services, a wholly-owned subsidiar…
  • 1 day ago +

Requirements

with technical managers to ensure required controls are implemented and security processes are followed.Build collaborative internal relationships with program and project teams, as well as external relationships with customers, regulatory bodies, other agencies, and business partners.Perform other duties as assigned.REQUIRED QUALIFICATIONSSecurity Clearance: SecretCertification Requirement: The applicant must meet DoD 8570.01-M IAT Level II, IAM Level I, or higher certification requirements on the date of hire.Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related Engineering field and a minimum of eight (8) years of experience; orMaster’s degree (MS or MBA) and six (6) years of relevant experience.Certification such as CISSP, CISSP-ISSEP, CASP+ CE (CompTIA SecurityX), or CSSLP.Professional experience in information security, with a proven track record of leading large-scale projects.Experience designing and implementing secure network architectures, Zero Trust environments, and cloud security frameworks (AWS, Azure, or GCP).Deep experience operating within regulatory frameworks such as NIST 800-53, NIST 800-171, ISO 27001, CMMC, or SOC 2.Experience leading high-severity security incident responses and conducting post-mortem root cause analyses.Proficiency in threat modeling frameworks such as STRIDE or PASTA to identify vulnerabilities.Expert-level knowledge of security tooling, including SIEM (Splunk, Sentinel), EDR/XDR, firewalls, and vulnerability scanners (Nessus, Qualys).Expertise in Identity and Access Management (IAM), including OAuth, SAML, and multi-factor authentication (MFA) implementation.Ability to integrate security into CI/CD pipelines using SAST (Static Analysis) and DAST (Dynamic Analysis) tools.Ability to translate business requirements into a technical security roadmap.Ability to communicate complex technical risks to non-technical executives to secure budget and buy-in.PREFERRED QUALIFICATIONSExperience transitioning security postures across different environments, such as moving a legacy on-premises system to a hybrid-cloud or fully cloud-native environment.In the defense and aerospace environment, experience with Cross-Domain Solutions (CDS), air-gapped networks, and highly classified environments.Proven experience as a Lead or Architect responsible for the security roadmap of an entire product line or business unit.History of contributing to the security community through white papers, conference presentations, or open-source security projects.Proficiency in Python, Go, or PowerShell to automate security responses (SOAR) and infrastructure as code using Terraform or Ansible.Deep understanding of Public Key Infrastructure (PKI), quantum-resistant encryption, and Hardware Security Modules (HSMs).Ability to perform Red Teaming and adversarial simulations to test organizational resilience against advanced persistent threats (APTs).Ability to apply machine learning (ML) and artificial intelligence (AI) to anomaly detection and threat hunting.LOCATION: Hill Air Force Base, UT (Onsite)TRAVEL: Less than 10% COMPANY OVERVIEWWho we are - CSEngineering, a Service-Disabled Veteran-Owned Small Business established in 2002, is dedicated to becoming the premier engineering and services firm in our industry, all while prioritizing client satisfaction above all else.What we do - With a rich history of excellence, we boast significant expertise in a wide array of areas, including satellite systems, weapons and missile systems, naval architecture, aviation systems, IT and Enterprise Architecture, and more. We offer a comprehensive range of services, including logistics, program management, and IT operations. As a recipient of the Hire Vets Gold Medallion award, we’re proud of our commitment to veteran hiring, retention, and professional development.Why should you be a part of CSE - At CSEngineering, our employees are at

Benefits & conditions

the heart of everything we do. We foster a culture of passion and growth, where individuals are encouraged to excel, build fulfilling careers, and continually strive for excellence. Our dedication to innovation and excellence propels us forward as we continuously strive to set new standards in our industry. Join us and be part of a team that’s redefining what’s possible.CSE offers a competitive salary and comprehensive benefits package, including medical, dental, life, disability, 401k, and paid time off. Job Posted by ApplicantPro

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all