> Markdown version of [/jobs/ext/2500032-principal-cybersecurity-engineer](https://www.wearedevelopers.com/jobs/ext/2500032-principal-cybersecurity-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Cybersecurity Engineer - **Company:** CSI Engineering LLC - **Location:** Ogden, UT, United States - **Salary:** $124,800.0 - $145,600.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cloud Computing Security, Static Program Analysis, Cyber Security, Multi-Factor Authentication, Dynamic Program Analysis, Hardware Security Module, Identity and Access Management, Information Technology Operations, Information Systems Security Architecture Professional, Information Systems Security Engineering Professional, Python (Programming Language), Network Security, Machine Learning, OAuth, Open Source Technology, Public Key Infrastructure, Windows PowerShell, Zero Trust Network Access, Security Assertion Markup Language (SAML), Security Information and Event Management, Systems Integration, Cyber Threat Analysis, HybridCloud, Information Technology, Nessus, Terraform, Splunk, Qualys, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** August 31, 2026 - **Apply:** https://www.careerjet.com/jobad/us724a46a78a34603dd64cf71490397efc ## About the Role with technical managers to ensure required controls are implemented and security processes are followed.Build collaborative internal relationships with program and project teams, as well as external relationships with customers, regulatory bodies, other agencies, and business partners.Perform other duties as assigned.REQUIRED QUALIFICATIONSSecurity Clearance: SecretCertification Requirement: The applicant must meet DoD 8570.01-M IAT Level II, IAM Level I, or higher certification requirements on the date of hire.Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related Engineering field and a minimum of eight (8) years of experience; orMaster's degree (MS or MBA) and six (6) years of relevant experience.Certification such as CISSP, CISSP-ISSEP, CASP+ CE (CompTIA SecurityX), or CSSLP.Professional experience in information security, with a proven track record of leading large-scale projects.Experience designing and implementing secure network architectures, Zero Trust environments, and cloud security frameworks (AWS, Azure, or GCP).Deep experience operating within regulatory frameworks such as NIST 800-53, NIST 800-171, ISO 27001, CMMC, or SOC 2.Experience leading high-severity security incident responses and conducting post-mortem root cause analyses.Proficiency in threat modeling frameworks such as STRIDE or PASTA to identify vulnerabilities.Expert-level knowledge of security tooling, including SIEM (Splunk, Sentinel), EDR/XDR, firewalls, and vulnerability scanners (Nessus, Qualys).Expertise in Identity and Access Management (IAM), including OAuth, SAML, and multi-factor authentication (MFA) implementation.Ability to integrate security into CI/CD pipelines using SAST (Static Analysis) and DAST (Dynamic Analysis) tools.Ability to translate business requirements into a technical security roadmap.Ability to communicate complex technical risks to non-technical executives to secure budget and buy-in.PREFERRED QUALIFICATIONSExperience transitioning security postures across different environments, such as moving a legacy on-premises system to a hybrid-cloud or fully cloud-native environment.In the defense and aerospace environment, experience with Cross-Domain Solutions (CDS), air-gapped networks, and highly classified environments.Proven experience as a Lead or Architect responsible for the security roadmap of an entire product line or business unit.History of contributing to the security community through white papers, conference presentations, or open-source security projects.Proficiency in Python, Go, or PowerShell to automate security responses (SOAR) and infrastructure as code using Terraform or Ansible.Deep understanding of Public Key Infrastructure (PKI), quantum-resistant encryption, and Hardware Security Modules (HSMs).Ability to perform Red Teaming and adversarial simulations to test organizational resilience against advanced persistent threats (APTs).Ability to apply machine learning (ML) and artificial intelligence (AI) to anomaly detection and threat hunting.LOCATION: Hill Air Force Base, UT (Onsite)TRAVEL: Less than 10% COMPANY OVERVIEWWho we are - CSEngineering, a Service-Disabled Veteran-Owned Small Business established in 2002, is dedicated to becoming the premier engineering and services firm in our industry, all while prioritizing client satisfaction above all else.What we do - With a rich history of excellence, we boast significant expertise in a wide array of areas, including satellite systems, weapons and missile systems, naval architecture, aviation systems, IT and Enterprise Architecture, and more. We offer a comprehensive range of services, including logistics, program management, and IT operations. As a recipient of the Hire Vets Gold Medallion award, we're proud of our commitment to veteran hiring, retention, and professional development.Why should you be a part of CSE - At CSEngineering, our employees are at ## Description Principal Cybersecurity EngineerFuture OpportunityCSEngineering is seeking a Principal Cybersecurity Engineer to join our growing team! This role will support cybersecurity and information security initiatives within a federal government environment, contributing to mission-critical operations. The ideal candidate will bring extensive experience in information security, cybersecurity engineering, risk management, secure architecture, and the implementation of cybersecurity controls within complex environments.JOB RESPONSIBILITIESFulfill the Information Systems Security Engineering (ISSE) responsibilities defined in DoD Instructions 8500.01 and 8510.01, AFI 17-101 Risk Management Framework (RMF) for Air Force Information Technology (IT), and the DoD Program Manager's Guidebook for Integrating the Cybersecurity Risk Management Framework (RMF) into the System Acquisition Lifecycle.Coordinate closely with Information Systems Security Managers (ISSMs) to ensure compliance with DoD Instructions 8500.01 and 8510.01, AFI 17-101 Risk Management Framework (RMF) for Air Force Information Technology (IT), and the DoD Program Manager's Guidebook for Integrating the Cybersecurity Risk Management Framework (RMF) into the System Acquisition Lifecycle.Support efforts to integrate cybersecurity throughout the lifecycle of IT systems, including the development and review of cybersecurity-related artifacts such as System Security Plans, Cybersecurity Strategies, Cybersecurity Impact Assessments, policies, plans, and procedures.Continually assess activities and controls to secure information. Assess gaps in security and identify solutions to mitigate risk, including business processes, technical controls, and policy improvements.Assist in the development of security policies, plans, and procedures to meet government regulations and industry best practices.Develop security impact analyses.Review technical assessments.Use automated tools to analyze system security control compliance.Collaborate, Are you interested in being part of an innovative team that supports Westinghouse's mission to provide clean energy solutions? At WECTEC Staffing Services, a wholly-owned subsidiar… + 1 day ago, Are you interested in being part of an innovative team that supports Westinghouse's mission to provide clean energy solutions? At WECTEC Staffing Services, a wholly-owned subsidiar… + 1 day ago + ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)