> Markdown version of [/jobs/ext/2565051-cybersecurity-engineer](https://www.wearedevelopers.com/jobs/ext/2565051-cybersecurity-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Engineer - **Company:** Sonalysts, Inc. - **Location:** Colorado Springs, CO, United States - **Experience:** Experienced - **Salary:** $80,000.0 - $115,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Software Applications, Audit Trail, Backup Devices, Configuration Management, Cyber Security, Information Systems, Linux, Multi-Factor Authentication, Python (Programming Language), Network Architecture, Networking Cables, Nmap, Windows PowerShell, Systems Development Life Cycle, Shell Script, Security Information and Event Management, Software Engineering, Verification and Validation (Software), Virtual Machines, Scripting, Computer Networking Systems, Firewalls (Computer Science), Information Technology, Metasploit, Tenable Nessus, National Industrial Security Program Operating Manual (NISPOM), Splunk, Scap Compliance Checker, Network Server, Vulnerability Analysis - **Published:** August 6, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=6395ae9884e17e1c ## About the Role * Must be a U.S. citizen, eligible for a U.S. Department of Defense (DoD) SECRET security clearance* * Bachelor's degree in Computer Science, Information Technology, Information Systems, Computer Security or related technical field or 4 years of equivalent related experience * Minimum 3 years of experience providing information assurance or cyber security development support for system development, * Ability to work in a fast-paced environment and a desire to learn new systems and software/hardware tools * Excellent written and verbal communication skills * Possessing an active U.S. Department of Defense (DoD) security clearance* * Hold current DoD Cyber Workforce certification(s) (e.g., Security+ or equivalent certification(s)) or can obtain certification within 6 months of employment * Five years of experience providing information assurance or cyber security development support for system development * Experience with the eMASS system * Experience following DoD IA doctrine (RMF); and/or the National Industrial Security Program Operating Manual (NISPOM) and/or NIST SP 800 series publications. * Strong understanding of NIST SP 800-53 Revision 4 or 5 controls with familiarity of the development and tailoring to system policies, procedures, documentation, artifacts, and configuration management to meet security control requirements. * Knowledgeable in the use of scripting languages/tools to automate information system administration and security functions (Shell Script, PowerShell, Python, etc.) * Experience with applying security hardening techniques and procedures on information systems (access control/permissions, group policy, MFA, ACLs, etc.) * Experience with a variety of information system components including Windows, Linux, virtual machines, network cabling & infrastructure, firewalls, backup/recovery solutions, etc.) * Experience with tools and techniques in the following areas: vulnerability scanning (Tenable Nessus/ACAS, Nmap, Metasploit), configuration compliance (STIG Viewer, SCAP Compliance Checker), endpoint security (Trellix, Windows Defender), audit logs and SIEM tools (Splunk, Elastic, Windows Event Collector) . * Obtaining a U.S. Government security clearance involves a comprehensive background check. Candidates are eligible for a clearance if they have demonstrated sound financial management (including good credit) over time, are free of criminal records, have limited foreign contacts or ties, and other factors indicative of a position of trust to protect information sensitive to the U.S. Government. ## Description Sonalysts, Inc. is seeking an experienced Cybersecurity Engineer with critical thinking skills capable of developing and implementing security controls for classified network systems. Candidates should have familiarity with U.S. Department of Defense (DoD) information systems and knowledge of Information Assurance concepts to include the application of Risk Management Framework (RMF) policies and procedures. Knowledge of U.S. Air Force and/or Space Force related security procedures or systems is a plus. Submission Deadline: September 6, 2026 Prompt responses are encouraged because the deadline could be accelerated or delayed if, in our judgement, either is warranted. What you will be doing: * Working onsite at our campus in Colorado Springs, CO * Design, develop, and implement security controls to preserve confidentiality, integrity and availability of information systems * Integrate security configuration procedures and tools on Windows and Linux platforms * Evaluate requirements, select/implement security controls, translate technical concepts & control requirements into guidance, create and/or review installation procedures, conduct verification and validation of test procedures and script changes, tailor and configure security controls for specific product use, tailor platform hardening, implement application software and/or Operating System vulnerability patches, draft security assessment plans, prepare test procedures, perform security tests, and perform security vulnerability assessments using Tenable Assured Compliance Assessment Solution (ACAS) * Identify issues and recommend solutions for remediation to the software development team * Identify issues, recommend, and develop solutions for enhancing current processes and procedures * Participate in assessment and authorization (A&A) activities with various government authorities and authorization agents to obtain and maintain official system Authorization to Operate (ATO) * Provide security control guidance to the customer in compliance with the NIST SP 800-53 Revision 5 Risk Management Framework (RMF) and the respective Cognizant Security Office * Completing security DoD and Information Assurance (IA) training as required * Input data into the Enterprise Mission Assurance Support Service (eMASS) system * Perform vulnerability scans, analyze results, construct remediation plans with system engineers, and implement remediation solutions in compliance with SLAs * Support day-to-day information system operations: installing, configuring, & upgrading software, conduct preventative maintenance inspections, and resolving network/computer/peripheral issues on workstations, servers, and network infrastructure * Verify accuracy and completion of security procedures, documents, and forms * Assist with classified spills/incident response or other security-related incidents ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)