Cybersecurity Engineer

Stralynn Consulting Services, Inc.
Ashburn, VA, United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services User Authentication Microsoft Azure Cloud Computing Cloud Computing Security Cyber Security Multi-Factor Authentication Identity and Access Management Role-Based Access Control Zero Trust Network Access Security Information and Event Management Software Vulnerability Management
+4 more
Data Logging Cloud Platform System Patch Management Vulnerability Analysis

Job description

We are seeking a Cybersecurity Engineer to provide engineering, operational, and advisory support to secure, sustain, and enhance the enterprise cybersecurity environment. In this role, you will design, implement, and maintain enterprise security controls that enforce Zero Trust principles, including identity-centric access, least privilege enforcement, and continuous monitoring. You will ensure that all security technologies-across cloud platforms, identity services, endpoints, and networks-are properly configured, hardened, and continuously monitored in accordance with federal security standards (NIST SP 800-53 and NIST SP 800-207) and industry best practices., * Security Architecture & Compliance: Implement and maintain enterprise security controls aligned with NIST SP 800-53 (AC, CM, SC, AU, IR, and SI families). Enforce Zero Trust Architecture principles (NIST SP 800-207) across cloud, network, and endpoint environments.

  • Identity & Access Management (IAM): Design and manage least-privilege access controls, including Role-Based Access Control (RBAC), Privileged Access Management (PAM), and Multi-Factor Authentication (MFA). Secure authentication and integration with enterprise identity providers.
  • Threat Detection & Incident Response: Monitor, analyze, and respond to security events using enterprise tools (SIEM, EDR/XDR). Support incident triage, containment, forensic data collection, reporting, and Root Cause Analysis (RCA).
  • Vulnerability & Risk Management: Conduct continuous security monitoring and vulnerability assessments in alignment with the NIST Risk Management Framework (RMF). Coordinate patch management and mitigate vulnerabilities across systems, infrastructure, and applications.
  • Cloud & Enterprise SecOps: Secure hybrid and cloud environments (e.g., AWS, Azure), including configuring security services, network protections, and workload security. Implement segmentation to limit lateral movement. Harden systems and disable unnecessary services using secure configuration baselines.
  • Monitoring & Logging: Configure and maintain centralized logging, continuous monitoring, and audit capabilities. Ensure integration with enterprise SIEM tools and adherence to log retention policies.
  • Change Management & Documentation: Develop, implement, and update cybersecurity Standard Operating Procedures (SOPs). Ensure all security changes follow formal change management processes and maintain accurate system configurations, baselines, and asset inventories for audit readiness.
  • Collaboration: Serve as a technical resource for advanced security-related service desk tickets and collaborate with network, cloud, and application teams to resolve complex challenges.

Requirements

  • Frameworks & Standards: Deep understanding and practical experience with federal cybersecurity frameworks, specifically NIST SP 800-53, NIST SP 800-207 (Zero Trust), and NIST RMF.
  • Security Tooling: Hands-on experience operating enterprise security platforms, including SIEM and EDR/XDR solutions.
  • Cloud Security: Proven experience securing public cloud and hybrid environments, specifically AWS and Azure.
  • IAM & Access Controls: Expertise in configuring and managing RBAC, PAM, and MFA solutions.
  • Operations & Remediation: Strong background in vulnerability management, patch coordination, system hardening, and incident response.
  • Process & Compliance: Experience participating in formal change management, conducting security impact analyses, and authoring technical SOPs.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:19 min

Writing secure code and utilizing threat modeling methodologies

Jasmin Azemović Jasmin Azemović · World Congress 2023

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:06 min

Outline of free tools for Microsoft Azure

Radu Vunvulea Radu Vunvulea · World Congress 2022

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

1:56 min

Discovering incidents using logs, metrics, and traces

Nele Uhlemann · World Congress 2023

Videos

See all

Related articles

See all