> Markdown version of [/jobs/ext/2645624-cybersecurity-engineer](https://www.wearedevelopers.com/jobs/ext/2645624-cybersecurity-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Engineer - **Company:** Stralynn Consulting Services, Inc. - **Location:** Ashburn, VA, United States - **Contract:** Permanent contract - **Skills:** Amazon Web Services, User Authentication, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Multi-Factor Authentication, Identity and Access Management, Role-Based Access Control, Zero Trust Network Access, Security Information and Event Management, Software Vulnerability Management, Data Logging, Cloud Platform System, Patch Management, Vulnerability Analysis - **Published:** August 5, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=a74ab34f665b3b75 ## About the Role * Frameworks & Standards: Deep understanding and practical experience with federal cybersecurity frameworks, specifically NIST SP 800-53, NIST SP 800-207 (Zero Trust), and NIST RMF. * Security Tooling: Hands-on experience operating enterprise security platforms, including SIEM and EDR/XDR solutions. * Cloud Security: Proven experience securing public cloud and hybrid environments, specifically AWS and Azure. * IAM & Access Controls: Expertise in configuring and managing RBAC, PAM, and MFA solutions. * Operations & Remediation: Strong background in vulnerability management, patch coordination, system hardening, and incident response. * Process & Compliance: Experience participating in formal change management, conducting security impact analyses, and authoring technical SOPs. ## Description We are seeking a Cybersecurity Engineer to provide engineering, operational, and advisory support to secure, sustain, and enhance the enterprise cybersecurity environment. In this role, you will design, implement, and maintain enterprise security controls that enforce Zero Trust principles, including identity-centric access, least privilege enforcement, and continuous monitoring. You will ensure that all security technologies-across cloud platforms, identity services, endpoints, and networks-are properly configured, hardened, and continuously monitored in accordance with federal security standards (NIST SP 800-53 and NIST SP 800-207) and industry best practices., * Security Architecture & Compliance: Implement and maintain enterprise security controls aligned with NIST SP 800-53 (AC, CM, SC, AU, IR, and SI families). Enforce Zero Trust Architecture principles (NIST SP 800-207) across cloud, network, and endpoint environments. * Identity & Access Management (IAM): Design and manage least-privilege access controls, including Role-Based Access Control (RBAC), Privileged Access Management (PAM), and Multi-Factor Authentication (MFA). Secure authentication and integration with enterprise identity providers. * Threat Detection & Incident Response: Monitor, analyze, and respond to security events using enterprise tools (SIEM, EDR/XDR). Support incident triage, containment, forensic data collection, reporting, and Root Cause Analysis (RCA). * Vulnerability & Risk Management: Conduct continuous security monitoring and vulnerability assessments in alignment with the NIST Risk Management Framework (RMF). Coordinate patch management and mitigate vulnerabilities across systems, infrastructure, and applications. * Cloud & Enterprise SecOps: Secure hybrid and cloud environments (e.g., AWS, Azure), including configuring security services, network protections, and workload security. Implement segmentation to limit lateral movement. Harden systems and disable unnecessary services using secure configuration baselines. * Monitoring & Logging: Configure and maintain centralized logging, continuous monitoring, and audit capabilities. Ensure integration with enterprise SIEM tools and adherence to log retention policies. * Change Management & Documentation: Develop, implement, and update cybersecurity Standard Operating Procedures (SOPs). Ensure all security changes follow formal change management processes and maintain accurate system configurations, baselines, and asset inventories for audit readiness. * Collaboration: Serve as a technical resource for advanced security-related service desk tickets and collaborate with network, cloud, and application teams to resolve complex challenges. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)