Cybersecurity Engineer

INNOVIM, LLC
Washington, DC, United States
5 days ago
Apply on www.careerbuilder.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$90,000.0 - $107,000.0
Working hours
Regular working hours

Tech stack

Active Directory Amazon Web Services User Authentication Microsoft Azure Cloud Computing CompTIA Security+ Cyber Security Information Systems Data Centers Multi-Factor Authentication GNU Compiler Collection Identity and Access Management
+19 more
Internet Security Information Systems Security Architecture Professional Microsoft Software Role-Based Access Control Zero Trust Network Access Information Technology Security Auditing Server Administration Service Pack Security Information and Event Management Systems Integration Software Vulnerability Management Computer Network Operations Cloud Platform System Software Security Information Technology Microsoft Sentinel Data Management Splunk Vulnerability Analysis

Job description

The Cybersecurity Engineer designs, implements, and maintains enterprise security controls that enforce Zero Trust principles - identity-centric access, least-privilege enforcement, continuous monitoring, and threat detection - across cloud, network, and endpoint environments for a U.S. legislative branch agency. The role strengthens the organization’s overall security posture and improves detection and response capabilities in alignment with NIST SP 800-53 and NIST SP 800-207., * Implement and maintain enterprise security controls aligned with NIST SP 800-53 (AC, CM, SC, AU, IR, SI control families).

  • Enforce Zero Trust Architecture per NIST SP 800-207, including continuous verification, identity-centric security, and least-privilege access across cloud, network, and endpoint environments.
  • Configure and manage Identity and Access Management (IAM): authentication, authorization, role-based access control (RBAC), privileged access management (PAM), and multi-factor authentication (MFA).
  • Monitor, analyze, and respond to security events using enterprise tools (SIEM, EDR/XDR); support incident triage, containment, investigation, and remediation.
  • Maintain continuous monitoring capabilities - centralized log collection, correlation, and analysis with compliant log retention.
  • Conduct vulnerability scanning, assessment, and remediation across systems and applications; coordinate patching and mitigation.
  • Support cloud and application security (e.g., AWS, Azure): secure configuration, identity controls, and workload security.
  • Harden systems, applications, and cloud environments to secure configuration baselines; implement segmentation to limit lateral movement.
  • Perform risk analysis aligned with the NIST Risk Management Framework (RMF); conduct RCA for security incidents and control failures.
  • Develop and maintain cybersecurity SOPs, security baselines, and audit-ready documentation; support 24/7 security monitoring operations.

Requirements

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field (equivalent experience considered).
  • Minimum 8 years of hands-on cybersecurity engineering experience.
  • Demonstrated experience with SIEM (e.g., Microsoft Sentinel or Splunk), EDR/XDR (e.g., Microsoft Defender), IAM/MFA, and vulnerability management (e.g., Tenable).
  • Working knowledge of NIST SP 800-53, NIST SP 800-207 Zero Trust, and the NIST Risk Management Framework.
  • CompTIA Security+ (DoD 8140/8570 IAT/IAM) required; higher-level certification preferred.
  • S. citizenship or permanent residence status; ability to obtain a Public Trust (Tier 2) determination., * CISSP, CySA+, GIAC (e.g., GCIH, GCIA), or CEH.
  • Microsoft (SC-200/AZ-500) or AWS security certifications.
  • Hands-on experience with Microsoft Sentinel, Microsoft Defender, and Tenable.sc.
  • Experience securing hybrid Active Directory / Entra ID and M365 GCC environments.
  • Prior experience supporting federal or Congressional / legislative branch environments.

Clearance, Suitability & Security

U.S. citizenship or permanent residence status is required. The selected candidate must be able to obtain and maintain a Public Trust (Tier 2) suitability determination and will undergo an FBI criminal background check and U.S. Capitol Police fingerprinting prior to starting work, in accordance with the contract’s security requirements. Remote work is authorized; however, on-site presence at the customer’s facilities in Washington, DC (and, as needed, data-center/computing facilities in Ashburn, VA and Manassas, VA) may be required based on task assignment. Local travel to these sites is non-reimbursable. Core hours are 9:00 AM-6:00 PM ET, Monday-Friday; occasional after-hours or weekend maintenance activity may be required., Access Control, Amazon Web Services (AWS), Analysis Skills, Applications Security, Authentication, Background Investigation, CISSP - Certified Information Systems Security Professional, Change Control, Cloud Applications, Cloud Computing, CompTIA Security+, Computer Science, Computer Security, DoD Directive 8140, DoD Directive 8570, Documentation, Engineering, Enterprise Protection, Federal Bureau of Investigation (FBI), GCIA - GIAC Certified Intrusion Analyst, GCIH - GIAC Certified Incident Handler, GIAC - Global Information Assurance Certification, GNU C Compiler, IAM - Information Assurance Management, IAT - Information Assurance Technical, IR (Infrared), Identity Data Management, Incident Management, Information Technology & Information Systems, Internet Security, Microsoft Active Directory, Microsoft Product Family, Microsoft Windows Azure, Network Operations Center, Risk Analysis, Risk Management Framework (RMF), Security Attacks, Security Auditing, Security Information and Event Management (SIEM), Security Monitoring, Software Administration, Software Patches, Splunk, Standard Operating Procedures (SOP), System Integration (SI), Technical/Engineering Design, U.S. National Institute of Standards and Technology (NIST), United States Citizen, Vulnerability Scanners, Willing to Travel, Work From Home

Benefits & conditions

Salary Range: $90,000 - $107,000, commensurate with experience, education, and certifications. INNOVIM offers a comprehensive benefits package including health, dental, and vision coverage, retirement savings, paid time off, and professional development support.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerbuilder.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

51 sec

Repurposing hardware and operating underwater data centers

Chris Heilmann +1 · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

4:03 min

Managing massive power consumption scaling in AI data centers

Stephan Gillich Stephan Gillich +3 · World Congress 2024

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all