> Markdown version of [/jobs/ext/3054234-cybersecurity-engineer](https://www.wearedevelopers.com/jobs/ext/3054234-cybersecurity-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Engineer - **Company:** OCH Technologies LLC - **Location:** Washington, DC, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software System Penetration Testing, Bash Shell, Cyber Security, Information Systems, Continuous Integration, Supervisory Control and Data Acquisition (SCADA), Intrusion Detection Systems, Python (Programming Language), Machine Learning, NetCDF, Network Architecture, Network Segmentation, Windows PowerShell, Ansible, Security Software, Tripwire, Webinspect, Data Processing, Scripting, Kubernetes, Information Technology, Nessus, Firewall Services Module, Terraform, Cisco, Blue Team (Cyber Security), Docker, Vulnerability Analysis - **Published:** September 24, 2026 - **Apply:** https://www.thejobnetwork.com/job/39528afb-ba29-4ca0-bde9-e901abd33566/cybersecurity-engineer ## About the Role Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, or Physics from an accredited institution., * A minimum of eight (8)+ years of experience in cybersecurity engineering, security operations engineering, or related technical roles in federal or critical infrastructure environments. At least 2 years of relevant experience must be recent (performed within the last 3 years). * Hands-on experience administering and configuring vulnerability scanning platforms (Nessus, WebInspect, or equivalents). * Experience building and managing isolated test and simulation environments. * Understanding of network architecture, firewall configuration, IDS/IPS deployment, and network segmentation. * Experience evaluating cybersecurity tools and equipment against security requirements and producing written technical evaluations. * Scripting/automation skills (Python, Bash, PowerShell) for tool integration, data processing, and workflow automation. Security Clearance Requirement Candidate must have the ability to obtain and maintain a Public Trust Certifications * At least one of the following risk assessment certifications required: CISSP, GCED (GIAC Certified Enterprise Defender), CASP (CompTIA Advanced Security Practitioner), or CISA (Certified Information Systems Auditor). * Vendor-specific certifications (Palo Alto PCNSE, Cisco CCNP Security) a plus for specialized equipment evaluation work., * Understanding of NAS or critical infrastructure network architectures. * Prior experience at WJHTC or other FAA test facilities. * Experience with ICS/SCADA security tooling and assessment. * Experience with container-based or virtualized test environment management. * Familiarity with FAA-approved equipment lists and the ACG equipment evaluation process. * Infrastructure-as-code (Terraform, Ansible) for repeatable, version-controlled test environment builds rather than manual standup. * Container orchestration (Docker, Kubernetes) for building isolated, reproducible sandbox and simulation environments for red/blue team exercises. * CI/CD pipeline security tooling (CodeQL, Semgrep, Trivy) for evaluating software supply chain risk in candidate NAS equipment and applications. * AI/ML model evaluation tools for assessing the security posture of AI-enabled systems being introduced into NAS infrastructure. ## Description OCH Technologies is seeking a Cybersecurity Engineer to support the assessment and operations teams by maintaining scanning infrastructure, building and managing sandboxing and simulation test environments, evaluating new cybersecurity tools for FAA approval, and performing specialized testing of equipment against FAA performance and cybersecurity requirements. This role is the technical backbone that keeps the assessment and pen testing teams productive. Candidate will support building the environments they test in, maintain the tools they test with, and evaluate the equipment the FAA is considering adding to its approved list. This position supports a proposal effort and is contingent upon award, customer approval, and successful onboarding requirements. Location Hybrid- William J. Hughes Technical Center (WJHTC) Egg Harbor, NJ OR Air Traffic Control System Command Center (ATCSCC) Washington, DC This position has the potential to travel up to 25%. Core Responsibilities & Duties * Design, prepare, and maintain sandboxing and simulation test environments for penetration testing, red/blue team exercises, and specialized equipment evaluations. * Maintain and administer vulnerability scanning infrastructure including Nessus, WebInspect, and related platforms. * Perform specialized testing and evaluation of industry equipment (switches, firewalls, KVMs, TAPs, data diodes, Palo Alto appliances) against FAA and ATO cybersecurity requirements. * Evaluate NAS edge devices being considered for deployment by NAS system owners. Gather requirements, conduct assessments, and produce written evaluation reports. * Identify and evaluate emerging cybersecurity tools and technologies for potential adoption. Conduct risk analysis considering operational safety impact, data handling, supply chain risk, and integration complexity. * Support pre- and post-scan activities for NAS systems. Coordinate scanning schedules with system owners. * Develop and maintain technical documentation for test environments, tool configurations, and standard operating procedures. * Support the NCO Technical Lead with monitoring tool deployment, log source integration, and detection rule development as needed. * Provide technical support during on-site assessment and penetration testing events as needed. Responsibilities may evolve over time to support team and organizational goals but will remain consistent with the overall scope of the role., About Us: At OCH, we are more than just a government contracting firm; we are innovators and leaders in providing cutting-edge IT services and cybersecurity solutions. Driven by a set of fundamental values, we excel in creating secure, efficient, and forward-thinking solutions that empower the government agencies we work with. Our commitment to maintaining the highest standards of integrity, adapting swiftly to new challenges, and focusing on the people we serve ensures that we consistently exceed expectations and lead the industry in innovation and reliability. What Defines Us: * Integrity - We act with unwavering honesty, ensuring every decision is rooted ethically. * Adaptable - We swiftly adapt to changes, seizing opportunities to innovate and lead. * People-Focused - We prioritize relationships, championing growth and mutual success. * Accountable - We own our outcomes, striving for excellence through continuous improvement. * Collaborative - We cultivate teamwork, harnessing diverse talents to forge groundbreaking solutions. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Computer Vision from the Edge to the Cloud done easy](https://www.wearedevelopers.com/videos/263-computer-vision-from-the-edge-to-the-cloud-done-easy) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Top 6 Hackathons for Developers in 2023](https://www.wearedevelopers.com/magazine/263-top-6-hackathons-for-developers-in-2023)