Cyber Security Engineer III
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+14 more
Job description
The Cyber Security Engineer III is the dedicated, full-time Tenable platform lead. The engineer owns engineering, operations, and maintenance of the CA Tenable vulnerability and compliance scanning platform used to assess on-premises consular systems (platform integrations, troubleshooting, backups, patching, user access, dashboard development, plugin updates, scan template design, and scan scheduling) and sustains 24x7x365 platform availability. The engineer also leads ad-hoc and BOD-driven scanning and agent deployment and integration efforts., * Serve as the dedicated, full-time Tenable subject matter expert; maintain 24x7x365 platform availability and lead the on-call rotation.
- Administer the Tenable platform end toend:integrations, troubleshooting, backups, patching and version upgrades, user access and role management, plugin and feed updates.
- Design and maintain scan templates, policies, and schedules to ensure requiredcoverage: weeklyservers, monthly workstations, and any additional cadence required by Binding Operational Directives (RMF Step 6).
- Perform ad-hoc and BOD-specific scans on request to confirm hardened server builds for developers, production applications, and appliances.
- Ensure all in-scope assets are onboarded, grouped, and tagged in Tenable in accordance with CA configuration standards; support CA iPost application groupings and asset inventory accuracy.
- Develop dashboards, reports, and metrics for the ISSM, AO, ISSOs, and other stakeholders, including KEV, CVE, and STIG compliance reporting.
- Lead Nessus Agent deployment, data ingest and sharing, pipeline, and other integration efforts.
- Deliver vulnerability and compliance scan results to ISSOs within timelines and to the assessment team during RMF Step 4.
- Coordinate logistics for Red Cell penetration testing and Blue Team cyber hygiene scans; support hardened-build verification.
- Document platform architecture, SOPs, and configuration baselines; provide Tenable evidence for the Evidence Index and SSPs.
- Mentor the Cyber Security Engineer on platform operations and serve as escalation point for scanning issues.
Requirements
- Seven (7)+ years of cybersecurity or systems engineering experience, including four (4)+ years administering Tenable (Tenable Security Center / tenable.sc, Nessus, Nessus Agents, Tenable One / Vulnerability Management) at enterprise scale.
- Strong Linux and Windows administration skills and scripting proficiency (Python, PowerShell, or Bash) including use of REST APIs for automation and reporting.
- Experience with STIG/SCAP compliance scanning and audit files.
- Active, final SECRET security clearance; U.S. citizenship.
- DoD 8140/8570 IAT Level III baseline certification (e.g., CISSP, CASP+, GCIH, GCED) or IAT Level II with ability to obtain Level III within 6 months.
- Experience supporting a 24x7 on-call rotation for a production security platform., * Tenable certifications (Tenable Security Center Specialist, Nessus Specialist, Tenable One).
- Department of State experience, including iPost integration; DoD ACAS experience.
- Experience with Wiz or another CNAPP for cloud scanning; SIEM (Splunk) integration.
- Experience with CISA BOD 22-01 (KEV) and BOD 23-01 asset visibility reporting.
Technical Skills
- Tenable Security Center / tenable.sc, Nessus Manager and Scanners, Nessus Agents, Tenable One; plugin/feed management; scan policy and credentialed-scan design.
- SCAP/STIG benchmarks, DISA STIG Viewer, CIS benchmarks.
- Linux (RHEL) and Windows Server administration; Python/PowerShell/Bash; Tenable REST API.
- Dashboards and reporting; ticketing (ServiceNow or equivalent); SIEM integration.
Education
Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field, or an additional four (4) years of directly relevant experience in lieu of degree.
Remote/Hybrid/On-site and any other relevant work-environment requirement
Remote. Duties are performed remotely; the selected candidate must reside within the National Capital Region (NCR). The Government does not furnish equipment; OneZero provides the laptop and collaboration tools. Position requires an OpenNet account, DoS PIV badge, multifactor authentication, and adherence to DoS SBU/CUI handling requirements. Local travel within the National Capital Region; minimal other travel.
Benefits & conditions
We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. OneZero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance. Additional details are available on our website
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Fully Remote Software Engineer Jobs
Dev Digest 134 - Where pixels sing?
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Is Software Engineering Over-Saturated?