> Markdown version of [/jobs/ext/3096669-cyber-security-engineer-iii](https://www.wearedevelopers.com/jobs/ext/3096669-cyber-security-engineer-iii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Engineer III - **Company:** OneZero Solutions - **Location:** United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Systems Engineering, Backup Devices, Bash Shell, Collaborative Software, Cyber Security, Linux, Multi-Factor Authentication, Python (Programming Language), Windows Servers, Windows PowerShell, Red Hat Enterprise Linux, Security Content Automation Protocol, Security Information and Event Management, Systems Integration, Management of Software Versions, Software Vulnerability Management, Scripting, Information Technology, Nessus, Enterprise Integration, CIS Benchmarks, Restful APIs, Splunk, Blue Team (Cyber Security), Servicenow - **Published:** September 26, 2026 - **Apply:** https://www.dice.com/job-detail/367b3580-eab3-4b42-9ca6-329a0e49c6e3 ## About the Role * Seven (7)+ years of cybersecurity or systems engineering experience, including four (4)+ years administering Tenable (Tenable Security Center / tenable.sc, Nessus, Nessus Agents, Tenable One / Vulnerability Management) at enterprise scale. * Strong Linux and Windows administration skills and scripting proficiency (Python, PowerShell, or Bash) including use of REST APIs for automation and reporting. * Experience with STIG/SCAP compliance scanning and audit files. * Active, final SECRET security clearance; U.S. citizenship. * DoD 8140/8570 IAT Level III baseline certification (e.g., CISSP, CASP+, GCIH, GCED) or IAT Level II with ability to obtain Level III within 6 months. * Experience supporting a 24x7 on-call rotation for a production security platform., * Tenable certifications (Tenable Security Center Specialist, Nessus Specialist, Tenable One). * Department of State experience, including iPost integration; DoD ACAS experience. * Experience with Wiz or another CNAPP for cloud scanning; SIEM (Splunk) integration. * Experience with CISA BOD 22-01 (KEV) and BOD 23-01 asset visibility reporting. Technical Skills * Tenable Security Center / tenable.sc, Nessus Manager and Scanners, Nessus Agents, Tenable One; plugin/feed management; scan policy and credentialed-scan design. * SCAP/STIG benchmarks, DISA STIG Viewer, CIS benchmarks. * Linux (RHEL) and Windows Server administration; Python/PowerShell/Bash; Tenable REST API. * Dashboards and reporting; ticketing (ServiceNow or equivalent); SIEM integration. Education Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field, or an additional four (4) years of directly relevant experience in lieu of degree. Remote/Hybrid/On-site and any other relevant work-environment requirement Remote. Duties are performed remotely; the selected candidate must reside within the National Capital Region (NCR). The Government does not furnish equipment; OneZero provides the laptop and collaboration tools. Position requires an OpenNet account, DoS PIV badge, multifactor authentication, and adherence to DoS SBU/CUI handling requirements. Local travel within the National Capital Region; minimal other travel. ## Description The Cyber Security Engineer III is the dedicated, full-time Tenable platform lead. The engineer owns engineering, operations, and maintenance of the CA Tenable vulnerability and compliance scanning platform used to assess on-premises consular systems (platform integrations, troubleshooting, backups, patching, user access, dashboard development, plugin updates, scan template design, and scan scheduling) and sustains 24x7x365 platform availability. The engineer also leads ad-hoc and BOD-driven scanning and agent deployment and integration efforts., * Serve as the dedicated, full-time Tenable subject matter expert; maintain 24x7x365 platform availability and lead the on-call rotation. * Administer the Tenable platform end toend:integrations, troubleshooting, backups, patching and version upgrades, user access and role management, plugin and feed updates. * Design and maintain scan templates, policies, and schedules to ensure requiredcoverage: weeklyservers, monthly workstations, and any additional cadence required by Binding Operational Directives (RMF Step 6). * Perform ad-hoc and BOD-specific scans on request to confirm hardened server builds for developers, production applications, and appliances. * Ensure all in-scope assets are onboarded, grouped, and tagged in Tenable in accordance with CA configuration standards; support CA iPost application groupings and asset inventory accuracy. * Develop dashboards, reports, and metrics for the ISSM, AO, ISSOs, and other stakeholders, including KEV, CVE, and STIG compliance reporting. * Lead Nessus Agent deployment, data ingest and sharing, pipeline, and other integration efforts. * Deliver vulnerability and compliance scan results to ISSOs within timelines and to the assessment team during RMF Step 4. * Coordinate logistics for Red Cell penetration testing and Blue Team cyber hygiene scans; support hardened-build verification. * Document platform architecture, SOPs, and configuration baselines; provide Tenable evidence for the Evidence Index and SSPs. * Mentor the Cyber Security Engineer on platform operations and serve as escalation point for scanning issues. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)