> Markdown version of [/jobs/ext/3099465-cyber-security-engineer](https://www.wearedevelopers.com/jobs/ext/3099465-cyber-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Engineer - **Company:** OneZero Solutions - **Location:** United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Systems Engineering, Microsoft Azure, Bash Shell, Configuration Management, Static Program Analysis, Collaborative Software, Cyber Security, Continuous Integration, Linux, Multi-Factor Authentication, Github, IT Management, Python (Programming Language), Windows PowerShell, Fortify (Software), Security Content Automation Protocol, SonarQube, Tripwire, Software Vulnerability Management, Scripting, Sonatype, Software Security, Git, Gitlab-ci, Kubernetes, Information Technology, Nessus, CIS Benchmarks, Restful APIs, Terraform, Devsecops, Jenkins, Static Application Security Testing - **Published:** September 26, 2026 - **Apply:** https://www.dice.com/job-detail/a90fde5d-6e36-41ea-9fed-9becdf3927c4 ## About the Role * Five (5)+ years of cybersecurity or systems engineering experience, including two (2)+ years operating Tenable, Wiz, or a comparable enterprise vulnerability management platform. * Hands-on experience with CI/CD tooling (GitLab CI, Jenkins, Azure DevOps, or GitHub Actions) and at least one SAST/SCA or container scanning tool (e.g., SonarQube, Fortify, Snyk, Trivy, Anchore, Prisma). * Scripting proficiency (Python, PowerShell, or Bash) and comfort with REST APIs. * Active, final SECRET security clearance; U.S. citizenship. * DoD 8140/8570 IAT Level II baseline certification (e.g., Security+ CE, CySA+, GSEC) or ability to obtain within 6 months. * Working knowledge of NIST SP 800-53 Rev. 5 vulnerability and configuration management controls (RA-5, SI-2, CM-6, SA-11)., * Tenable or Wiz certification; Certified DevSecOps Professional or equivalent. * Experience with Kubernetes/containers, Terraform, and cloud (AWS/Azure) security. * Department of State or other federal civilian experience; iPost familiarity. * STIG/SCAP experience and DISA STIG Viewer proficiency. Technical Skills * Tenable (tenable.sc/NessAgents) and Wiz operations; scan scheduling and results analysis. * CI/CD security tooling: SAST, SCA/dependency scanning, container image scanning, IaC scanning (e.g., Checkov, tfsec). * Linux/Windows fundamentals, Git, Python/PowerShell/Bash, REST APIs. * NIST SP 800-53 Rev. 5, SP 800-218 (SSDF), CISA KEV, STIG/CIS benchmarks. Education Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field, or an additional four (4) years of directly relevant experience in lieu of degree. Remote/Hybrid/On-site and any other relevant work-environment requirement Remote. Duties are performed remotely; the selected candidate must reside within the National Capital Region (NCR). The Government does not furnish equipment; OneZero provides the laptop and collaboration tools. Position requires an OpenNet account, DoS PIV badge, multifactor authentication, and adherence to DoS SBU/CUI handling requirements. Local travel within the National Capital Region; minimal other travel. ## Description The Cyber Security Engineer supports daily operation of the Tenable and Wiz vulnerability and compliance scanning platforms and serves as the program's DevSecOps security engineer. The engineer deploys agents, executes and schedules scans, triages and distributes results to ISSOs, and works with development teams to ensure static analysis, dependency, container image, and infrastructure-as-code security checks are implemented in CI/CD/CM pipelines and captured as authorization evidence., * Operate Tenable andWiz dayto day: scan execution and scheduling, Nessus Agent deployment and health, asset onboarding, grouping and tagging per CA configuration standards, and quality review of results. * Distribute vulnerability and compliance scan results to ISSOs within 5 business days of scan completion; produce remediation tracking reports and metrics; supportiPostapplication groupings. * Participate in the on-call rotation and support platform backups, patching, and troubleshooting under direction of the Cyber Security Engineer III. * Triage vulnerability, KEV, CVE, and STIG scan results; assist ISSOs in prioritizing critical and high findings to Department and BOD timelines. * Ensure applicable pipeline securitycontrols (SAST, dependency scanning, container image scanning, and infrastructure-as-codechecks) are implemented in DevSecOps CI/CD/CM pipelines; document the controls for the SSP and capture scan reports in the Evidence Index (RMF Step 3). * Analyze code and pipeline findings for security weaknesses and verify that mitigation strategies are validated and sustained across the system lifecycle. * Perform risk identification and IT governance assessments throughout the CI/CD/CM pipeline; brief ISSOs on pipeline risks. * Support hardened-build verification for development and production systems and ad-hoc scanning requests. * Support agent, data ingest and sharing, and pipeline integration efforts. * Maintain scanning SOPs and runbooks; provide Tenable/Wiz evidence for control demonstrations during RMF Step 4. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)