Cyber Security Engineer
Trinity Global Consulting
Springfield, VA, United States
2 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.juju.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source
Tech stack
Xacta
Java (Programming Language)
Microsoft Windows
Agile Methodology
Confluence
JIRA
Big Data
CentOS
Configuration Management
Cyber Security
Databases
Linux
+12 more
Networking Hardware
Python (Programming Language)
Red Hat Enterprise Linux
Security Information and Event Management
Web Applications
Scripting
SARS Software Products
DevOps Tools - Open-source
ReactJS
Devsecops
Plan of Action and Milestones
Vulnerability Analysis
Job description
- Apply RMF processes to support system Assessment & Authorization (A&A), including control selection, implementation, assessment, and continuous monitoring
- Develop, review, and maintain security documentation such as SSPs, POA&Ms, SARs, and ATO artifacts in tools such as XACTA or eMASS
- Conduct vulnerability assessments and compliance scans (e.g., ACAS) and track remediation of findings and IAVM requirements
- Implement and validate security controls aligned with NIST 800-53, CNSSI 1253, and related DoD guidance
- Support system hardening, patching, and configuration management in compliance with STIGs for Linux, Windows, and network devices
- Monitor systems for security events and support incident response and risk mitigation activities
- Assess security impacts of system changes and support configuration control boards (CCBs)
- Collaborate with system engineers, administrators, and DevSecOps teams to integrate security throughout the system lifecycle
- Provide cybersecurity risk input to program leadership, Authorizing Officials (AOs), and stakeholders
Requirements
- Bachelor’s degree with 5+ years of experience (or equivalent experience)
- DoD 8570 IAT Level II or higher certification (e.g., Security+, CySA+, CISSP)
- Experience with RMF, A&A, POA&M, and ATO documentation (XACTA/eMASS)
- Hands-on vulnerability scanning and compliance tracking (ACAS, IAVM)
- Experience securing Linux and Windows systems, STIGs, patching, and system hardening
- Knowledge of NIST 800-series publications and incident response processes
- Strong analytical, communication, and collaboration skills
- US Citizenship required
- Active or current (within two years of active) Top Secret clearance with SCI eligibility
Desired Qualifications:
- Scripting or development experience (Python, Java, React)
- DevSecOps tools and pipeline experience
- Experience with Linux (Red Hat/CentOS), databases, web apps, or big data platforms
- Familiarity with Agile environments and tools (Jira, Confluence)
- Experience with NIST SP 800-171 and System Security Engineering (SSE)
Benefits & conditions
At Trinity Global Consulting (TGC), we value our employees and provide a comprehensive benefits package that includes:
- Medical, Dental & Vision Coverage - Coverage for eligible employees and family through CareFirst and VSP.
- Paid Time Off - PTO granted in accordance with contract requirements.
- Paid Holidays - 11 federal holidays observed annually.
- Disability & Life Insurance - Short-term/long-term disability, life insurance, and AD&D coverage included.
- 401(k) Retirement Plan - Competitive plan managed through Ameritas.
- Professional Training - Formal training provided as required, with additional learning opportunities based on role.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.juju.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
LM
Luis Minvielle
over 2 years ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
8 months ago
IK
Igor Khokhriakov
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
about 2 months ago
LM
Luis Minvielle
What’s the Difference between a Junior, Mid, and Senior Developer?
over 3 years ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
about 2 years ago
LM
Luis Minvielle
Is Software Engineering Over-Saturated?
over 2 years ago