> Markdown version of [/jobs/ext/3114681-cyber-security-engineer](https://www.wearedevelopers.com/jobs/ext/3114681-cyber-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Engineer - **Company:** Trinity Global Consulting - **Location:** Springfield, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Xacta, Java (Programming Language), Microsoft Windows, Agile Methodology, Confluence, JIRA, Big Data, CentOS, Configuration Management, Cyber Security, Databases, Linux, Networking Hardware, Python (Programming Language), Red Hat Enterprise Linux, Security Information and Event Management, Web Applications, Scripting, SARS Software Products, DevOps Tools - Open-source, ReactJS, Devsecops, Plan of Action and Milestones, Vulnerability Analysis - **Published:** September 27, 2026 - **Apply:** https://www.juju.com/job/16_e115634f5 ## About the Role * Bachelor's degree with 5+ years of experience (or equivalent experience) * DoD 8570 IAT Level II or higher certification (e.g., Security+, CySA+, CISSP) * Experience with RMF, A&A, POA&M, and ATO documentation (XACTA/eMASS) * Hands-on vulnerability scanning and compliance tracking (ACAS, IAVM) * Experience securing Linux and Windows systems, STIGs, patching, and system hardening * Knowledge of NIST 800-series publications and incident response processes * Strong analytical, communication, and collaboration skills * US Citizenship required * Active or current (within two years of active) Top Secret clearance with SCI eligibility Desired Qualifications: * Scripting or development experience (Python, Java, React) * DevSecOps tools and pipeline experience * Experience with Linux (Red Hat/CentOS), databases, web apps, or big data platforms * Familiarity with Agile environments and tools (Jira, Confluence) * Experience with NIST SP 800-171 and System Security Engineering (SSE) ## Description * Apply RMF processes to support system Assessment & Authorization (A&A), including control selection, implementation, assessment, and continuous monitoring * Develop, review, and maintain security documentation such as SSPs, POA&Ms, SARs, and ATO artifacts in tools such as XACTA or eMASS * Conduct vulnerability assessments and compliance scans (e.g., ACAS) and track remediation of findings and IAVM requirements * Implement and validate security controls aligned with NIST 800-53, CNSSI 1253, and related DoD guidance * Support system hardening, patching, and configuration management in compliance with STIGs for Linux, Windows, and network devices * Monitor systems for security events and support incident response and risk mitigation activities * Assess security impacts of system changes and support configuration control boards (CCBs) * Collaborate with system engineers, administrators, and DevSecOps teams to integrate security throughout the system lifecycle * Provide cybersecurity risk input to program leadership, Authorizing Officials (AOs), and stakeholders ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)