Cybersecurity Engineer, Governance & Compliance - Frederick, MD

Rohde & Schwarz
United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
$96,000.0 - $130,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Systems Engineering User Authentication Authentication Protocols VoIP CompTIA Security+ Cyber Security Information Systems Linux Internet Protocol Network Security Network Architecture
+10 more
Software Requirements Analysis Data Streaming Systems Architecture Software Vulnerability Management Data Logging Software Security Firewalls (Computer Science) Information Technology Atlassian Tools CIS Benchmarks

Job description

Recently named by Newsweek as one of the Best American Mid-Sized Workplaces in 2026, Rohde & Schwarz is expanding our Cybersecurity team. The Cybersecurity Engineer, Governance & Compliance position plays a critical role in supporting the development, delivery, and sustainment of secure mission-critical systems across Rohde & Schwarz North America. This position will serve as a versatile member of the U.S. cybersecurity organization while providing primary expertise in cybersecurity governance, compliance, risk management, security requirements, and security documentation. The engineer will work across the cybersecurity lifecycle, collaborating with engineering, product development, program management, customers, and global cybersecurity teams. While Governance & Compliance will be the position’s primary area of specialization, the successful candidate will also support broader cybersecurity engineering activities including security assessments, system architecture, vulnerability management, testing, product security, and customer/program support. Initially, the position will support Air Traffic Control (ATC) programs, with the opportunity to support additional Rohde & Schwarz products, programs, and business areas as the North American cybersecurity capability grows. This position requires being onsite in our Frederick, MD facility and requires US citizenship., * Develop, maintain, and improve cybersecurity governance processes, standards, procedures, templates, and technical guidance.

  • Analyze customer, contractual, regulatory, and internal cybersecurity requirements and translate them into actionable system and engineering requirements.
  • Map technical and operational security controls to applicable frameworks, primarily NIST SP 800-53, as well as NIST CSF, DISA STIGs, CIS Benchmarks, ISO 27001, and other applicable customer or industry requirements.
  • Develop and maintain System Security Plans (SSPs), security assessment reports, control implementation summaries, risk assessments, risk matrices, security procedures, and related cybersecurity documentation.
  • Maintain traceability between customer requirements, system requirements, implemented security controls, verification activities, and supporting evidence.
  • Support cybersecurity risk management activities including risk identification, analysis, treatment, acceptance, and residual risk documentation.
  • Participate in customer cybersecurity meetings, design reviews, audits, assessments, and approval activities.
  • Assist engineering teams in interpreting cybersecurity requirements and determining practical implementation approaches.
  • Perform cybersecurity assessments of systems, subsystems, COTS products, software, and embedded components.
  • Support threat modeling, attack-surface analysis, security architecture reviews, and security design activities.
  • Review network architectures, interfaces, data flows, trust boundaries, segmentation, authentication mechanisms, logging, and security controls.
  • Support Factory Acceptance Testing (FAT), Site Acceptance Testing (SAT), customer deployments, onsite assessments, and other cybersecurity project activities when required.
  • Contribute to cybersecurity process improvement, standardization, training, knowledge transfer, automation, and development of reusable security artifacts.
  • Maintain awareness of evolving U.S. cybersecurity regulations, standards, customer requirements, and industry best practices.
  • Support the broader cybersecurity organization as priorities, programs, and customer requirements evolve.

Requirements

  • BS degree in Cybersecurity, Computer Science, Engineering, Information Systems, or a related technical field. Master’s degree preferred.
  • 7+ years of relevant cybersecurity, systems engineering, security compliance, or information assurance experience.
  • Strong understanding of NIST SP 800-53 and cybersecurity risk management principles.
  • Experience developing System Security Plans, security assessment reports, risk assessments, control matrices, or similar compliance documentation.
  • Experience interpreting contractual, regulatory, and technical cybersecurity requirements.
  • Knowledge of cybersecurity frameworks and standards such as NIST CSF, DISA STIGs, CIS Benchmarks, RMF, or ISO 27001.
  • Working knowledge of system and network security architecture including IP networking, segmentation, firewalls, ACLs, authentication, logging, encryption, and secure communications.
  • Ability to perform structured cybersecurity assessments and communicate findings and remediation recommendations.
  • Experience working with engineering, R&D, program management, customers, and other cross-functional teams.
  • Strong technical writing, analytical, organizational, and communication skills.
  • Ability to communicate cybersecurity requirements to both technical and non-technical stakeholders.
  • Experience with Atlassian products such as Jira and Confluence preferred.
  • Familiarity with mission-critical, safety-critical, aviation, transportation, defense, or critical infrastructure environments preferred.
  • Cybersecurity certifications such as CISSP, CISM, CAP/CGRC, Security+, GSEC, or similar are preferred.
  • Experience with threat modeling, security architecture, vulnerability management, or security testing is beneficial.
  • Familiarity with IP networking, VoIP, RF communications, Linux, Windows, and embedded systems is beneficial.
  • In order to be considered, candidates must be a U.S. citizen or permanent resident able to obtain an interim or final suitability determination, subject to completion and favorable adjudication of the required background investigation.

Benefits & conditions

The total compensation for this position is $96K-$130K. Total compensation includes base salary, variable pay (when applicable) plus benefits. The range is determined by the position, geographic location and level. Individual pay within the range is determined by several factors including location, education or training, relevant work history, sales incentive structure and job-related skills.

About the company

Rohde & Schwarz is a global technology company with approximately 14,000 employees and three divisions: Test & Measurement, Technology Systems and Networks & Cybersecurity. For 90 years, the company has been developing cutting-edge technology, pushing the boundaries of what is technically possible and enabling customers from various sectors such as business, government and public authorities to maintain their technological sovereignty.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Loading talks and stories from around this role…