> Markdown version of [/jobs/ext/3331905-hpc-cybersecurity-engineer](https://www.wearedevelopers.com/jobs/ext/3331905-hpc-cybersecurity-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # HPC Cybersecurity Engineer - **Company:** Oak Ridge National Laboratory - **Location:** Oak Ridge, TN, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cyber Security, Information Engineering, Dynamic Host Configuration Protocol, Linux, Domain Name System (DNS), Federal Information Processing Standards (FIPS), HTTP Secure, Intrusion Detection and Prevention, Network Security, Lightweight Directory Access Protocols (LDAP), Simple Mail Transfer Protocols, Network Intrusion Detection Systems, Scientific Computating, Simple Network Management Protocols, Software Vulnerability Management, Transport Layer Security, High Performance Computing, Infrastructure as Code (IaC), Infrastructure Automation Frameworks, Information Technology, Devsecops, Blue Team (Cyber Security), Vulnerability Analysis - **Published:** September 18, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/87389931/1 ## About the Role You automate wherever possible, using Infrastructure as Code (IaC) and repeatable patterns so security can scale with operations. You can translate governance requirements into implementable standards and aggregate technical realities into clear risk-based decision options for leadership. You collaborate well, document what matters, and enjoy driving improvements that are both technically sound and audit ready. You may have more than a couple of our Preferred Qualifications and probably do not yet have any prior HPC experience. You may have technical leadership experience and/or want to grow into this role. You may or may not think Hackers is an incredible movie., * BS degree in Computer Science, Cybersecurity, or related field * Minimum of five years of relevant experience * Equivalent combination of education and experience will be considered, * MS degree in Computer Science, Cybersecurity, or related field and at least eight years of relevant experience * Strong understanding of U.S. Federal cybersecurity frameworks, standards, and guidelines including FISMA, NIST RMF (SP 800-37) and SP 800-53, FIPS 199/200, FedRAMP, and OMB Memorandums * Experience as an Information Systems Security Officer (ISSO) and/or administering systems in UNIX/Linux environments * Solid understanding of networked computing concepts and common protocols (DNS, DHCP, LDAP, SNMP, SMTP, HTTP(S), TLS/SSL) * Experience representing organization during security cybersecurity audits * Familiarity building or operating security tools such as SIEMs, vulnerability scanners, NIDS/HIDS, server telemetry, and detection engineering * Experience with incident response and Linux forensics * Familiarity with automated configuration management tools * Experience in network, application, and/or security architecture and design, including threat modeling and security review practices * Experience in a high-performance computing environment, including multi-tenant compute, high-speed interconnects, and parallel filesystems Special Requirements: * This position requires the ability to obtain and maintain a clearance from the Department of Energy. As such, this position is a Workplace Substance Abuse (WSAP) testing designated position. WSAP positions require passing a pre-placement drug test and participation in an ongoing random drug testing program. ## Description The HPC Cybersecurity Engineering team is one half of the NCCS Security and Information Engineering Group. We architect, develop, deploy, and maintain the supercomputing-specific security program (an enclave within the broader ORNL authorization boundary) and provide HPC security expertise to projects of national interest. We collaborate across incident response, blue team engineering, vulnerability research, policy architecture, and DevSecOps. We work closely with scientific and operations teams and act as liaisons to ORNL's broader risk management framework. We are a Linux focused environment with security challenges that prioritize scale, performance, and scientific computing integrity., * Translate complex technical concepts to communicate effectively with scientific, operations, project, and management staff * Help shape the Supercomputing security architectural vision and lead security reviews of new capabilities, services, and designs against core security plans * Design, implement, and automate policy/control assessments to verify cybersecurity and operational policy compliance * Engineer secure software development frameworks, tools, and guardrails that enable teams to deliver securely at HPC scale * Define and implement best practices, standards, and technical baselines within the organization * Analyze, triage, and respond to application, system, and network security relevant events * Serve as a security liaison for projects of national interest and external partners * Interpret cybersecurity policy and requirements; recommend enhancements to current policies/standards and lead implementation efforts with stakeholders * Lead vulnerability management activities including remediation coordination, patch planning, verification, and approved penetration testing * Document cybersecurity procedures, standards, control narratives, and decision records to support operations, audits, and continuous improvement * Participate in a 24/7 on-call incident response rotation ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security in modern Web Applications - OWASP to the rescue!](https://www.wearedevelopers.com/videos/724-security-in-modern-web-applications-owasp-to-the-rescue) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Top 6 Hackathons for Developers in 2023](https://www.wearedevelopers.com/magazine/263-top-6-hackathons-for-developers-in-2023) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers) - [What is a Hackathon? The Hackathon Guide](https://www.wearedevelopers.com/magazine/349-what-is-a-hackathon-the-hackathon-guide)