> Markdown version of [/jobs/ext/3414762-cybersecurity-engineer-iii-insite-secret-clearance](https://www.wearedevelopers.com/jobs/ext/3414762-cybersecurity-engineer-iii-insite-secret-clearance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Engineer III (InSITE) - Secret Clearance - **Company:** V2X Inc - **Location:** Orlando, FL, United States - **Experience:** Expert - **Salary:** $120,000.0 - $130,000.0 - **Contract:** Permanent contract - **Skills:** .NET Framework, Adobe InDesign, Agile Methodology, Software System Penetration Testing, Microsoft Azure, Burp Suite, Cloud Computing, Static Program Analysis, Cyber Security, Information Systems, Databases, Continuous Integration, Internet Information Services (IIS), SQL Azure, Windows Servers, Open Web Application Security, Package Development Process, Systems Development Life Cycle, Fortify (Software), SonarQube, SQL Databases, Software Vulnerability Management, Web Applications, Software Security, Veracode, SC Clearance, Information Technology, Nessus, Qualys, Plan of Action and Milestones, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** September 1, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9134689/cybersecurity-engineer-iii-insite-secret-clearance ## About the Role * Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or related field; or equivalent experience. * 6+ years of progressive experience in cybersecurity or system security engineering. Proven experience leading: * Application security assessments (SAST/DAST, vulnerability scans) for complex systems. * DISA STIG/SRG-based hardening for servers, applications, and databases. * RMF/ATO efforts and continuous monitoring for government/regulated systems. * Penetration testing (hands-on or through oversight of specialized teams). Knowledge, Skills & Abilities: * Expert knowledge of application security, OWASP Top 10, and secure SDLC practices. * Strong experience with vulnerability management across Dev/Test/Prod and with Windows Server, IIS, SQL/Azure SQL, and cloud-hosted environments. * Hands-on experience with: Enterprise vulnerability tools (e.g., Tenable/Nessus, Qualys). Application security tools (e.g., SonarQube, Fortify, Veracode, Burp Suite, OWASP ZAP). DISA STIGs, DoD SRGs, and their implementation in production environments. Solid understanding of NIST SP 800-53, NIST RMF, and ATO/continuous monitoring requirements; Azure cloud security preferred. Demonstrated leadership: * Leading cross-functional security initiatives and remediation. * Mentoring junior and mid-level engineers. * Collaborating effectively with managers, customers, and stakeholders. * Excellent written and verbal communication skills for technical reporting and presenting complex security issues to varied audiences. * Strong analytical and decision-making skills, balancing mission needs, risk, and compliance. CERTIFICATES, LICENSES & REGISTRATIONS: * DoD 8570/8140 compliant certification at IAT III or IASAE level (e.g., CISSP, CASP+, CSSLP, or similar) strongly preferred * Offensive or advanced security certifications (e.g., OSCP, OSWE, GPEN, GCIH) highly desirable. SECURITY CLEARANCE: * Ability to obtain and maintain a [Secret / Top Secret / as required] security clearance for the WTRS program. * U.S Citizenship ## Description V2X is seeking an experienced Cybersecurity Engineer to serve as the senior/lead cybersecurity engineer for the InSITE application within the WTRS program. This role provides technical leadership for cybersecurity activities, including program planning, static and dynamic application security testing, penetration testing, monthly vulnerability assessments, quarterly STIG reviews, and RMF/ATO and continuous monitoring. The Cybersecurity Engineer III is responsible for driving the overall security posture of the InSITE solution across Dev, Test, and Production environments., * Serve as the primary cybersecurity lead for the InSITE/WTRS program and main point of contact for program management, engineering, and customer stakeholders. * Drive cybersecurity planning, schedules, and resource estimates; represent cybersecurity in design reviews, TIMs, and Agile events. * Define and manage the integrated security assessment strategy (SAST, DAST, penetration testing, vulnerability assessments, STIG/SRG compliance) aligned with RMF and ATO requirements. * Lead application security testing: * Oversee static code analysis and web application vulnerability scanning. * Interpret findings, assess risk, and guide remediation. * Lead vulnerability management and continuous monitoring across Dev/Test/Prod: * Direct monthly scanning and analysis of servers and infrastructure. * Prioritize vulnerabilities, coordinate remediation, and refine monitoring, metrics, and reporting. * Lead quarterly STIG/SRG assessments and system hardening for Windows Server, IIS, .NET, Azure SQL, and related technologies: * Maintain accurate STIG documentation and drive remediation and risk acceptance. * Plan and lead penetration tests: * Develop test plans and rules of engagement. * Coordinate execution and produce/review reports with clear risk and mitigation guidance. * Own RMF/ATO and continuous monitoring for InSITE: * Lead Security Authorization Package development and submission. * Oversee control implementation, assessment, POA&M management, and ongoing risk activities. * Ensure scans, log reviews, and configuration checks are executed and documented. * Mentor Cybersecurity Engineers I and II; promote secure design, coding, and operations. * Produce and review formal security deliverables (vulnerability and pen test reports, ATO documentation, STIG packages) and present findings to leadership and customers. * Identify and drive process and tool improvements, including automation and CI/CD integration. * Perform other duties as assigned. ## Related Videos - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)