> Markdown version of [/jobs/ext/3533524-staff-cyber-security-engineer](https://www.wearedevelopers.com/jobs/ext/3533524-staff-cyber-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Cyber Security Engineer - **Company:** Leidos, Inc. - **Location:** Gaithersburg, MD, United States (Remote available) - **Experience:** Expert - **Salary:** $107,900.0 - $195,050.0 - **Contract:** Permanent contract - **Skills:** Xacta, Kubernetes Security, Agile Methodology, Artificial Intelligence, Amazon Web Services, Automation of Tests, Bash Shell, Cloud Computing, Cloud Computing Security, Cloud Engineering, Code Review, Cyber Security, Continuous Integration, Linux, Identity and Access Management, Information Systems Security Architecture Professional, Information Systems Security Engineering Professional, Python (Programming Language), Key Management, Role-Based Access Control, Red Hat Enterprise Linux, Software Tools, Fortify (Software), Zero Trust Network Access, Secure Coding, Software Engineering, SonarQube, Systems Integration, Oracle Linux, Scripting, Cloud Platform System, Istio, Generative AI, Kubernetes, Information Technology, Nessus, Checkmarx, Splunk, Devsecops, Static Application Security Testing, Vulnerability Analysis, Microservices, Dynamic Application Security Testing - **Published:** October 2, 2026 - **Apply:** https://www.careerjet.com/job/us8dca9b6af7e3ce0d04d5d0ac1cf36247/eaa ## About the Role Candidates must have a demonstrated ability to work in a dynamic and challenging environment and possess a solid understanding of the software development life cycle all while working within an Agile framework., * Clearance: Active or current Top Secret with SCI eligibility and the ability to obtain Polygraph * Education & Experience: Bachelor's degree in Cybersecurity, Computer Science, Information Assurance, Engineering, or related technical discipline and 8-12 years of relevant experience OR Master's degree with 6-10 years of relevant experience. Additional years of experience may be considered in lieu of a degree. ISSO experience must be supplemented with demonstrated technical expertise. * Certification: At least one DoD 8570.01-M IAT and one IAT Level II or higher certification e.g., CCNA Security, CySA+, Security+ CE, CISSP (or Associate) and the ability to obtain Privileged User Account (PUA)/elevated access per DoD 8570 policy, and Linux+ certification * At least 5 years of experience hardening Linux hosts and applying DISA STIG * Demonstrated experience securing Kubernetes platforms (secrets management, RBAC, etc.) and integrating security into CI/CD pipelines and containers * Demonstrated experience developing A&A packages to obtain and maintain ATO in secure environments. * Grounded knowledge in NIST SP 800-37, SP 800-53, CNSSI 1253 * XACTA/eMass experience, performing vulnerability compliance with ACAS, STIG automation * Experience with scripting languages (Bash, Python) * Understanding of secure software development practices and code reviews * Experience with encryption and transport * Understanding of microservices architecture and service mesh., * Active TS/SCI with polygraph * Experience with Commercial Cloud Services (C2S) and cloud-based enterprise services, preferably AWS * Experience supporting the Intelligence Community in RMF activities with ICD 503 and related compliance directives, policies, procedures * Experience with the Zero Trust pillars and applying Zero Trust framework to secure systems * DAST & SAST tools for on-prem (Fortify, Checkmarx, SonarQube), configuring Nessus, Splunk * Multiple IAT/IAM II or III advanced certifications such as, CISSP-ISSAP/ISSEP, CISM, CCSP, Security X/CASP+ * Cloud certifications such as AWS Solutions Architect, AWS Security Specialty, Kubernetes and Cloud Native Associate (KCNA), Certified Kubernetes Administrator (CKA), Certified Kubernetes Security Specialist (CKS) * Linux certifications such as: Red Hat Certified System Administrator - Enterprise Linux (RHCSA), Red Hat Certified Engineer - Enterprise Linux (RHCE), Red Hat Certified Architect - Enterprise Linux (RHCA) * Prior Linux sys admin experience * Oracle Linux 8 System Administrator certification * Experience applying security controls to various AI implementations * Experience with ICD 503 compliance * Experience applying security controls to Generative AI implementations * Prior network engineering experience ## Description You will work closely with the team on the following key tasks * Collect, review, assess, and provide feedback on system cybersecurity, architecture, and engineering artifacts * Collect, review, assess, and provide feedback on system cybersecurity Body-of-Evidence (BOE) results required to support DoD & IC RMF cybersecurity authorization processes * Conduct periodic compliance scanning, vulnerability assessments, and risk analysis for cloud-based systems * Implement and manage security controls for containerized applications and the underlying cloud-based infrastructure * Collaborate with DevSecOps, infrastructure, and software development teams to ensure secure coding and engineering practices * Ensure integration of security measures into software development processes, CI/CD pipelines, and engineering tools * Develop, maintain, and execute shell commands, scripts, and automation code for STIG compliance and validation * Implement and manage continuous monitoring solutions of cloud-based architectures * Support Government cybersecurity officials & program personnel in preparing cybersecurity packages, including Interim Authority to Test (IATT) packages, Authority to Operate (ATO) packages, and Change Requests (CRs) * Stay current with emerging cloud security threats, technologies, and best practices ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)