> Markdown version of [/jobs/ext/464187-technical-consultant-cyber-security-engineering](https://www.wearedevelopers.com/jobs/ext/464187-technical-consultant-cyber-security-engineering). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Technical Consultant- Cyber Security Engineering - **Company:** Environmental Systems Research Institute, Inc. - **Location:** Washington, DC, United States - **Experience:** Expert - **Salary:** $84,240.0 - $142,480.0 - **Contract:** Permanent contract - **Skills:** Xacta, Java (Programming Language), Microsoft Windows, Agile Methodology, Confluence, JIRA, Big Data, CentOS, Configuration Management, Cyber Security, Databases, Linux, Networking Hardware, Python (Programming Language), Red Hat Enterprise Linux, Security Information and Event Management, Software Vulnerability Management, Web Applications, Esri GIS (Software), Scripting, SARS Software Products, DevOps Tools - Open-source, ReactJS, Information Technology, Devsecops, Vulnerability Analysis - **Published:** June 7, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=5e243c19133905b7 ## About the Role Do you have experience in Vuls?, Do you have a Bachelor's degree?, * 5+ years of professional experience in a similar position, supporting similar responsibilities * Professional experience with RMF, A&A, POA&M, and ATO documentation (XACTA/eMASS) * Hands-on experience with vulnerability scanning and compliance tracking (ACAS, IAVM) * Experience securing Linux and Windows systems, STIGs, patching, and system hardening * Knowledge of NIST 800-series publications and incident response processes * DoD 8570 IAT Level II or higher certification (such as Security +, CySA +, CISSP) * Strong analytical, communication, and collaborative skills * US citizenship with Active or Current (within 2 years of active) Top Secret Security Clearance with SCI eligibility * Bachelor's degree in Computer Science, Cybersecurity, Information Technology or STEM related field Recommended Qualifications * Scripting or development experience (Python, Java, React) * DevSecOps tools and pipeline experience * Experience with Linux (Red Hat/CentOS), databases, web apps, or big data platforms * Familiarity with Agile environments and tools (Jira, Confluence) * Experience with NIST SP 800-171 and System Security Engineering (SSE) * Master's degree in Computer Science, Cybersecurity, Information Technology or STEM related field ## Description This position plays a hands-on role securing systems that support critical Defense and Intelligence missions. This position is focused on applying risk management frameworks, engineering security controls, and maintaining system authorizations for cloud and on-prem environments. You'll work closely with system engineers, administrators, and program teams to ensure systems are built, assessed, and operated in compliance with DoD and NIST requirements. From managing RMF and ATO packages to driving vulnerability remediation and system hardening, this role is central to maintaining secure, mission-ready systems throughout their lifecycle. Esri has a Relocation Assistance Program and can provide support with relocating to the Vienna, VA area for this position. Responsibilities * Apply RMF processes to support system Assessment & Authorization (A&A), including control selection, implementation, assessment, and continuous monitoring * Develop, review, and maintain security documentation such as SSPs, POA&Ms, SARs, and ATO artifacts in tools such as XACTA or eMASS * Conduct vulnerability assessments and compliance scans (such as ACAS) and track remediation of findings and IAVM requirements * Implement and validate security controls aligned with NIST 800-53, CNSSI 1253, and related DoD guidance * Support system hardening, patching, and configuration management in compliance with STIGs for Linux, Windows, and network devices * Monitor systems for security events and supporting incident response and risk mitigation activities * Assess security impacts of system changes and supporting configuration control boards (CCBs) * Collaborate with system engineers, administrators, and DevSecOps teams to integrate security throughout the system lifecycle * Provide cybersecurity risk input to program leadership, Authorizing Officials (AOs), and stakeholders ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)