> Markdown version of [/jobs/ext/546790-security-engineer-cyber-security-analyst](https://www.wearedevelopers.com/jobs/ext/546790-security-engineer-cyber-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer/Cyber Security Analyst - **Company:** Ampcus Inc - **Location:** Fairfax County, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Training Data, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Continuous Integration, DevOps, Identity and Access Management, Intrusion Detection and Prevention, Network Security, Open Web Application Security, Information Security Management System, Google Cloud, Large Language Models, Gitlab, Cloudformation, AI Platforms, Information Technology, Tenable Nessus, Machine Learning Operations, Terraform, Splunk, Devsecops, Jenkins, Vulnerability Analysis - **Published:** June 15, 2026 - **Apply:** https://diversityjobs.com/career/14922805/Security-Engineer-Cyber-Security-Analyst-Virginia-Chantilly ## About the Role * Bachelor's degree in computer science, Cybersecurity, Information Technology, or a related field, or equivalent practical experience. * 5 years of hands-on experience in cybersecurity engineering or analyst role. * Demonstrable, expert-level experience with the NIST RMF and successfully achieving Client for federal or DoD systems. * Deep understanding of NIST 800-53 (Rev 4 or 5) security controls and how to implement them technically. * Strong technical background in cloud security (AWS, Azure, or GCP) and infrastructure-as-code (e.g., Terraform, CloudFormation). * Experience with security assessment and scanning tools. * Excellent written and verbal communication skills, with the ability to translate complex technical requirements for engineers and business justification for management., * Direct, hands-on experience securing AI/ML, GenAI, or Large Language Model (LLM) platforms in a production environment. * Knowledge of AI-specific security concerns (e.g., OWASP Top 10 for LLMs, MITRE ATLAS). * Relevant certifications such as: + Compliance: CISSP, CISM, CAP, CISA, Security. + Cloud: AWS Certified Security - Specialty, Azure Security Engineer Associate, Google Professional Cloud Security Engineer. * Experience with DevOps/DevSecOps practices and tools (CI/CD pipelines, GitLab, Jenkins). * Familiarity with other security frameworks such as FedRAMP, FISMA, or DoD SRG. ## Description Ampcus Inc. is a certified global provider of a broad range of Technology and Business consulting services. We are in search of a highly motivated candidate to join our talented Team. Job Title: Security Engineer/Cyber Security Analyst. Location: Chantilly, VA. Role Summary * We are looking for an experienced Security Engineer or Cybersecurity Analyst with deep expertise in the NIST Risk Management Framework (RMF) and a proven track record of achieving Authorities to Operate (ATO). * The ideal candidate will be the key technical authority responsible for guiding our AI and ML systems from development through to a secure, production-ready state, ensuring they meet stringent security and compliance requirements., * Security Compliance & ATO Leadership: + Serve as the subject matter expert on NIST Special Publication 800-53 security controls and the end-to-end RMF process. + Lead and manage the entire ATO process for new and existing systems, from initial assessment to successful accreditation. + Develop, maintain, and update all critical security documentation, including the System Security Plan (SSP), Security Assessment Report (SAR), Plan of Action and Milestones (POA&M), and Continuous Monitoring Strategy. + Conduct security control assessments, gap analyses, and work directly with engineering teams to implement necessary remediation. * AI & ML System Security Hardening: + Partner with AI/ML engineers and data scientists to embed security into the AI development lifecycle (AISecOps). + Perform threat modeling for AI systems, focusing on unique risks such as data poisoning, model inversion, adversarial attacks, and prompt injections. + Develop and implement security controls specific to AI/ML workloads, including securing training data pipelines, model repositories, and inference endpoints. + Assess the security posture of AI services and APIs and ensure their configuration meets compliance requirements. * Technical Security Engineering: + Design and implement security architecture for cloud-based (AWS, Azure, GCP) and on-premises systems hosting sensitive AI workloads. + Configure and manage security tools for vulnerability scanning, intrusion detection, and log management (e.g., Tenable, Splunk, Wiz). + Implement and validate identity and access management (IAM) policies, network security controls, and data encryption standards. * Continuous Monitoring & Improvement: + Establish and manage a continuous monitoring program to maintain security posture and ATO status. + Analyze security findings and audit logs to identify and respond to potential incidents or compliance deviations. + Stay current with emerging cybersecurity threats, especially those targeting AI/ML systems, and evolving NIST guidelines. ## Related Videos - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)