> Markdown version of [/jobs/ext/553453-senior-cybersecurity-engineer](https://www.wearedevelopers.com/jobs/ext/553453-senior-cybersecurity-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cybersecurity Engineer - **Company:** BCMC, LLC - **Location:** Falls Church, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software System Penetration Testing, Cloud Computing Security, Cyber Security, Zero Trust Network Access, Malware, Information Technology, Devsecops, Vulnerability Analysis - **Published:** June 14, 2026 - **Apply:** https://www.juju.com/job/00000000g7ywbd ## About the Role U.S. Citizenship - Active TS/SCI clearance - Ability to obtain Department of Homeland Security (DHS) Entry on Duty (EOD) Suitability - 10+ years of experience in cybersecurity engineering or security architecture - Expert knowledge of federal security frameworks (NIST 800-53, RMF, FISMA) - Experience leading security assessments and authorization activities - Strong understanding of risk management and security controls implementation - Experience with security compliance in operational environments - Knowledge of Zero Trust architecture and implementation principles - Experience assessing security of AI/ML and emerging technologies - Strong analytical and problem-solving skills - Excellent documentation and communication abilities Desired Skills: - ITIL, PMP, or similar operations/project management certification - Experience with CISA programs or similar federal cybersecurity operations - Background in security assessment of malware analysis platforms - Experience with cloud security assessment and authorization - Knowledge of critical infrastructure security requirements - Experience with continuous monitoring and automated compliance tools - Familiarity with DevSecOps and security automation practices - Background in penetration testing or vulnerability assessment Required Education: BS in Cyber Security, Computer Science, or related degree; Master's degree preferred, or HS Diploma and 7+ years of directly relevant experience Desired Certifications: - DoD 8140 IAT Level III - CAP, CRISC ## Description BCMC is supporting a U.S. Government customer to provide support for onsite incident response to civilian Government agencies and critical asset owners who experience cyber-attacks, providing immediate investigation and resolution. Contract personnel perform investigations to characterize the severity of breaches, develop mitigation plans, and assist with the restoration of services. We are seeking a Senior Cybersecurity Engineer (Controls & Assessment Lead) to support this critical customer mission. The Senior Cybersecurity Engineer will lead security controls implementation and risk assessment activities for technology integration initiatives. This role ensures all pilot and production integrations meet federal security requirements, maintain compliance frameworks, and align with CISA's risk reduction priorities while enabling innovation and modernization. Responsibilities: - Lead security controls assessment and implementation for technology integration pilots - Establish risk frameworks for pilot design and execution activities - Ensure compliance with federal security requirements (NIST, FISMA, FedRAMP) - Conduct security assessments of proposed technology insertions - Define security boundaries and controls for pilot environments - Coordinate with RMF and security teams on authorization activities - Ensure pilots maintain security posture and avoid becoming security liabilities - Assess security readiness for scaling pilots into production - Develop security metrics for measuring pilot and production outcomes - Lead security governance review processes and decision points - Ensure alignment with CISA Zero Trust Strategy and security architecture - Conduct risk assessments for technology insertions across federated environments - Support continuous monitoring and security validation of integrated capabilities - Provide security guidance to development and operations teams - Document security controls, procedures, and compliance evidence ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)