Salary
💰 $135,000 - $220,000 per year
Tech Stack
AWSCloudCyber SecuritySplunk
About the role
- Serve as the Cybersecurity SME for a cross-functional Agile team modernizing a federal case management platform.
- Design and implement a comprehensive security architecture for a cloud-based enterprise system deployed on AWS.
- Define and enforce security policies, controls, and procedures in alignment with FedRAMP, FISMA, and NIST 800-53 requirements.
- Lead the development and maintenance of key security documentation, including:
- System Security Plans (SSP)
- Security Assessment Plans (SAP)
- Plans of Action & Milestones (POA&M)
- Incident Response Plans
- Continuous Monitoring Strategy
- Support the ATO process, including coordination with agency ISSOs, auditors, and other cybersecurity stakeholders.
- Conduct regular vulnerability assessments, risk analysis, and penetration testing using approved tools (e.g., Nessus, Tenable, AWS Inspector).
- Work closely with DevOps and cloud architecture teams to ensure secure configuration and deployment of AWS services.
- Implement and monitor continuous security monitoring (ConMon) tools and processes, ensuring real-time compliance and threat detection.
- Enforce identity and access management (IAM) best practices, including role-based access control, MFA, and least privilege policies.
- Conduct regular audits and provide expert guidance during security incidents or breach simulations.
- Stay current with evolving federal cybersecurity mandates, AWS security services, and industry trends.
Requirements
- Bachelor’s degree in Cybersecurity, Information Assurance, Computer Science, or related field (or equivalent experience)
- 10+ years of experience in cybersecurity roles, with at least 5+ years supporting federal systems
- Proven experience securing applications and workloads in AWS cloud environments
- Strong knowledge of NIST RMF, NIST 800-53, FedRAMP, and FISMA compliance frameworks
- Experience managing or supporting the ATO process in a federal setting
- Familiarity with AWS native security tools (e.g., IAM, KMS, GuardDuty, Security Hub, Config, CloudTrail)
- Proficiency in using vulnerability scanning and compliance tools (e.g., Nessus, Tenable, Splunk, AWS Security tools)
- Strong understanding of DevSecOps principles and integration of security in CI/CD pipelines
- Strong communication skills and ability to interface with both technical and non-technical stakeholders
- US citizenship required
- Must be able to obtain and maintain a DoD security clearance. A current DoD Public Trust clearance is desirable
- PTO available to use immediately upon joining (prorated based on start date)
- Paid parental leave
- Individual and family health, vision, and dental benefits
- Annual budget for training, professional development and tuition reimbursement
- 401(k) plan with company match fully vested after 60 days of employment
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
cybersecuritysecurity architecturevulnerability assessmentsrisk analysispenetration testingidentity and access managementDevSecOpssecurity documentationcloud securitycompliance frameworks
Soft skills
communicationleadershipinterpersonal skillsorganizational skillsproblem-solving
Certifications
DoD security clearanceDoD Public Trust clearance