Senior Cyber Systems Engineer - JobID-0324
Summary
A senior cybersecurity engineer who leads RMF/ATO accreditation, vulnerability management, and DevSecOps-driven continuous monitoring for U.S. Navy mission systems, working on-site in San Diego. Core technologies include RMF/eMASS, CI/CD security gates (SAST/DAST), Kubernetes, Docker, Terraform/Ansible, and ACAS/Nessus scanning.
- All applicants must be able to obtain/maintain an active Secret U.S. Security Clearance.
- This is an on-site position. Requiring at least 4 days in office, based out of our San Diego, CA location and nearby government facilities.
- Help design and implement secure, high-performance architectures for autonomous systems, AI-driven platforms, and edge-computing devices.
- Embed automated security gates (SAST, DAST, IAST, SRM) into CI/CD pipelines to ensure that security is "code-driven" rather than a manual bottleneck.
- Lead the transition from static RMF cycles to Continuous Authority to Operate (cATO) by automating control verification and continuous monitoring.
- Architect secure multi-tenant environments using advanced virtualization (Type-1 Hypervisors) and container orchestration (Kubernetes) tailored for IL5/IL6 mission sets.
- Engineer Identity, Credential, and Access Management (ICAM) solutions that enforce Zero Trust principles across distributed hardware and software nodes.
- Lead RMF efforts across all six RMF steps including Categorization, Control Selection, Control Implementation, Assessment, Authorization, and Continuous Monitoring.
- Develop and maintain RMF artifacts including SSPs, SARs, SAPs, POA&Ms, inventories, architecture diagrams, and continuous monitoring documentation.
- Coordinate directly with U.S. Navy Authorizing Officials (AOs), Security Control Assessors (SCAs), ISSMs, ISSOs, and Program Managers. Performing regular server updates, patch management, and software installations.
- Manage cybersecurity authorization packages and support ATO, IATT, and IATO activities.
- As needed, performing ACAS Scans on various devices across multiple systems
- Collect, review, and submit various STIG checklists for RMF processes
- Develop and maintain access control policies for various organization assets
- Remediate Vulnerabilities and documenting POAMs as required.
- Work with developers and engineers to implement, maintain, and review security processes to maintain compliance and ensure user permissions are accordingly
- Help develop and maintain various golden images in support of business area activities to include operating system images and virtual machines.
- Creating and maintaining detailed documentation of systems and networks for usage by both technical and non-technical stake holders
- Manage local area IDT network infrastructure per awarded contracts and network expansion efforts to support project needs. Serve as Information Systems Security Manager (ISSM) for product ATOs and, as required, IDT infrastructure networks and supported products in coordination with IDT’s CIO. As required, serve as principle on-site representative to Defense Counterintelligence and Security Agency (DCSA) and other government organizations, as needed, to ensure IT and network security requirements are met.
- Bachelor’s Degree in in Cyber Security, Information Assurance, Computer Science, Information Technology or equivalent full-time professional experience
- DoD 8570/8140 IAM Level III (CISSP, CISM) Certified
- 10+ years experience in Cybersecurity or Systems Engineering within the Defense Industrial Base (DIB), with a mastery of the Risk Management Framework (RMF).
- Ability to travel up to 10% of the time as needed
- 5+ years in Cybersecurity or Systems Engineering within the Defense Industrial Base (DIB), with a mastery of RMF; this includes:
- Experience navigating the Department of the Navy RAISE 2.0 process to achieve continuous cyber readiness and inherit platform Authority to Operate (cATO/eATO) for containerized mission applications.
- Familiarity with the Overmatch Software Armory (or similar Navy DevSecOps Platforms / RAISE Platforms of Choice) for pipeline execution, automated security gating, SBOM generation, and container scanning.
- Familiarity with deploying, hardening, or integrating software services within Navy tactical environments, specifically ACS and CANES architectures.
- Proficient in CI/CD pipelines, including automated STIG compliance, SAST/DAST, vulnerability remediation, and container hardening to meet Navy Cyber Ready directives.
- Expert-level knowledge of securing OCI-compliant containers (Docker) and Kubernetes (K8s) clusters, including network policies, service meshes (Istio), and runtime security.
- Significant experience with Server Virtualization (ESXi, KVM) and Desktop Virtualization (VDI), including hardware-root-of-trust and secure hypervisor configuration.
- Firm grasp of Infrastructure as Code (IaC) deployments of secure, reproducible environments using Terraform, Ansible, or CloudFormation.
- Experience with automated security assessment tools (ACAS/Nessus, SCAP) and the technical integration of security data into eMASS.
- Experience with configuring multiple forms of authentication to include PKI concepts.
- Experience with having to identify hardware and/or software for purchase to meet various use-cases.
- Experience with Ansible, PowerShell, Chef, Salt, Puppet, or any other configuration automation software.
- Generous benefits package
- Competitive PTO
- Paid holidays
- 401(k) with immediate vesting and matching
- 9/80 optional schedule (2nd and 4th Friday off every month)
- Tuition Assistance Reimbursement Program
- Professional Development Resources
- Pre-Tax Commuter Benefits
- Organization-Wide Monthly Tech Connect Events
- Annual Employee Recognition Awards
- Regular Social Events and Catered Lunches