Senior Cybersecurity Engineer Location: Reston, Virginia Work Arrangement: Hybrid — three days onsite Salary: $160,000–$195,000 Clearance: Active Top Secret; must be eligible for TS/SCI Cleared2Hire is seeking a Senior Cybersecurity Engineer to support a high-impact federal technology program in Reston, Virginia. This individual will help secure complex systems, identify vulnerabilities and ensure compliance across a mission-critical environment. What You’ll Do Design and implement security controls for federal information systems. Conduct vulnerability assessments and analyze security findings. Support RMF activities, security authorization and continuous monitoring. Develop and maintain SSPs, POA&Ms and assessment documentation. Partner with engineering and operations teams to remediate security risks. Support incident response and recommend improvements to security posture. Communicate technical risks clearly to program and government leadership. What You’ll Bring Active Top Secret clearance. Seven or more years of cybersecurity experience. Experience supporting federal or Department of Defense environments. Strong knowledge of RMF, NIST 800-53 and federal security requirements. Experience with vulnerability-management and SIEM platforms. Security+ required; CISSP or equivalent advanced certification preferred. Bachelor’s degree or equivalent relevant experience. Preferred Experience TS/SCI eligibility. AWS or Azure government cloud. Tenable, Splunk, ACAS, eMASS or similar tools. Zero Trust architecture or cloud security. Experience leading remediation and authorization efforts.
What you'll do
- Design and implement NIST 800-53-aligned security controls across federal information systems
- Conduct vulnerability assessments using tools such as ACAS/Tenable and analyze findings to prioritize remediation
- Own and maintain RMF artifacts including SSPs, POA&Ms, and security assessment documentation in support of ATO efforts
- Support continuous monitoring programs and security authorization activities across the program lifecycle
- Partner with engineering and operations teams to drive risk remediation and close security gaps
- Lead or support incident response activities and develop recommendations to improve overall security posture
- Translate complex technical risks into clear, actionable communications for program leadership and government stakeholders
Mission
Federal information system security — RMF/ATO lifecycle, vulnerability management, and continuous monitoring in a DoD or IC-adjacent environment
Required skills
- Risk Management Framework (RMF)
- NIST 800-53
- vulnerability management
- SIEM platforms
- security authorization / ATO
- SSP and POA&M development
- federal/DoD cybersecurity compliance
- incident response