ThinkTek
Posted 4d ago

Cybersecurity Engineer

ThinkTek
Arlington, Virginia, United States
$150k-$185k/yrOnsiteFull Time
Responsibilities
  • leading cybersecurity
  • maintaining authorization
  • assessing controls
Requirements
  • Requires active Secret clearance
  • A technical bachelor's degree
  • 5+ years of cybersecurity experience
  • 3+ years supporting DoD programs
  • RMF/eMASS expertise
  • Cloud security experience, and a qualifying DoD IAM or IAT certification
Technical tools mentioned
Risk Management Framework (RMF)Cybersecurity Risk Management Construct (CSRMC)Continuous Authorization to Operate (cATO)Zero TrusteMASSNIST 800-53DoD RMFDISA STIGFedRAMPDoD Cloud Computing Security Requirements Guide (CC SRG)Compliance-as-Code (CaC)Policy-as-Code (PaC)DevSecOpsAWSAzure

Job description

Cybersecurity Engineer (Secret Clearance)

Who We Are:
ThinkTek LLC is a fast-growing Certified SBA 8(a) and Service-Disabled Veteran-Owned Small Business (SDVOSB) company. We specialize in providing management and technology consulting services to support the business and technology modernization efforts of the Federal Government. ThinkTek was formed with the specific purpose of providing its clients a tailored solution around Program & Project Management, Strategic Planning, and IT Operations.

Position Overview

We are seeking an experienced Cybersecurity Engineer to support a Federal Government customer by providing advanced cybersecurity engineering, assessment, and compliance support. This position serves as a senior cybersecurity practitioner responsible for implementing and assessing security controls, maintaining system authorization packages, conducting security assessments, and supporting risk-based authorization decisions across a portfolio of mission-critical systems.

The Cybersecurity Engineer will work across traditional, cloud-native, and SaaS environments, supporting the Risk Management Framework (RMF), Cybersecurity Risk Management Construct (CSRMC), Continuous Authorization to Operate (cATO), and Zero Trust initiatives. The role requires deep expertise in cybersecurity engineering, security compliance automation, cloud security, vulnerability analysis, risk assessment, and governance, risk, and compliance (GRC) processes.

This position requires a highly skilled cybersecurity professional with strong technical expertise, project management experience, and an active Secret security clearance.

Responsibilities

  • Serve as the lead cybersecurity engineer and Information System Security Officer (ISSO) supporting a portfolio of DSCA mission systems across on-premises, cloud, and SaaS environments.
  • Lead RMF and Cybersecurity Risk Management Construct (CSRMC) activities, including system authorization, continuous monitoring, and maintenance of ATO/cATO packages.
  • Manage and maintain eMASS records, authorization artifacts, control implementation evidence, and Plans of Action & Milestones (POA&Ms).
  • Assess and validate NIST 800-53, DoD RMF, DISA STIG, FedRAMP, and DoD Cloud Computing Security Requirements Guide (CC SRG) security controls.
  • Conduct security control assessments and independent validations to evaluate control effectiveness and support risk-informed authorization decisions.
  • Develop Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), and authorization recommendation memorandums.
  • Analyze vulnerabilities, security findings, automated scan results, and threat data to assess mission impact and prioritize remediation activities.
  • Review and validate Compliance-as-Code (CaC), Policy-as-Code (PaC), and automated security assessment outputs to ensure accuracy and compliance.
  • Collaborate with system owners, developers, engineers, and program stakeholders to implement security controls, address findings, and reduce enterprise risk.
  • Support DevSecOps and cloud security initiatives by integrating security throughout the system development lifecycle and continuous delivery processes.
  • Monitor security posture across AWS cloud, traditional infrastructure, and SaaS platforms, ensuring compliance with federal and DoD cybersecurity requirements.
  • Brief government leadership and Authorizing Officials on system risk posture, assessment results, remediation strategies, and authorization recommendations.

Required Qualifications

  • Active Secret Security Clearance.
  • Bachelor's degree in Information Technology, Computer Science, Engineering or a related technical field from an accredited college or university.
  • Minimum 5 years of dedicated Information Assurance, Cybersecurity, or Information Security experience.
  • At least 3 consecutive years of recent experience supporting DoD cybersecurity programs.
  • Experience with Risk Management Framework (RMF) authorization processes.
  • Experience administering and maintaining eMASS authorization packages.
  • Experience conducting security control assessments, validations, and risk assessments.
  • Experience supporting ATO, cATO, and continuous monitoring programs.
  • Experience analyzing vulnerabilities, security findings, and organizational risk posture.
  • Experience supporting cloud security initiatives in AWS, Azure, or other FedRAMP-authorized environments.
  • Strong understanding of NIST 800-53 security controls and DISA STIG requirements.

Required Certifications

Candidates must possess:

  • One DoD 8570/8140 IAM Level II or IAT Level ll baseline requirements, such as:
    • CISSP
    • Security+ CE
    • CISM
    • CASP+ CE

Pay Range

The anticipated annual salary range for this position is $150,030 – $185,020. This range is a good-faith estimate and not a guarantee of compensation. Final compensation will be based on factors including experience, education, skills, geographic location, internal equity, market data, and applicable contract requirements, and may fall outside the posted range.

**THIS POSITION IS CONTINGENT UPON CONTRACT AWARD**

ThinkTek LLC is proud to be an Equal Opportunity Employer (EOE), making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. ThinkTek offers medical, dental, and vision insurance to all full-time employees; PTO and a variety of other paid leave options are also available. You can read more about ThinkTek benefits at https://www.thinktekllc.com/careers/.

 

About ThinkTek

Provides management and IT consulting services to federal agencies.

Similar jobs

Cybersecurity Engineer roles near Arlington, Virginia
8h
Save
Mark Applied
Hide
Information Assurance – Cybersecurity
Bethesda, Maryland, United States
$121k-$189k/yr OnsiteFull Time
Noblis
Noblis: Nonprofit science, technology, and strategy firm supporting government missions.
10+ YOEU.S. citizenship, Top Secret/SCI clearance with CI polygraph, BS plus 12+ years or master's plus 10+ years, and expertise in offensive and defensive security, vulnerability research, malware analysis, reverse engineering, and penetration testing.
AWS, Azure, Google Cloud, Python, C, C++, Java, Assembly, Metasploit, Burp Suite, Kali Linux, SQL, NIST, OWASP, CIS Controls, ISO 27001
22h
Save
Mark Applied
Hide
Cybersecurity Engineer
Glendale or Houston or Reston
RemoteFull Time
Bechtel
Bechtel: Designs and constructs large-scale industrial and infrastructure projects.
8+ YOEBachelor's degree in computer science, information technology, cybersecurity, or related field plus 8–10 years' experience, or 12–14 years' work experience; foundational security knowledge and cloud familiarity required.
AWS, Microsoft Azure, Google Cloud Platform, Nessus, Burp Suite, Nmap, Wireshark, Python, Bash, PowerShell, GitHub, ServiceNow, Jira, SIEM
1d
Save
Mark Applied
Hide
Cybersecurity Engineer
Chantilly, Virginia, United States
$110k-$140k/yr OnsiteFull Time
Chenega Corporation
Chenega Corporation: Provides professional government, defense, and facility support services.
3+ YOERequires 3+ years of experience, U.S. citizenship, CompTIA Security+ and CCNA, ability to obtain a Secret clearance, and expertise in systems administration, networks, cybersecurity compliance, and electronic security systems.
Microsoft Active Directory, C++, C#, JavaScript, Python, SQL, Lua, LenelS2, AMAG, Genetec, Milestone, Hirsch, Software House C-CURE 9000, SCAP, NESSUS, RMF, NIST SP 800-53, NIST SP 800-82, DoDI 8510.01, UFC 4-010-06
1d
Save
Mark Applied
Hide
Cybersecurity Engineer 3
Reston, Virginia, United States
OnsiteFull Time
Base-2 Solutions
Base-2 Solutions: Delivers engineering and technology services for national security.
7+ YOERequires 7+ years of cybersecurity engineering experience, active Top Secret/SCI with CI Polygraph, CISSP or equivalent, security-control implementation, incident response, log analysis, cloud and DevSecOps expertise.
Splunk, Fortify, Acunetix, Prisma Cloud, NIST SP 800-53, RMF, ICD 503, FISMA, FedRAMP, DevSecOps
1d
Save
Mark Applied
Hide
Cybersecurity Engineer [JOB ID 20260804]
Alexandria, Virginia, United States
OnsiteFull Time
Phoenix Cyber
Phoenix Cyber: Provides cybersecurity engineering and managed security services.
5+ YOESTEM degree or 5+ years of experience, security operations and incident response expertise, IT certifications, and security clearance required. Experience with cybersecurity platforms, Linux, and cloud infrastructure preferred.
SOAR, SIEM, IDS/IPS, DLP, WAF, Linux, AWS, Google Cloud, Microsoft Azure, E-Verify
3d
Save
Mark Applied
Hide
Cybersecurity Engineer
Suitland or Alexandria
$130k-$160k/yr OnsiteFull Time
GovCIO
GovCIO: Provides technology and mission support services to federal agencies.
9+ YOEHigh school diploma with 9+ years or equivalent experience, DoD 8570 IAT Level II certification, cybersecurity or network experience, active Secret clearance, vulnerability remediation, patching, and compliance documentation skills.
Risk Management Framework (RMF), System Security Plans (SSP), Security Assessment Reports (SAR), Enterprise Mission Assurance Support Service (eMASS), Windows, LAN, WIN 10, ACAS/Nessus, DISA STIGs, BAPS
3d
Save
Mark Applied
Hide
Cybersecurity Engineer - US Federal
Reston, Virginia, United States
$130k-$195k/yr HybridFull Time
Workday
WorkdayNASDAQ: WDAY: Provides cloud-based software for financial and human capital management.
5+ YOERequires active TS/SCI with CI polygraph, 5+ years of security experience, 2+ years of technical leadership, AWS or Microsoft Top Secret cloud experience, and a computer science or engineering degree or equivalent experience.
AWS, Microsoft Top Secret, SIEM, SOAR
3d
Save
Mark Applied
Hide
OT R&D Cybersecurity Engineer
Huntsville or Fort Belvoir or Richmond or Battle Creek or New Cumberland or Columbus or Philadelphia or Virginia or Michigan or Pennsylvania or Ohio or Alabama
RemoteFull Time
Zantech
Zantech: Provides technology and cybersecurity solutions to federal government agencies.
10+ YOERequires 10 years of relevant IT experience, 5 years of OT experience, DoD 8570/8140 IAT III and IASAE III certification, U.S. citizenship, and ability to obtain and maintain Secret clearance.
NIPRNet, SIPRNet, AWS, Microsoft Azure, Azure Security Engineer Associate, Azure Solutions Architect Expert, AZ-500, AZ-305, CCNA, CCNP, RHCE, ACAS, blockchain