Position Title
Cybersecurity Engineer
Position Classification
Exempt
Position Type
On-site, full-time and scheduled to work standard business hours from 8:00 a.m. to 5:00 p.m.
Work Location
MCTSSA Cyber Branch – Camp Pendleton, California
Position Description
The Cybersecurity Engineer delivers software assurance testing expertise and cybersecurity engineering support across both offensive assessment findings and independent engineering analysis. This position directly supports static and dynamic code analysis, Code Review Reporting, Security Posture Assessments, vulnerability mitigation engineering, system hardening guidance, DCO detectability engineering, and DCO integration support.
The incumbent serves as the team’s primary link between offensive findings and the implementable engineering changes that make Marine Corps systems more survivable and more defensible for DCO operators.
Essential Position Functions
-
Develop detailed, technically grounded mitigation recommendations for vulnerabilities identified during Cyber Assessment events, software assurance reviews, and vulnerability scans; tailor recommendations to the operational and programmatic constraints of each program of record.
-
Provide system and network configuration hardening guidance based on assessment findings, applicable STIGs, and industry best practices, including specific implementation steps for program engineers and administrators.
-
Analyze assessed systems and provide engineering recommendations for system or network changes that improve the ability of DCO Marines to monitor, detect, and respond to adversarial activity, including sensor placement, logging configuration, alerting thresholds, and data logging standards.
-
Assist in integrating program systems with the tools, processes, and personnel of designated DCO providers; produce DCO System Playbooks outlining incident response procedures tailored to each assessed system.
-
Implement STIG checklists across a wide range of technologies; review Windows, Linux, Cloud, network/application STIGs, DoD Security Requirement Guides (SRGs), and vendor hardening guides.
-
Conduct administration, configuration, and support of IT infrastructure including operating systems, network components, and application security.
-
Run ACAS vulnerability scans; generate reports and propose remediations for open findings.
-
Continuously monitor, report, and respond to changes in application security posture; create and track audit reports and metrics; report issues to the Information System Security Manager (ISSM).
-
Support investigation of cyber breaches; conduct analysis of multiple data sources to identify indicators of compromise.
-
Draft client reports explaining findings, recommendations, and engineering rationale for non-technical Program Office stakeholders.
-
Utilize PowerShell, JavaScript, or Python to automate repetitive cybersecurity engineering and reporting tasks.
-
Collaborate with other cybersecurity engineers and penetration testers to review security tool issues, develop integrated solutions, and ensure recommendations are implementable within each program’s operational constraints.
-
Perform additional duties as assigned by the Program Manager.
Competencies for the role
Five (5) or more years of demonstrated experience in cybersecurity.
Two (2) or more years of demonstrated experience with tools such as FTK, Wireshark, Autopsy, or similar technologies.
One (1) or more years of demonstrated experience with development of code in languages such as Python, C/C++, Ruby, or similar.
Desired: Information Assurance Technical (IAT) Level I or Level II certification.
Desired: Bachelor’s Degree in Cybersecurity, Computer Science, or equivalent.
Desired: Certified Secure Software Lifecycle Professional (CSSLP), Offensive Security Exploit Developer (OSED), or equivalent software assurance certification.
Desired: experience with DoD and Marine Corps Risk Management Framework (RMF), STIG implementation, and ACAS/Nessus vulnerability management.
Physical Requirements for the role
This position is primarily sedentary and performed in an office setting, requiring extended periods of computer use and close visual attention to technical detail. Occasional lifting of IT equipment up to 25 lbs. may be required.
Reports To
MCTSSA Cyber Branch Lead / Assigned Program Manager
Supervisory responsibilities
None.
Work Environment
The work environment is a standard office setting, which may include access to sensitive or classified systems and materials in accordance with applicable Security Classification Guides.
Security Clearance Requirements
Active DoD Secret clearance required.
Travel Requirements
Travel is anticipated to be less than 10% within the Continental United States.
Compensation
Commensurate with experience and qualifications.
Lumbee Holdings is an Equal Opportunity Employer. We do not discriminate in employment based on race, color, religion, sex (including pregnancy, sexual orientation, or gender identity), national origin, age, disability, protected veteran status, or any other status protected by applicable federal, state, or local law.
Note: This summary is not intended to be a complete description of all benefits. Employees will receive detailed information about benefit plan terms, conditions, and eligibility during onboarding. These statements are intended to describe the general nature and level of work involved for this job. It is not an exhaustive list of all responsibilities, duties, and skills required of this job.