● Brief Description: The Cyber Security Engineer implements, validates, and maintains security controls across a complex, mission-critical cloud platform hosted in AWS GovCloud supporting 300+ applications and services. This role integrates security into the DevSecOps pipeline, implements Zero Trust Architecture principles, manages container and infrastructure security, supports penetration testing and red team activities, and ensures the platform maintains continuous compliance with NIST, FISMA, FIPS, HIPAA, and VA-specific security requirements across all environments and authorization boundaries.
● Responsibilities:
○ Implement and maintain required NIST security controls in accordance with the approved baseline across all platform environments
○ Integrate Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), container scanning, and Infrastructure as Code scanning into CI/CD pipelines
○ Ensure vulnerabilities identified through scanning are remediated within Government-defined timelines
○ Enforce secure coding standards and approved dependency management practices across all platform development activities
○ Implement and maintain Zero Trust Architecture principles and least-privilege access controls across all platform components and tenant boundaries
○ Configure and manage container security including image signing, vulnerability scanning, runtime protection, and registry security
○ Implement and operate centralized secrets management ensuring automated rotation for 100% of production secrets where automation is supported
○ Support zero-trust and least-privilege principles in pipeline and deployment configurations
○ Validate security control effectiveness through automated testing, configuration validation, and periodic assessments
○ Support penetration testing, red team activities, and independent security assessments as required
○ Implement and maintain encryption in transit and at rest across all platform data flows, storage, and backup assets using FIPS 140-3 validated cryptographic modules
○ Configure and manage independent per-region KMS keys for multi-region deployments ensuring a compromise in one region does not affect data confidentiality in the other
○ Support cybersecurity incident response activities in coordination with VA security operations including forensic analysis, root cause determination, and corrective action planning
○ Implement and maintain firewall configurations, security group definitions, and network access controls in accordance with VA security policies
○ Support continuous monitoring activities including configuration validation, security event correlation, and anomaly detection
○ Ensure all platform components comply with VA Critical Security Controls and are authorized for use prior to connection to the VA network
○ Support FICAM requirements including PIV-based authentication, automated provisioning, and Identity/Authenticator/Federation Assurance Level compliance
○ Contribute to security documentation including Security Impact Assessments, Information System Vulnerability Management Plans, Security Assessment Plans, and Security Assessment Reports
○ Participate in security audits and assessments providing technical evidence, documentation, and remediation support
○ Participate in Agile and SAFe ceremonies including sprint planning, backlog refinement, demos, and retrospectives
● Qualifications:
○ Demonstrated experience in cybersecurity engineering for complex, mission-critical cloud platforms in Federal or enterprise environments
○ Hands-on experience implementing security controls in AWS cloud environments including EKS, IAM, KMS, security groups, VPC security, and encryption services
○ Experience integrating SAST, DAST, SCA, and container scanning tools into CI/CD pipelines
○ Deep knowledge of Zero Trust Architecture principles and implementation practices
○ Experience with container security including image scanning, runtime protection, and Kubernetes security policies
○ Hands-on experience with secrets management tools (AWS Secrets Manager, HashiCorp Vault, Kubernetes secrets)
○ Knowledge of FIPS 140-3 cryptographic requirements and their implementation in cloud environments
○ Experience with NIST SP 800-53 Rev. 5 security controls implementation and validation
○ Familiarity with penetration testing, red team methodologies, and vulnerability remediation practices
○ Experience with incident response including forensic analysis, evidence collection, and corrective action development
○ Knowledge of Federal identity and access management requirements including FICAM, PIV, and multi-factor authentication
○ Experience with firewall configuration, network security, and secure external connections in Federal cloud environments
○ Knowledge of HIPAA, Privacy Act, FISMA, and Federal data protection requirements
○ Experience working in Agile or SAFe environments with sprint-based delivery cadences
○ CISSP, CEH, GIAC, or equivalent cybersecurity certification required
○ AWS Security Specialty or equivalent cloud security certification preferred
○ Certified Kubernetes Security Specialist (CKS) or equivalent certification preferred
○ Bachelor's Degree from an accredited academic institution with a minimum of 5 years of experience in cybersecurity engineering, with at least 2 years implementing security controls for cloud-native platforms in Federal or enterprise IT environments
○ OR
○ Associate's Degree from an accredited academic institution with a minimum of 7 years of experience in cybersecurity engineering, with at least 3 years implementing security controls for cloud-native platforms in Federal or enterprise IT environments
● Plus:
○ Department of Veterans Affairs (VA) experience
○ Active Personal Identity Verification (PIV) card
○ Experience with VA Critical Security Controls and VA Handbook 6500 security requirements
○ Experience implementing security controls across multi-tenant authorization boundaries
○ Experience with VA-specific security tools and governance processes including SNOWCAM, TRM, and BPE
Pay: Up to $150,000.00 per year
Experience:
- cybersecurity engineering: 5 years (Required)
Work Location: Remote