Cyber Security Engineer 3

RPMGlobal

Bethesda, Northern (MD, KY)

Hybrid

USD 120,000 - 180,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

RPMGlobal seeks an experienced DoD cybersecurity professional to design, develop, and implement secure DoD systems compliant with RMF+ and DoDI 8510.01. You will lead RMF integration within the SDLC, maintain security artifacts, and drive vulnerability management across Windows and Linux platforms.

Experience with XACTA/eMASS, STIGs, and SCAP is essential, along with a DoD 8570 IASAE II certification. This role requires active TS/SCI clearance and a strong background in security across

Qualifications

  • Active TS/SCI with ability to obtain a CI Polygraph.
  • Bachelor's degree with a minimum of six years of experience; three additional years may substitute for the degree.
  • At least one DoD 8570.01-M IASAE Level II certification: CISSP, CISSP-ISSAP, CISSP-ISSEP, CSSLP, or CASP+ CE.
  • Developer experience in at least one scripting or programming language.
  • Experience reviewing cybersecurity vulnerabilities across systems and building mitigation plans.
  • Ability to architect and deploy vulnerability scanning solutions (OWASP, Fortify, SonarQube, Tenable).
  • Experience with XACTA, eMASS or similar tools.
  • Strong understanding of Windows and Linux/UNIX operating systems.
  • Experience with middleware/web technologies, databases, TCP/IP, and CI/CD.
  • Familiarity with NIST 800-171/800-172, NIST SSDF, CMMC, CNSSI 1253.
  • Experience supporting DoD/IC systems through the RMF+ process.

Responsibilities

  • Support secure architecture, design, and DoD system implementation per DoDI 8510.01 and NIST 800-53.
  • Lead integration of RMF activities into SDLC, including selection, implementation, and validation of security controls.
  • Develop and maintain SSPs, SARs, risk assessments, and POA&Ms.
  • Apply STIGs and validate compliance using SCAP, STIG Viewer, and ACAS.
  • Maintain scanning infrastructure and analyze vulnerabilities for mitigation or risk acceptance.
  • Support system authorization, incident response, forensics analysis, and security automation efforts.

Skills

TS/SCI clearance
DoD 8570 IASAE II
CISSP/CISSP-ISSAP/CISSP-ISSEP/CSSLP/CA
Scripting/programming
Vulnerability management
RMF+ / RMF process
Windows/Linux
CI/CD / networking
NIST 800-171/172, CNSSI 1253
DoD/IC systems experience

Education

Bachelor's degree
HS Diploma/GED with 9y exp
Associates degree with 9y exp
Master's degree with 6y exp
PhD with 6y exp

Tools

XACTA
eMASS
SCAP
STIG Viewer
Tenable

Job description

Position Summary

Support multiple task orders under the DOMEX Technology Platform contract supporting NMEC by designing, developing, and implementing secure systems in on-premises infrastructure and integrating security across the system lifecycle.

Essential Duties and Responsibilities
  • Support the secure architecture, design, and implementation of DoD systems in accordance with DoDI 8510.01, NIST SP 800-53, and other DoD security guidance.
  • Lead integration of RMF activities into the SDLC, including selection, implementation, and validation of security controls.
  • Develop and maintain SSPs, SARs, risk assessments, and POA&Ms.
  • Apply STIGs and validate compliance using SCAP, STIG Viewer, and ACAS.
  • Maintain scanning infrastructure and analyze vulnerabilities for mitigation or risk acceptance.
  • Support system authorization, incident response, forensics analysis, and security automation efforts.
Required Qualifications
  • Active TS/SCI with ability to obtain a CI Polygraph.
  • Bachelor's degree with a minimum of six years of experience in the category field. Three additional years of experience may be substituted for the bachelor's degree.
  • At least one DoD 8570.01-M IASAE Level II certification: CISSP, CISSP-ISSAP, CISSP-ISSEP, CSSLP, or CASP+ CE.
  • Developer experience preferred in at least one scripting or programming language.
  • Experience reviewing cybersecurity vulnerabilities for risk and relevance and building mitigation/remediation plans across systems, network, application, and database vulnerabilities.
  • Ability to architect, design, troubleshoot, maintain, and deploy vulnerability scanning solutions such as OWASP, Fortify, SonarQube, and Tenable.
  • Experience with XACTA, eMASS, or similar tools.
  • Strong understanding of Microsoft Windows and Linux/UNIX operating systems.
  • Experience with middleware/web technologies, databases, TCP/IP networking, and CI/CD platforms.
  • Familiarity with NIST 800-171, 800-172, NIST SSDF, CMMC, and CNSSI 1253.
  • Experience supporting DoD/IC systems through the RMF+ process.
Preferred Qualifications
  • Software development experience with Python, Java, or React.
  • Experience successfully achieving ATO under RMF+.
  • Experience with big data applications.
  • Experience with GitLab, Jira, and Confluence.
  • Experience in Agile environments.
  • Experience with OIDC or OAuth2.
  • Experience with Kubernetes, Rancher, Strimzi, Cloudera, Active Directory, and scripting languages such as Bash, Python, or PowerShell.
Required Education and Experience Equivalency
  • High School Diploma/GED with 9 years of experience.
  • Associates Degree with 9 years of experience.
  • Bachelors' Degree with 6 years of experience.
  • Masters' Degree with 6 years of experience.
  • PhD with 6 years of experience.
RequiredCertifications
  • One DoD 8570.01-M IASAE Level II certification: CISSP, CISSP-ISSAP, CISSP-ISSEP, CSSLP, or CASP+ CE.
Required Security Clearance
  • Active TS/SCI with ability to obtain a CI Polygraph.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Security Engineer 2
Cyber Security Engineer 2

Base-2 Solutions, LLC • Bethesda (MD)

On-site
USD 120,000 - 160,000
Cyber Security Engineer 3
Cyber Security Engineer 3

Base-2 Solutions, LLC • Bethesda (MD)

On-site
USD 110,000 - 150,000
Cyber Security Engineer 2
Cyber Security Engineer 2

RPMGlobal • Bethesda (MD), Northern (KY)

Hybrid
USD 110,000 - 170,000
Cyber Security Engineer 4
Cyber Security Engineer 4

Base-2 Solutions, LLC • Bethesda (MD)

On-site
USD 140,000 - 180,000
Security Engineering Architect Lead
Security Engineering Architect Lead

RPMGlobal • Bethesda (MD), Northern (KY)

Hybrid
USD 150,000 - 190,000
Cloud Security Engineer 3
Cloud Security Engineer 3

Base-2 Solutions, LLC • Bethesda (MD)

On-site
USD 140,000 - 190,000
Cloud Security Engineer 2
Cloud Security Engineer 2

RPMGlobal • Bethesda (MD), Northern (KY)

Hybrid
USD 120,000 - 160,000
Cloud Security Engineer 2
Cloud Security Engineer 2

Base-2 Solutions, LLC • Bethesda (MD)

On-site
USD 120,000 - 150,000
Cloud Security Engineer 3
Cloud Security Engineer 3

RPMGlobal • Bethesda (MD), Northern (KY)

Hybrid
USD 140,000 - 190,000
Cloud Security Engineer 4
Cloud Security Engineer 4

Base-2 Solutions, LLC • Bethesda (MD)

On-site
USD 160,000 - 210,000