Cyber Security Engineer (5462)

SMX

Hartford (CT)

On-site

USD 103,100 - 1,718,200

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
Paid leave
Retirement

Job summary

SMX, a trusted federal security partner, seeks a Cyber Security Engineer to lead security engineering, compliance, and RMF activities for cloud environments up to DoD IL4–6. Remote role supporting a Herndon, VA based team, advising partners on FedRAMP, DoD requirements, and risk management, while building automation for evidence collection and continuous monitoring.

You will collaborate with cloud engineering and DevOps to implement controls across AWS/Azure, maintain SSPs/POA&Ms, and drive

Qualifications

  • Bachelor's degree or equivalent practical experience.
  • Five+ years in cybersecurity with federal cloud security experience.
  • Experience with SSPs, POA&Ms, SARs, and authorization artifacts.
  • US citizenship with ability to obtain Secret or higher clearance.
  • Hands-on AWS/Azure or hybrid cloud security experience.

Responsibilities

  • Provide security engineering, compliance, and RMF support for FedRAMP and DoD cloud environments.
  • Advise partners on federal security requirements, authorization strategies, and audit readiness.
  • Develop and maintain authorization documentation including SSPs, SAPs, SARs, and POA&Ms.
  • Support authorization and reauthorization activities with evidence development and remediation planning.
  • Automate compliance workflows using GRC platforms, APIs, scripts, and cloud services.
  • Collaborate with cloud engineering and DevOps to implement controls across AWS/Azure/hybrid.
  • Coordinate with 3PAOs, Authorizing Officials, and stakeholders to address findings.

Skills

Analytical thinking
Documentation
Stakeholder management
Federal security knowledge
Communication
Security controls design

Education

Bachelor's degree in Info Security / CS

Tools

eMASS
Paramify
Nessus/Tenable
Splunk
Prisma Cloud

Job description

The Cyber Security Engineer will provide security engineering, compliance, and risk management support for cloud-based systems aligned with NIST SP 800-53, FedRAMP, and DoD IL4–6 requirements. The role will advise partners and customers navigating government security requirements while supporting authorization, audit readiness, and continuous monitoring activities. A key focus will be improving compliance efficiency through GRC platforms, APIs, scripts, cloud-native services, and automation for evidence collection, control validation, documentation, reporting, and remediation tracking. This position is remote supporting a Herndon, VA based team.

Essential Skills
  • Provide cybersecurity engineering and compliance support for FedRAMP and DoD-authorized cloud environments, including IL4–6.
  • Advise partners and customers on federal and DoD security requirements, authorization strategies, control implementation, and audit readiness.
  • Develop, review, and maintain authorization documentation, including SSPs, SAPs, SARs, POA&Ms, FedRAMP appendices, policies, and supporting evidence.
  • Support system authorization and reauthorization activities across FedRAMP/RMF, including gap assessments, control validation, evidence development, and remediation planning.
  • Leverage GRC platforms, APIs, scripts, and automation to streamline compliance workflows, evidence collection, documentation updates, control testing, and reporting.
  • Develop repeatable and auditable processes that reduce manual compliance effort and improve the accuracy and consistency of authorization artifacts.
  • Collaborate with cloud engineering and DevOps teams to design, implement, and validate security controls across AWS, Azure, and hybrid environments.
  • Review system changes and significant change requests to assess security impact, identify documentation updates, and maintain authorization boundaries.
  • Coordinate with system owners, engineers, 3PAOs, Authorizing Officials, and government stakeholders to address findings and support authorization outcomes.
  • Support continuous monitoring, vulnerability management, POA&Ms updates, remediation tracking, and recurring compliance deliverables.
  • Evaluate security tooling and data sources to identify opportunities for automated control validation and compliance reporting.
  • Track evolving federal cybersecurity requirements and translate them into practical technical and operational actions.
Required Skills & Experience
  • Strong analytical, documentation, and problem-solving skills with a focus on secure and compliant outcomes.
  • Excellent communication and stakeholder-management skills, including the ability to advise partners, customers, engineers, and government stakeholders.
  • Ability to translate federal security requirements into practical technical controls and operational processes.
  • U.S. citizenship with the ability to obtain and maintain a Secret or higher security clearance.
  • Bachelor’s degree in Information Security, Cybersecurity, Computer Science, or a related field, or equivalent practical experience.
  • Five or more years of cybersecurity experience, including at least three years supporting federal cloud security engineering, information assurance, RMF, or ISSO functions.
  • Knowledge of NIST SP 800-53 Rev. 5, FedRAMP Moderate and High, DoD IL4–6 overlays, RMF, and related federal compliance frameworks.
  • Experience developing and maintaining SSPs, POA&Ms, SARs, policies, control evidence, and other authorization artifacts.
  • Experience supporting authorization planning, gap assessments, audit readiness, control implementation, and remediation activities.
  • Hands-on experience with AWS, Azure, or hybrid cloud environments, including IAM, encryption, logging, configuration management, and security monitoring.
  • Experience using GRC platforms, APIs, scripting, or automation to improve compliance and security workflows.
  • Familiarity with tools such as eMASS, Paramify, Nessus/Tenable, Splunk, Prisma Cloud, or comparable solutions.
  • CISSP, CGRC/CAP, CISM, Security+, or similar cybersecurity certificate.
Desired Skills & Experience
  • Experience supporting FedRAMP, DoD, DISA, or federal agency ATO activities.
  • Experience developing automation with Python, PowerShell, REST APIs, infrastructure-as-code, or cloud-native services.
  • Experience integrating vulnerability, configuration, and cloud-security data into GRC (Paramify) and POA&Ms workflows.
  • Familiarity with DevSecOps pipelines, automated security testing, policy-as-code, and continuous control validation.
  • Knowledge of FISMA, the Privacy Act, and agency-specific security requirements.

The SMX salary determination process takes into account a number of factors, including but not limited to, geographic location, Federal Government contract labor categories, relevant prior work experience, specific skills, education and certifications. At SMX, one of our Core Values is to Invest in Our People so we offer a competitive mix of compensation, learning & development opportunities, and benefits. Some key components of our robust benefits include health insurance, paid leave, and retirement.

  • health insurance
  • paid leave
  • retirement

The proposed salary for this position is:

$103,100—$1,718,200 USD

At SMX®, we are a team of technical and domain experts dedicated to enabling your mission. From priority national security initiatives for the DoD to highly assured and compliant solutions for healthcare, we understand that digital transformation is key to your future success.

We share your vision for the future and strive to accelerate your impact on the world. We bring both cutting edge technology and an expansive view of what’s possible to every engagement. Our delivery model and unique approaches harness our deep technical and domain knowledge, providing forward-looking insights and practical solutions to power secure mission acceleration.

SMX is an Equal Opportunity employer including disabilities and veterans.

Selected applicant may be subject to a background investigation and/or education verification.

SMX does not sponsor a new applicant for employment authorization or immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, E-2, E-3, L-1 and O-1, or any EADs or other forms of work authorization that require immigration support from an employer).

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Engineer (5462)
Cyber Security Engineer (5462)

SMX • San Juan (PR)

On-site
USD 103,100 - 1,718,200
Health insurance
Paid leave
Retirement
Cyber Security Engineer (5462)
Cyber Security Engineer (5462)

Socket.dev • United States

On-site
USD 103,100 - 1,718,200
Health insurance
Paid leave
Retirement plan
IA/Cybersecurity Specialist (Secret) (4499)
IA/Cybersecurity Specialist (Secret) (4499)

SMX • Boston (MA)

On-site
USD 103,000 - 172,000
Health insurance
Paid leave
Retirement
Cleared On Site Cybersecurity Automation Architect (5357)
Cleared On Site Cybersecurity Automation Architect (5357)

SMX • United States

On-site
USD 126,100 - 212,000
Health insurance
Paid leave
Retirement benefits
IA/Cybersecurity Specialist (Secret) (4499)
IA/Cybersecurity Specialist (Secret) (4499)

SMX • United States

On-site
USD 103,000 - 172,000
Health insurance
Paid time off
Retirement plan
Cybersecurity Engineer (5316)
Cybersecurity Engineer (5316)

遠鉄システムサービス(株) • Arlington (VA)

On-site
USD 120,000 - 200,000
Health insurance
Paid leave
Retirement benefits
Cleared Hybrid Information System Security Officer (5420)
Cleared Hybrid Information System Security Officer (5420)

SMX • Town of Hanover (NY)

Hybrid
USD 103,000 - 172,000
Health insurance
Paid leave
Retirement
Cleared On Site Information Systems Security Engineer (ISSE) (5362)
Cleared On Site Information Systems Security Engineer (ISSE) (5362)

SMX • United States

On-site
USD 105,000 - 177,000
Health insurance
Paid leave
Cleared Hybrid Information System Security Officer (5420)
Cleared Hybrid Information System Security Officer (5420)

Socket.dev • Hanover (MD)

Hybrid
USD 103,000 - 172,000
Health insurance
Paid leave
Retirement
Cleared On Site ISaaS Technical Lead & Program Manager (4984)
Cleared On Site ISaaS Technical Lead & Program Manager (4984)

SMX • United States

On-site
USD 158,000 - 255,000