Cyber Security Engineer DoS CSS

OneZero Solutions

Washington (District of Columbia)

Remote

USD 120,000 - 160,000

Full time

11 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

OneZero Solutions LLC– a security-focused employer – seeks a Cyber Security Engineer to operate Tenable and Wiz, deploy agents, schedule scans, and coordinate with development teams to implement static analysis, dependency, container image, and IaC security checks in CI/CD/CM pipelines, with results captured as authorization evidence.

The role emphasizes risk mitigation, on-call support, hardening-build verification, and RMF Step 4 artifact generation, requiring experience with vulnerability

Qualifications

  • Five (5)+ years of cybersecurity or systems engineering experience, including two (2)+ years operating Tenable, Wiz, or a comparable enterprise vulnerability management platform.
  • Hands-on experience with CI/CD tooling (GitLab CI, Jenkins, Azure DevOps, or GitHub Actions) and at least one SAST/SCA or container scanning tool (e.g., SonarQube, Fortify, Snyk, Trivy, Anchore, Prisma).
  • Active, final SECRET security clearance; U.S. citizenship.
  • DoD 8140/8570 IAT Level II baseline certification (e.g., Security+ CE, CySA+, GSEC) or ability to obtain within 6 months.
  • Working knowledge of NIST SP 800-53 Rev. 5 vulnerability and configuration management controls (RA-5, SI-2, CM-6, SA-11).

Responsibilities

  • Operate Tenable and Wiz day to day: scan execution and scheduling, Nessus Agent deployment and health, asset onboarding, grouping and tagging per CA configuration standards, and quality review of results.
  • Distribute vulnerability and compliance scan results to ISSOs within 5 business days of scan completion; produce remediation tracking reports and metrics; support iPost application groupings.
  • Participate in the on-call rotation and support platform backups, patching, and troubleshooting under direction of the Cyber Security Engineer III.
  • Triage vulnerability, KEV, CVE, and STIG scan results; assist ISSOs in prioritizing critical and high findings to Department and BOD timelines.
  • Ensure applicable pipeline security controls (SAST, dependency scanning, container image scanning, and infrastructure-as-code checks) are implemented in DevSecOps CI/CD/CM pipelines; document the controls for the SSP and capture scan reports in the Evidence Index (RMF Step 3).
  • Analyze code and pipeline findings for security weaknesses and verify that mitigation strategies are validated and sustained across the system lifecycle.
  • Perform risk identification and IT governance assessments throughout the CI/CD/CM pipeline; brief ISSOs on pipeline risks.
  • Support hardened-build verification for development and production systems and ad-hoc scanning requests.
  • Support agent, data ingest and sharing, and pipeline integration efforts.
  • Maintain scanning SOPs and runbooks; provide Tenable/Wiz evidence for control demonstrations during RMF Step 4.

Skills

Tenable/Wiz experience
CI/CD tooling
Scripting (Python/PowerShell/Bash)
REST API proficiency
Secret clearance
DoD 8140/8570 IAT II
NIST SP 800-53 controls

Education

Bachelor's degree or equivalent experience

Tools

GitLab CI
Jenkins
Azure DevOps
GitHub Actions

Job description

We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. OneZero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance. Additional details are available on our website: https://www.onezerollc.com/careers/

Position Title:Cyber Security Engineer

Location: Remote; must reside within the National Capital Region (NCR).

Work Schedule: Full-time, 40 hours per week. Must be available during Department core hours of 9:00 a.m. – 3:00 p.m. ET, Monday – Friday, and flex working hours as needed to meet CST day-to-day and emergent requirements. No work is performed on Federal holidays or during Government closures. Participates in a rotating on-call schedule supporting 24x7x365 availability of the vulnerability and compliance scanning platforms.

Employment Type: Full-Time, Exempt (W-2), contingent upon Call Order award

Clearance: Secret

Position Summary

The Cyber Security Engineer supports daily operation of the Tenable and Wiz vulnerability and compliance scanning platforms and serves as the program's DevSecOps security engineer. The engineer deploys agents, executes and schedules scans, triages and distributes results to ISSOs, and works with development teams to ensure static analysis, dependency, container image, and infrastructure-as-code security checks are implemented in CI/CD/CM pipelines and captured as authorization evidence.

Key Responsibilities
  • Operate Tenable andWiz day to day: scan execution and scheduling, Nessus Agent deployment and health, asset onboarding, grouping and tagging per CA configuration standards, and quality review of results.
  • Distribute vulnerability and compliance scan results to ISSOs within 5 business days of scan completion; produce remediation tracking reports and metrics; support iPost application groupings.
  • Participate in the on-call rotation and support platform backups, patching, and troubleshooting under direction of the Cyber Security Engineer III.
  • Triage vulnerability, KEV, CVE, and STIG scan results; assist ISSOs in prioritizing critical and high findings to Department and BOD timelines.
  • Ensure applicable pipeline security controls (SAST, dependency scanning, container image scanning, and infrastructure-as-code checks) are implemented in DevSecOps CI/CD/CM pipelines; document the controls for the SSP and capture scan reports in the Evidence Index (RMF Step 3).
  • Analyze code and pipeline findings for security weaknesses and verify that mitigation strategies are validated and sustained across the system lifecycle.
  • Perform risk identification and IT governance assessments throughout the CI/CD/CM pipeline; brief ISSOs on pipeline risks.
  • Support hardened-build verification for development and production systems and ad-hoc scanning requests.
  • Support agent, data ingest and sharing, and pipeline integration efforts.
  • Maintain scanning SOPs and runbooks; provide Tenable/Wiz evidence for control demonstrations during RMF Step 4.
Required Qualifications
  • Five (5)+ years of cybersecurity or systems engineering experience, including two (2)+ years operating Tenable, Wiz, or a comparable enterprise vulnerability management platform.
  • Hands-on experience with CI/CD tooling (GitLab CI, Jenkins, Azure DevOps, or GitHub Actions) and at least one SAST/SCA or container scanning tool (e.g., SonarQube, Fortify, Snyk, Trivy, Anchore, Prisma).
  • Scripting proficiency (Python, PowerShell, or Bash) and comfort with REST APIs.
  • Active, final SECRET security clearance; U.S. citizenship.
  • DoD 8140/8570 IAT Level II baseline certification (e.g., Security+ CE, CySA+, GSEC) or ability to obtain within 6 months.
  • Working knowledge of NIST SP 800-53 Rev. 5 vulnerability and configuration management controls (RA-5, SI-2, CM-6, SA-11).
Preferred Qualifications
  • Tenable or Wiz certification; Certified DevSecOps Professional or equivalent.
  • Experience with Kubernetes/containers, Terraform, and cloud (AWS/Azure) security.
  • Department of State or other federal civilian experience; iPost familiarity.
  • STIG/SCAP experience and DISA STIG Viewer proficiency.
Technical Skills
  • Tenable (tenable.sc/Nessus/Agents) and Wiz operations; scan scheduling and results analysis.
  • CI/CD security tooling: SAST, SCA/dependency scanning, container image scanning, IaC scanning (e.g., Checkov, tfsec).
  • Linux/Windows fundamentals, Git, Python/PowerShell/Bash, REST APIs.
  • NIST SP 800-53 Rev. 5, SP 800-218 (SSDF), CISA KEV, STIG/CIS benchmarks.
Education

Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field, or an additional four (4) years of directly relevant experience in lieu of degree.

Remote/Hybrid/On-site and any other relevant work-environment requirement

Remote. Duties are performed remotely; the selected candidate must reside within the National Capital Region (NCR). The Government does not furnish equipment; OneZero provides the laptop and collaboration tools. Position requires an OpenNet account, DoS PIV badge, multifactor authentication, and adherence to DoS SBU/CUI handling requirements. Local travel within the National Capital Region; minimal other travel.

Position Status:

New Position, contingent upon Call Order award

OneZero Solutions LLC is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Security Engineer (Vulnerability Management & DevSecOps) DoS CSS
Cyber Security Engineer (Vulnerability Management & DevSecOps) DoS CSS

OneZero Solutions • Washington

Remote
USD 120,000 - 180,000
Health insurance
Dental
Vision
+6
Cyber Security Engineer – III DoS CSS
Cyber Security Engineer – III DoS CSS

onezerollc • Washington

Remote
USD 130,000 - 180,000
Health insurance
Dental insurance
Vision insurance
+3
Cyber Security Engineer – III DoS CSS
Cyber Security Engineer – III DoS CSS

OneZero Solutions • Washington

Remote
USD 120,000 - 150,000
Health, dental, vision, and life
401(k) with company matching
Paid time off and holidays
+2
Cyber Security Engineer – Senior / Cloud DoS CSS
Cyber Security Engineer – Senior / Cloud DoS CSS

onezerollc • Washington

Remote
USD 140,000 - 190,000
Health insurance
Dental insurance
Vision insurance
+5
Cyber Security Engineer – Senior / Cloud DoS CSS
Cyber Security Engineer – Senior / Cloud DoS CSS

OneZero Solutions • Washington

Remote
USD 150,000 - 210,000
Health insurance
Dental insurance
Vision insurance
+5
Remote Cyber Security Engineer - Vulnerability & DevSecOps
Remote Cyber Security Engineer - Vulnerability & DevSecOps

OneZero Solutions • Washington

Remote
USD 120,000 - 180,000
Health insurance
Dental
Vision
+6
Information Assurance Analyst DoS CSS
Information Assurance Analyst DoS CSS

OneZero Solutions • Washington

Remote
USD 85,000 - 110,000
Health insurance
Dental insurance
Vision insurance
+6
Remote Cybersecurity Engineer: DevSecOps & Vulnerability Ops
Remote Cybersecurity Engineer: DevSecOps & Vulnerability Ops

OneZero Solutions • Washington

Remote
USD 120,000 - 160,000
Information Assurance Analyst DoS CSS
Information Assurance Analyst DoS CSS

OneZero Solutions • Washington

Remote
USD 120,000 - 160,000
Health insurance
Dental insurance
Vision insurance
+6
Senior Information Security Analyst DoS CSS
Senior Information Security Analyst DoS CSS

OneZero Solutions • Washington

Remote
USD 110,000 - 150,000