Cyber Security Engineer (Senior)

Pueo Business Solutions LLC

McLean (VA)

On-site

USD 120,000 - 180,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Pueo Business Solutions LLC seeks a Cybersecurity Engineer to design and secure air-gapped Kubernetes/OpenShift platforms in classified enclaves. The role focuses on container security, federal compliance (NIST 800-53, DISA STIGs, RMF/ATO), and automation across CI/CD and incident response.

Responsibilities include implementing admission controls, RBAC for multi-tenant environments, and reducing ATO lead times.

Qualifications

  • Bachelor's degree required or equivalent in cyber security, IT, or related field.
  • Experience with air-gapped and classified environments is preferred.
  • Familiarity with RMF/ATO processes and federal compliance standards is desirable.

Responsibilities

  • Design and secure air-gapped Kubernetes/OpenShift platforms in classified enclaves.
  • Implement CI/CD security automation and evidence generation for RMF/ATO workflows.
  • Lead or contribute to security initiatives across development, security, and operations teams.
  • Configure and enforce zero-trust principles, RBAC, and admission controls in isolated environments.

Skills

Kubernetes
OpenShift
RKE2
RBAC
Zero Trust
Incident response
Security automation

Education

Bachelor's degree in Cyber Security, Information Technology, or related field

Tools

Trivy
Grype
Syft
Cosign
OSCAL

Job description

Description

Pueo is known for bringing the best talent and unique tools to every opportunity. Pueo's Parliament (aka workforce) is composed of professionals who are seeking the opportunity to work in a business organization that thrives on career development and independence. In support of mission and professional growth, our Parliament has supported the development of multiple patents, proprietary tools, and applications as well as trademarked processes.

Our organization emphasizes career development across multiple career environments (at the members own pace) and ensures those who contribute broadly are properly rewarded. Pueo has four career environments where every member of the parliament can participate. Each environment has opportunities available for all levels. Opportunities are framed by an employee's desires and capabilities, and we ensure challenges, growth, and unique experiences are available for employees at all levels.

Our Career Environments (Program, Functional, Service, and Leadership) provide numerous opportunities for employees to invest in their personal growth and those things that offer fulfillment. We invest in helping our members create and execute their career development plans. Our Pods (small teams of 5 or less) are comprised of personnel with similar skillsets to ensure mentorship, understanding, and peer support.

Roles and Responsibilities:

Cybersecurity Engineer to design, and secure air-gapped Kubernetes/OpenShift platforms in classified enclaves. This role combines container platform expertise, federal compliance (NIST 800-53, DISA STIGs, RMF/ATO), CI/CD security automation, and incident response operations. Support architect disconnected container ecosystems, aid implementation of automated security controls, accelerate ATO timelines, and assess platforms supporting mixed sensitivity workloads in SCIFs.

Air-Gapped Container Platforms: Design and aid implementation of multi-tenant Kubernetes/OpenShift clusters in disconnected enclaves. Manage registry governance, image signing, SBOM/provenance, vulnerability gating, and offline patching. Implement admission control (OPA Gatekeeper, Kyverno) and RBAC for multi-tenancy in classified environments.

CI/CD Security Automation: Aid design/securing CI/CD pipelines integrating SAST, DAST, IaC scanning, and automated compliance checks. Generate RMF/ATO evidence via OSCAL mappings and eMASS integration. Enforce promotion gates requiring signed/provenanced artifacts and passing STIG checks.

Federal Compliance & RMF: Tailor NIST 800-53 controls for containerized systems using shared responsibility matrices. Apply Kubernetes/Docker/OpenShift DISA STIGs and track exceptions. Implement continuous monitoring (CONMON) dashboards via on-prem tools (Prometheus, Falco, auditd). Reduce ATO lead times through automation and evidence generation.

Zero Trust & Identity: Implement Zero Trust in Kubernetes using mTLS, service mesh (SPIFFE/SPIRE), and identity propagation across build/runtime layers. Manage offline PKI operations with short-lived certificates and air-gapped roots. Design east-west segmentation and cross-domain artifact transfer with tamper-evident controls.

Knowledge, Skills, and Abilities:
Knowledge:
  • Working knowledge of RMF, NIST standards, SA&A processes, DoD cybersecurity policies to include:
  • Federal cybersecurity frameworks: NIST 800-53, DISA STIGs, CNSS/CNSSI policies, RMF/ATO workflows
  • Container security standards and hardening baselines for Kubernetes, OpenShift, Docker
  • OSCAL control mapping frameworks and eMASS integration
  • Shared responsibility models in cloud-native and containerized environments
  • Zero Trust architecture principles and implementation patterns
  • Compliance automation and evidence generation best practices
  • Multi-domain classification handling and cross-domain data movement
Skills:
  • Strong interpersonal and communication skills to engage senior Government stakeholder
  • Hands-on expertise with Kubernetes, OpenShift, RKE2 in air-gapped/classified environments
  • Container registry management (image signing, SBOM generation, vulnerability scanning: Trivy, Grype, Syft, Cosign)
  • CI/CD pipeline design and implementation (GitLab, Jenkins) for disconnected networks with artifact promotion
  • Security testing automation: SAST, DAST, IAST, SCA, IaC scanning, and pipeline integration
  • Kubernetes security hardening, admission control (OPA Gatekeeper, Kyverno), and RBAC design
Abilities:
  • Lead or contribute to security initiatives requiring cross-functional coordination
  • Manage competing priorities and complex stakeholder relationships
  • Architect secure, scalable containerized platforms for mixed-sensitivity workloads in SCIFs
  • Map CI/CD artifacts to RMF/ATO controls and accelerate authorization timelines through automation
  • Tailor and reconcile federal compliance requirements across NIST, CNSS, and program-specific directives
  • Implement and enforce Zero Trust principles end-to-end (build through runtime)
  • Operate and troubleshoot Kubernetes clusters in air-gapped enclaves with minimal external support
  • Detect, investigate, and respond to security incidents while maintaining data integrity in classified environments
  • Coordinate between development, security, and operations teams to implement secure, compliant practices
  • Design and execute disaster recovery and resilience strategies across isolated sites
Requirements
IAT/IAM III Required:
  • Certified Information Security Manager (CISM)
  • Certified Information Security Analyst (CISA)
  • Certified Information Systems Security Professional (CISSP)
Certifications Preferred
  • Certified Kubernetes Administrator (CKA)
  • Certified Kubernetes Security Specialist (CKS)
  • GIAC Security Essentials Certification (GSEC)
  • Red Hat Certified Specialist in Kubernetes Administration (RHCSA/RHCE)
  • Certified Application Security Engineer (CASE)
Education

Bachelor's degree in Cyber Security, Information Technology, or related field.

Security Requirement

Hold a Top Secret Security Clearance with SCI eligibility.

Ability to Pass CI Poly.

Equal Employment Opportunity

Pueo is an equal employment opportunity employer and affirmative action employer. All interested individuals will receive consideration and will not be discriminated against on the basis of race, color, religion, sex, national origin, disability, age, sexual orientation, gender identity, genetic information, or protected veteran status. Pueo takes affirmative action in support of its policy to advance diversity and inclusion of individuals who are minorities, women, protected veterans, and individuals with disabilities.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

Pueo Business Solutions LLC • McLean (VA)

On-site
USD 120,000 - 160,000
Senior Air-Gapped Kubernetes Security Engineer
Senior Air-Gapped Kubernetes Security Engineer

Pueo Business Solutions LLC • McLean (VA)

On-site
USD 120,000 - 180,000
Senior Kubernetes Software Engineer
Senior Kubernetes Software Engineer

engineeringjobs.net, Inc. • San Antonio (TX)

On-site
USD 140,000 - 190,000
Medical
Dental
Vision
+9
Senior Security Engineer - Cloud Security
Senior Security Engineer - Cloud Security

PagerDuty • Atlanta (GA)

On-site
USD 170,000 - 210,000
Senior Kubernetes Software Engineer
Senior Kubernetes Software Engineer

IPSecure • Chicago (IL)

On-site
USD 140,000 - 190,000
Medical, Dental, Vision
401(k) with match
Paid federal holidays
+2
Information Systems Security Manager
Information Systems Security Manager

Pueo Business Solutions LLC • McLean (VA)

On-site
USD 120,000 - 170,000
Principal Platform Engineer
Principal Platform Engineer

Clarity Innovations, LLC • Herndon (VA)

Hybrid
USD 113,000 - 300,000
Senior Kubernetes Software Engineer
Senior Kubernetes Software Engineer

IPSecure, Inc. • San Antonio (TX)

On-site
USD 120,000 - 150,000
Medical
Dental
Vision
+7
Cyber Technical Engineer
Cyber Technical Engineer

Technomics, Inc. • Arlington (VA)

On-site
USD 80,000 - 100,000
Senior Kubernetes Software Engineer
Senior Kubernetes Software Engineer

IP Secure, LLC • San Antonio (TX)

On-site
USD 140,000 - 190,000
Medical Insurance
Unlimited PTO
Education Reimbursement
+4