Cybersecurity Engineer

Pioneering Evolution

Arlington (VA)

On-site

USD 100,000 - 153,000

Full time

10 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Paid time off
10 paid holidays
Medical insurance
Vision insurance
Legal assistance
Life insurance
Disability insurance

Job summary

Pioneering Evolution seeks a Cybersecurity Engineer in Arlington, VA to support the security and compliance posture of SyncPoint, a DoD financial system. You will manage the ATO lifecycle, maintain SSP/POA&M, and implement NIST SP 800-171 and CMMC Level 2 controls across Linux and cloud environments.

The role involves working with DevOps, infrastructure teams, and leadership to integrate security into system design and day-to-day operations while ensuring audit-ready documentation and continuous

Qualifications

  • Bachelor’s degree or equivalent professional experience in a technical field.
  • Hands-on experience implementing NIST SP 800-171 controls and CMMC Level 2.
  • Experience documenting SSP/POA&M and maintaining compliance evidence.

Responsibilities

  • Support ATO lifecycle for SyncPoint, maintain SSP and POA&Ms.
  • Monitor and remediate controls to maintain continuous ATO posture.
  • Collaborate with developers, DevOps, and leadership to embed security.
  • Implement and validate security controls across Linux and cloud infra.
  • Configure IAM, RBAC/ABAC, and zero-trust principles across environments.
  • Lead vulnerability management, logging, and incident response.

Skills

NIST SP 800-171
CMMC Level 2
Cloud security
IAM/RBAC/ABAC
Zero Trust
Linux administration
Scripting (Bash/PowerShell/Python)
SSP/POA&M documentation
DoD RMF/ATO
Vulnerability management

Education

Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or related technical discipline

Tools

Bicep
Terraform
Azure CLI
AWS CLI
Microsoft Defender for Cloud
Microsoft Sentinel
Azure Monitor

Job description

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

Cybersecurity Engineer

Arlington, VA, US

9 days ago Requisition ID: 1033

Salary Range: $100,000.00 To $153,000.00 Annually

POSITION DESCRIPTION:

Pioneering Evolution is seeking a Cybersecurity Engineer to support the security and compliance posture of SyncPoint — a DoD financial system of record operating in a Department of Defense Impact Level 4 (IL4) environment. This role is responsible for supporting the pursuit and maintenance of an Authority to Operate (ATO), implementing and validating NIST SP 800-171 and CMMC Level 2 controls, and serving as the technical security authority for the program.

This is an oversight and hands-on implementation role. The Cybersecurity Engineer will maintain the System Security Plan (SSP) and supporting compliance documentation, conduct gap assessments, implement technical controls, and work directly with developers, DevOps engineers, infrastructure teams, and program leadership to integrate security into system design and day-to-day operations, maintaining a continuously audit-ready NIST SP 800-171 and CMMC Level 2 compliance posture. The ability to work across compliance frameworks, cloud infrastructure, and software development workflows — rather than relying solely on automated scanning tools — is essential to this position.

Key Responsibilities:

ATO Lifecycle Management

  • Support the ATO lifecycle for SyncPoint, including contributing to and maintaining the System Security Plan (SSP), security assessment documentation, and Plan of Action and Milestones (POA&M) in coordination with the Director of Technology, Platforms, and Implementation.
  • Maintain continuous ATO posture through proactive control monitoring, evidence collection, and timely remediation of findings.
  • Serve as the technical point of contact for security assessors, authorizing officials, and compliance stakeholders throughout the ATO lifecycle.
  • Coordinate security review and assessment activities across engineering, operations, and leadership teams.

NIST SP 800-171 and CMMC Level 2 Compliance

  • Interpret and apply NIST SP 800-171 security requirements, translating them into specific technical and administrative controls implemented within the SyncPoint environment.
  • Conduct security and compliance gap assessments, document deficiencies, develop remediation plans, and validate that controls have been appropriately implemented.
  • Maintain and update the SSP, control implementation statements, policies, procedures, and supporting evidence artifacts on behalf of the Director of Technology, Platforms, and Implementation.
  • Coordinate with the organization’s Managed Service Provider (MSP) to validate MSP-implemented controls, define the organizational/project boundary, and ensure control coverage is accurate and complete within the ATO boundary.
  • Monitor DoD CMMC and NIST SP 800-171 program requirements and maintain the program’s ongoing compliance and assessment readiness.

Technical Security Implementation

  • Implement and validate security controls across Linux and cloud infrastructure, including system hardening, configuration management, patching, and logging.
  • Configure and maintain identity and access management (IAM) controls including RBAC, least-privilege access, privileged access management, and service identities across Azure and application tiers.
  • Implement and validate network segmentation, firewall rules, private connectivity, VPN configurations, and network access controls appropriate for IL4 environments.
  • Deploy and manage security monitoring, logging, alerting, and audit trail capabilities; investigate and respond to security findings and incidents.
  • Support vulnerability management processes including scan configuration, finding triage, risk acceptance, and remediation tracking.

Cloud and Infrastructure Security

  • Implement and validate cloud security controls within Microsoft Azure Government (and/or AWS GovCloud), including storage encryption, identity management, network security groups, private endpoints, and security posture management.
  • Review and contribute to Infrastructure as Code (IaC) using Bicep or Terraform to ensure secure-by-default infrastructure provisioning.
  • Support DevSecOps practices including repository security, secrets management, branch protections, and secure CI/CD pipeline configuration.
  • Apply Managed Identity, RBAC/ABAC, and Zero Trust principles across cloud-hosted workloads and services.

CUI Protection

  • Implement and oversee secure handling, storage, transmission, and disposal of Controlled Unclassified Information (CUI) across all SyncPoint environments and processes.
  • Ensure development and operational workflows do not expose CUI through logs, development tools, AI services, or unauthorized environments.
  • Support data classification, labeling, and access-control requirements consistent with CUI handling requirements.

Security Engineering Collaboration

  • Work directly with software developers, infrastructure engineers, and the DevOps team to integrate security requirements into application design, infrastructure provisioning, and deployment processes.
  • Provide actionable security requirements and guidance that engineers can implement — not just compliance checklist items.
  • Use scripting and command-line tools (Bash, PowerShell, Python, Azure CLI) for administration, evidence collection, and automated compliance checks.
  • Investigate and interpret logs, system configurations, vulnerability reports, and security findings; communicate risk clearly to leadership.

Technical Environment:
Compliance: NIST SP 800-171, CMMC Level 2, RMF, ATO, CUI
Cloud: Microsoft Azure Government, AWS GovCloud
IAM: Azure AD / Entra ID, RBAC, ABAC, Managed Identity, PAM
Infrastructure: Linux, Windows Server, Network Segmentation, VPN, Firewalls
IaC: Bicep, Terraform
Monitoring/SIEM: Microsoft Defender for Cloud, Microsoft Sentinel, Azure Monitor
CI/CD Security: Azure DevOps, Git, secrets management, branch protections
Scripting: Bash, PowerShell, Python, Azure CLI, AWS CLI
Documentation: SSP, POA&M, policies, procedures, control implementation statements

  • ATO lifecycle support and RMF process expertise
  • NIST SP 800-171 and CMMC Level 2 depth — both compliance and technical implementation
  • Hands-on security engineering across cloud, Linux, and application tiers
  • CUI handling and DoD data protection requirements
  • Clear, credible communication of risk and compliance status to leadership
  • Practical problem-solving orientation — builds solutions, not just findings reports
  • Effective cross-functional collaboration with engineering, DevOps, MSP partners, and program leadership

REQUIRED EXPERIENCE:

  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or a related technical discipline, or equivalent professional experience.
  • 5+ years of professional experience in cybersecurity, information assurance, or a closely related field.
  • Demonstrated hands-on experience implementing and assessing NIST SP 800-171 controls; familiarity with CMMC Level 2 requirements and assessment processes.
  • Strong working knowledge of fundamental security principles: least privilege, Zero Trust, defense in depth, IAM, encryption, network segmentation, vulnerability management, and system hardening.
  • Proficiency with Linux system administration including command-line tools, permissions, services, logging, patching, and OS-level security hardening.
  • Strong networking fundamentals: IP addressing, subnetting, routing, firewalls, VPN/private connectivity, and network access controls.
  • Working knowledge of cloud security within Microsoft Azure and/or AWS, including IAM, network security, storage encryption, logging, monitoring, and security posture management.
  • Ability to produce and maintain SSPs, control implementation statements, POA&Ms, policies, procedures, and compliance evidence packages.
  • Scripting proficiency in at least one of: Bash, PowerShell, Python, Azure CLI.
  • Strong written and verbal communication skills; ability to explain technical security risk to leadership and translate compliance requirements into engineering tasks.
  • Demonstrated ability to independently investigate technical security problems and develop practical solutions.

Required Certifications (One or More):

The following certifications are required, reflecting the ATO oversight responsibility and the DoD operating environment:

  • CompTIA Security+ (DoD 8570/8140 IAT Level II baseline — minimum acceptable; required if no higher certification held)
  • CISSP (Certified Information Systems Security Professional) — strongly preferred for candidates leading an ATO program
  • CISM (Certified Information Security Manager) — acceptable alternative to CISSP for candidates with a compliance/governance focus
  • CAP / CGRC (Certified Authorization Professional / Governance, Risk, and Compliance) — directly applicable to ATO and RMF activities; highly valued
  • Microsoft Certified: Cloud and AI Security Engineer Associate (SC-500) — required or expected to be obtained within 6 months of hire given the Azure Government operating environment

Note: Candidates holding CISSP + CAP/CGRC or CISSP + SC-500 represent the strongest certification profile for this role. Candidates who hold a legacy AZ-500 certification (earned prior to its August 31, 2026 retirement) remain qualified, as the certification stays valid on their transcript until its individual renewal date.

DESIRED EXPERIENCE:

  • Active experience working within DoD RMF (Risk Management Framework) processes, including ATO package preparation and assessment coordination.
  • Demonstrated experience obtaining or maintaining an ATO for a DoD system.
  • Experience with DoD IL4 or IL5 environments.
  • Familiarity with DISA STIGs, SCAP tooling, and automated compliance scanning.
  • Experience with Infrastructure as Code security review (Bicep, Terraform).
  • Experience configuring and reviewing Azure Policy, Microsoft Defender for Cloud, Microsoft Sentinel, or equivalent security posture tools.
  • Familiarity with PIEE, Navy ERP, or DoD financial system environments.
  • CASP+ (CompTIA Advanced Security Practitioner) — DoD 8570 IAT Level III; valued for technical depth.
  • CCSP (Certified Cloud Security Professional) — valued for cloud-native security expertise.

WHO WE ARE AND WHAT WE OFFER:

In addition to competitive salaries and opportunities for professional development and advancement, our employees enjoy a comprehensive range of benefits. To keep pace with the changing needs of our employees, we continually evaluate our benefit plans.

  • Paid time off
  • 10 paid holidays
  • Medical insurance
  • Vision insurance
  • Legal assistance
  • Company-paid life insurance and AD&D
  • Company-paid long-term and short-term disability insurance
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer
Cybersecurity Engineer

ADP, Inc. • Arlington (VA)

On-site
USD 100,000 - 153,000
Medical insurance
Paid time off
10 paid holidays
+3
Cybersecurity Engineer
Cybersecurity Engineer

Pioneering Evolution, LLC • Arlington (VA), Northern (KY)

Hybrid
USD 100,000 - 153,000
Paid time off
10 paid holidays
Medical insurance
+4
Data Engineer
Data Engineer

ADP, Inc. • Arlington (VA)

On-site
USD 100,000 - 155,000
Data Engineer
Data Engineer

Pioneering Evolution, LLC • Arlington (VA), Northern (KY)

Hybrid
USD 100,000 - 155,000
Paid time off
10 paid holidays
Medical insurance
+4
Tech Lead (.NET)
Tech Lead (.NET)

Pioneering Evolution, LLC • Arlington (VA), Northern (KY)

Hybrid
USD 150,000 - 190,000
Paid time off
10 paid holidays
Medical insurance
+4
Tech Lead (.NET)
Tech Lead (.NET)

ADP, Inc. • Arlington (VA)

On-site
USD 150,000 - 190,000
Paid time off
10 paid holidays
Medical insurance
+4
Cybersecurity Engineer: DoD IL4 ATO & NIST 800-171
Cybersecurity Engineer: DoD IL4 ATO & NIST 800-171

Pioneering Evolution • Arlington (VA)

On-site
USD 100,000 - 153,000
Paid time off
10 paid holidays
Medical insurance
+4
Chief Engineer
Chief Engineer

Pioneering Evolution, LLC • Arlington (VA)

On-site
USD 120,000 - 160,000
Paid time off
Medical insurance
Vision insurance
+2
Cybersecurity Systems Analyst, Sr.
Cybersecurity Systems Analyst, Sr.

TJ Consulting Group • Coronado (CA)

On-site
USD 120,000 - 170,000
PTO
Holiday Pay
401K with a 4% Match
+13
Security Control Assessor
Security Control Assessor

Novul Solutions • Arlington (TX)

On-site
USD 120,000 - 180,000
Paid Time Off (PTO)
Holidays
401(k) match
+2