Cybersecurity Engineer

Socket.dev

Fort Belvoir (VA)

On-site

USD 120,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Electrosoft Services, LLC is seeking a Cybersecurity Engineer to serve as the technical lead for enterprise web application and infrastructure vulnerability management. You will plan, execute, and support vulnerability assessments, validate findings, prioritize remediation, and implement security controls to reduce cyber risk in DoD environments.

You will collaborate with system owners, developers, network engineers, and cybersecurity teams to ensure compliance with DoD cybersecurity

Qualifications

  • Ten (10) years of relevant IT experience.
  • OT experience: five (5) years in Operational Technology environments.
  • Requires Moderate Risk, Confidential, Non-Critical Sensitive, Tier 3/NACLC/ANACI investigation at proposal time.
  • Must have IASAE III Certification within 6 months of start date; other requirements apply.

Responsibilities

  • Conduct authenticated and unauthenticated vulnerability scans of web applications, APIs, servers, databases, operating systems, and network devices.
  • Perform web application security assessments using automated and manual testing techniques.
  • Validate vulnerabilities to eliminate false positives.
  • Analyze CVEs and CWEs and assess associated security risks.
  • Prioritize vulnerabilities using CVSS, exploitability, mission impact, and threat intelligence.
  • Develop remediation recommendations and mitigation strategies.
  • Support patch management activities and verify remediation effectiveness.
  • Perform secure configuration reviews against DISA STIGs and other baselines.
  • Produce technical reports, executive dashboards, and risk summaries.
  • Support RMF monitoring activities and Authority to Operate (ATO) processes.
  • Coordinate with ISSOs, ISSMs, developers, and infrastructure teams.
  • Assist during security audits and inspections.
  • Maintain vulnerability management metrics and KPIs.
  • Develop scripts or automation to improve vulnerability management processes.

Education

IASAE III Certification
DOD 8570/8140 IAT III Certification

Job description

Electrosoft Services, LLC is an award-winning company that provides comprehensive technology-based solutions and services to federal customers. While cybersecurity is our specialty, we also focus on ICAM, Zero Trust, digital engineering and transformation, and enterprise AI and intelligent automation. We always seek to delight our customers, so we retain highly qualified employees and offer them meaningful work, growth opportunities, and work-life balance. What sets us apart from all other contractors is the sense of teamwork our employees feel – and the knowledge that outstanding effort is recognized and rewarded. The camaraderie we share emanates from Lunch & Learn sessions where we explore new ideas together, fun group activities ranging from escape rooms to miniature golf, and much, much more.
Cybersecurity Engineer
Position Summary

The Cybersecurity Engineer serves as the technical lead for enterprise web application and infrastructure vulnerability management. The engineer is responsible for planning, executing, and supporting vulnerability assessments, validating findings, prioritizing remediation activities, and implementing security controls to reduce organizational cyber risk. This position collaborates with system owners, developers, network engineers, and cybersecurity teams to ensure compliance with DoD cybersecurity requirements.

Primary Responsibilities
  • Conduct authenticated and unauthenticated vulnerability scans of web applications, APIs, servers, databases, operating systems, and network devices.
  • Perform web application security assessments using automated and manual testing techniques.
  • Validate vulnerabilities to eliminate false positives.
  • Analyze Common Vulnerabilities and Exposures (CVEs), Common Weakness Enumerations (CWEs), and associated security risks.
  • Prioritize vulnerabilities using CVSS, exploitability, mission impact, and threat intelligence.
  • Develop remediation recommendations and mitigation strategies.
  • Support patch management activities and verify remediation effectiveness.
  • Perform secure configuration reviews against DISA STIGs and other security baselines.
  • Produce technical reports, executive dashboards, and risk summaries.
  • Support continuous monitoring (RMF Step 6).
  • Coordinate with ISSOs, ISSMs, developers, and infrastructure teams.
  • Support Authority to Operate (ATO) activities and POA&M management.
  • Assist during security audits and inspections.
  • Maintain vulnerability management metrics and KPIs.
  • Support incident response investigations involving vulnerable systems.
  • Develop scripts or automation to improve vulnerability management processes.
Basic Qualifications
  • Ten (10) years of relevant IT experience
  • Operation Technology Five (5) Years of relevant OT experience
  • Investigative Requirement: At time of proposal the contractor must possess a Moderate Risk, Confidential, Non- Critical Sensitive, Tier 3/NACLC/ANACI investigation.
  • Relevant certification meeting DOD 8570/8140 IAT level III, and IASAE level III. (Must have IASAE III Certification within 6 months of coming on the contract. Must meet all other requirements.)
  • Computing Environment (CE): Microsoft Certified Solutions Associate or Expert, Cisco Certified Network Administrator, Microsoft Azure Security Technologies, Amazon Certified Security.

Electrosoft is an Equal Opportunity Employer/Veterans/Disabled

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer
Cybersecurity Engineer

electro soft • Fort Belvoir (VA)

On-site
USD 120,000 - 180,000
R&D Cybersecurity Engineer
R&D Cybersecurity Engineer

electro soft • Fort Belvoir (VA)

On-site
USD 130,000 - 180,000
Cybersecurity Engineer SME
Cybersecurity Engineer SME

Socket.dev • United States

On-site
USD 120,000 - 180,000
R&D Cybersecurity Engineer
R&D Cybersecurity Engineer

Socket.dev • Fort Belvoir (VA)

On-site
USD 120,000 - 180,000
Cybersecurity Engineer - Vulnerability & Risk Lead
Cybersecurity Engineer - Vulnerability & Risk Lead

Socket.dev • Fort Belvoir (VA)

On-site
USD 120,000 - 160,000
Cybersecurity Engineer: Vulnerability & Risk Lead
Cybersecurity Engineer: Vulnerability & Risk Lead

electro soft • Fort Belvoir (VA)

On-site
USD 120,000 - 180,000
Information System Security Engineer (Pipeline)
Information System Security Engineer (Pipeline)

Electrosoft • Belleville (IL)

On-site
USD 80,000 - 110,000
Growth opportunities
Team-building activities
Work-life balance
Senior Cybersecurity Engineer - Vulnerability & Risk Lead
Senior Cybersecurity Engineer - Vulnerability & Risk Lead

Electrosoft • Fort Belvoir (VA)

On-site
USD 110,000 - 160,000
Information System Security Engineer (Pipeline)
Information System Security Engineer (Pipeline)

electro soft • Belleville (IL)

On-site
USD 85,000 - 115,000
DevSecOps Engineer
DevSecOps Engineer

Socket.dev • Arlington (VA)

On-site
USD 120,000 - 150,000