Cybersecurity Engineer

S2i2, Inc

Washington (District of Columbia)

On-site

USD 110,000 - 120,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

S2i2, Inc. is seeking a Cybersecurity Engineer for on-site duties at the Pentagon area in Arlington, VA. The role requires hands-on RMF activities, DoD security posture assessment, and clear communication with program leadership.

You will work with RMF artifacts, STIG compliance, and enterprise security tools to protect DoD enterprise systems. Responsibilities include managing RMF packages in eMASS, coordinating with cross-functional teams, and delivering data-driven security reports.

Job description

Job Title

Cybersecurity Engineer

Clearance

Secret or Top-Secret (TS)

Location

Pentagon - Arlington/Crystal City, VA

Work Schedule

On-site, 5 days/week

Salary Range

$110k-$120K

Application Deadline

September 30, 2026

Description

The Cybersecurity Engineer supports the assessment, hardening, remediation, and reporting of cybersecurity posture across DoD enterprise systems. The role requires hands-on experience with RMF-related security artifacts, DISA STIG compliance, enterprise security tools, and clear communication with both technical personnel and program leadership. DISA identifies eMASS and ACAS among its supported cybersecurity services, while STIGs provide DoD configuration-hardening guidance.

Core Responsibilities
  • Perform technical cybersecurity assessments of servers, endpoints, applications, network devices, and other enterprise information systems using DISA STIGs, ACAS, Axonius, Evaluate-STIG, Trellix, and other approved Enterprise Security Services (ESS) tools.
  • Analyze scan results, configuration findings, asset inventory data, and security-control evidence to identify vulnerabilities, misconfigurations, compliance gaps, and remediation priorities.
  • Develop, maintain, and update RMF and authorization artifacts in eMASS, including control implementation statements, assessment evidence, POA&Ms, risk records, and remediation status.
  • Support Cyber Command Readiness Inspection/Operational Readiness Inspection activities, including CCORI-related preparation, evidence collection, technical validation, corrective-action tracking, and post-assessment remediation.
  • Support Cyber Hardening Mission activities by validating secure configurations, coordinating technical remediation, documenting exceptions, and tracking risk acceptance or mitigation actions.
  • Correlate ACAS vulnerability data, STIG assessment results, Axonius asset-discovery data, Trellix security telemetry, and other ESS outputs to provide a complete view of enterprise cyber risk.
  • Create data-driven reports, dashboards, trackers, and remediation metrics using advanced Microsoft Office tools, especially Excel formulas, pivot tables, lookups, data analysis functions, charts, and PowerPoint briefing materials.
  • Brief technical teams, system owners, ISSMs/ISSOs, program managers, and senior leadership on assessment results, cyber risk, trends, remediation progress, and decisions needed.
  • Coordinate with infrastructure, network, cloud, application, endpoint, and security operations teams to validate findings and resolve vulnerabilities within required timelines.
  • Maintain assessment artifacts and documentation in accordance with contract, organizational, DoD, and RMF requirements.
Required Qualifications
  • Bachelor's degree in cybersecurity, information technology, computer science, engineering, or a related discipline
  • 5+ years of cybersecurity engineering, security assessment, vulnerability management, or RMF experience in a DoD or federal enterprise environment.
  • Hands-on experience using eMASS to support RMF packages, security controls, assessment evidence, POA&Ms, and authorization activities.
  • Experience conducting technical assessments using DISA STIGs, ACAS, Axonius, Evaluate-STIG, Trellix, and/or comparable enterprise cybersecurity tools.
  • Experience supporting CCORI/CCRI/CORA-type inspections, cyber readiness assessments, Cyber Hardening Mission efforts, or similar enterprise compliance and operational-risk initiatives. CCORI programs emphasize mission, threat, and vulnerability analysis in evaluating operational cyber risk.
  • Strong knowledge of vulnerability management, secure configuration validation, asset management, remediation verification, risk analysis, and cybersecurity reporting.
  • Advanced Microsoft Office proficiency, including Excel and creation of executive-ready PowerPoint briefings.
  • Communicate complex technical issues, risk impacts, and remediation recommendations clearly to engineers, system owners, program managers, and senior leaders.
  • Ability to work independently, manage competing priorities, maintain detailed records, and operate effectively in a mission-focused environment.
  • Active DoD Secret clearance, or ability to obtain and maintain one, as required by the contract.
Preferred Qualifications
  • Current DoD 8140-aligned cybersecurity qualification or certification appropriate to the assigned work role and proficiency level. DoD workforce guidance requires assigned personnel to meet qualification and continuing professional-development requirements associated with their designated work roles.
  • Experience with NIST RMF, NIST SP 800-53 controls, control assessments, security test procedures, POA&Ms management, and authorization-to-operate support.
  • Experience supporting DISA, Army, Navy, Air Force, Fourth Estate, or other DoD enterprise environments.
  • Familiarity with SCAP Compliance Checker, STIG Viewer, Tenable SecurityCenter/Nessus, Splunk, ServiceNow, Power BI, and vulnerability remediation workflow automation.
  • Experience developing cyber metrics for leadership, such as CAT I–III vulnerability trends, STIG compliance percentages, overdue remediation rates, asset accountability, and POA&Ms aging.
  • Experience supporting cloud, hybrid-cloud, on-premises data-center, or large-scale enterprise environments.
About S2i2

S2i2 is a growing company with a supportive and inclusive culture and many opportunities for professional development and growth. We have created a supportive, family-like work environment where contributions are recognized. Regular company updates and open lines of communication with leadership fosters collaboration within the company.

We are proud to include:

Support to achieve professional certifications and degrees

Leadership that is accessible to all employees

Regular company updates

Client networking social engagements

Monthly team-building activities (past examples: Top Golf)

Supporting our community - including veterans

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer — DoD Enterprise Security
Cybersecurity Engineer — DoD Enterprise Security

S2i2, Inc • Washington

On-site
USD 110,000 - 120,000
Lead Cyber Defense Incident Responder TS/SCI
Lead Cyber Defense Incident Responder TS/SCI

S2i2, Inc • Arlington (VA)

On-site
USD 165,000 - 180,000
Professional certification support
Leadership accessibility
Regular company updates
+1
Cybersecurity Systems Analyst, Sr.
Cybersecurity Systems Analyst, Sr.

TJ Consulting Group • Coronado (CA)

On-site
USD 120,000 - 170,000
PTO
Holiday Pay
401K with a 4% Match
+13
Lead Cyber Defense Incident Responder TS/SCI
Lead Cyber Defense Incident Responder TS/SCI

S2i2, Inc • Arlington (VA)

On-site
USD 165,000 - 180,000
Cyber Security Engineer
Cyber Security Engineer

Triglocon • Arlington (VA)

On-site
USD 110,000 - 150,000
Medical, Dental & Vision Coverage
Paid Time Off
Paid Holidays
+3
Cyber Security Engineer
Cyber Security Engineer

Trinity Global Consulting • McKnight and Bay (MA)

On-site
USD 90,000 - 130,000
Medical, Dental & Vision Coverage
Paid Time Off
Paid Holidays
+3
Information System Security Engineer (ISSE)
Information System Security Engineer (ISSE)

SOSi • Hawaii

On-site
USD 125,000 - 168,000
CyberSecurity Engineer
CyberSecurity Engineer

Spatial Front, Inc • Arlington (VA)

Hybrid
USD 100,000 - 150,000
Comprehensive benefits
On-site/Hybrid work
EOE
Information System Security Specialist II
Information System Security Specialist II

DirectViz Solutions, LLC • Virginia Beach (VA)

On-site
USD 80,000 - 100,000
Competitive compensation
Comprehensive medical benefits
401(k) match
+2
Security Control Assessor
Security Control Assessor

Novul Solutions • Arlington (TX)

On-site
USD 120,000 - 180,000
Paid Time Off (PTO)
Holidays
401(k) match
+2