Cybersecurity Engineer

CMT Services, Inc.

Washington (District of Columbia)

Hybrid

USD 110,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

CMT Services, Inc. seeks a Cybersecurity Engineer for the US Congressional Budget Office project in Washington, DC. This role designs and maintains enterprise security controls, enforcing Zero Trust across cloud, on-premises, and hybrid environments.

Responsibilities include implementing NIST-aligned controls, managing IAM and MFA, SIEM integration, and continuous monitoring to strengthen posture and incident response capabilities.

Qualifications

  • Hands-on experience engineering enterprise security controls across cloud, network, and endpoint per NIST SP 800-53 and NIST SP 800-207 Zero Trust.
  • Experience with IAM, RBAC, PAM, and MFA, and integration with enterprise identity providers.
  • Experience with SIEM and EDR/XDR — centralized logging, continuous monitoring, threat detection, triage, containment, and forensic collection.
  • Experience with vulnerability management, NIST RMF risk analysis, secure-baseline hardening, and patch/mitigation coordination.
  • Experience securing AWS and Azure cloud/hybrid environments and supporting audit readiness, SOPs, RCA, and 24/7 operations.

Responsibilities

  • Support implementation, operation, and optimization of enterprise security platforms across cloud, on-premises, and hybrid environments.
  • Implement/maintain controls aligned with NIST SP 800-53 and NIST SP 800-207 Zero Trust.
  • Design/maintain least-privilege access — RBAC, PAM, and MFA across enterprise systems.
  • Configure/manage IAM solutions; integrate with enterprise identity providers for secure authentication/authorization.
  • Configure/maintain centralized logging, monitoring, and audit; integrate with enterprise SIEM; comply with retention policies.
  • Conduct continuous monitoring, vulnerability assessment, and risk analysis aligned with NIST RMF; harden systems/apps/cloud to secure baselines.
  • Secure cloud/hybrid environments (AWS, Azure) — security services, identity controls, network protections, workload security.
  • Identify/remediate vulnerabilities; coordinate patching/mitigation; support IR (alert monitoring, analysis, containment, forensic collection).
  • Maintain segmentation/access strategies to limit lateral movement; follow formal change management with security impact analysis.
  • Develop/maintain cybersecurity SOPs, system configurations, baselines, and asset inventories; perform RCA; support 24/7 monitoring (SIEM, EDR/XDR, cloud-native tools).
  • Collaborate with network, cloud, and application teams; serve as technical resource for advanced service desk and security issues.

Skills

NIST SP 800-53
NIST SP 800-207 Zero Trust
IAM / RBAC / PAM / MFA
SIEM / EDR/XDR
Vulnerability management

Education

Bachelor’s degree in IT / Cybersecurity

Tools

AWS
Azure

Job description

ABOUT US

CMT Services Inc. is a dynamic and small business supporting Federal, State, and Local government agencies. As an SBA-certified HUBZone, Woman Owned Small Business (WOSB), we deliver quality, professional services to support the missions and strategic business goals of our clients.

Position Title

Cybersecurity Engineer

Location

US Congressional Budget Office
Ford House Office Building, 4th floor
2nd St SW, 441 D St SW
Washington, DC 20024

Period of Performance

08/15/2026 - 08/14/2031

Place of Performance

Remote work is authorized under this contract; however, at CBO’s discretion, contractor employees may be required to work on-site at CBO facilities without reimbursement for related travel or expenses.

Security Clearance

Public Trust (Tier 2)

Citizenship

U.S. Citizenship or Permanent Residence status

Position Summary

The Cybersecurity Engineer designs, implements, and maintains enterprise security controls that enforce Zero Trust — identity-centric access, least-privilege enforcement, continuous monitoring, and threat detection across cloud, network, and endpoint environments — ensuring security technologies and services are configured, hardened, and continuously monitored to strengthen CBO’s posture and detection/response capabilities.

Key Responsibilities
  • Support implementation, operation, and optimization of enterprise security platforms across cloud, on-premises, and hybrid environments.
  • Implement/maintain controls aligned with NIST SP 800-53 (AC, CM, SC, AU, IR, SI families) and NIST SP 800-207 Zero Trust.
  • Design/maintain least-privilege access — RBAC, privileged access management (PAM), and MFA across enterprise systems.
  • Configure/manage IAM solutions; integrate with enterprise identity providers for secure authentication/authorization.
  • Configure/maintain centralized logging, monitoring, and audit; integrate with enterprise SIEM; comply with retention policies.
  • Conduct continuous monitoring, vulnerability assessment, and risk analysis aligned with NIST RMF; harden systems/apps/cloud to secure baselines.
  • Secure cloud/hybrid environments (AWS, Azure) — security services, identity controls, network protections, workload security.
  • Identify/remediate vulnerabilities; coordinate patching/mitigation; support IR (alert monitoring, analysis, containment, forensic collection).
  • Maintain segmentation/access strategies to limit lateral movement; follow formal change management with security impact analysis.
  • Develop/maintain cybersecurity SOPs, system configurations, baselines, and asset inventories; perform RCA; support 24/7 monitoring (SIEM, EDR/XDR, cloud-native tools).
  • Collaborate with network, cloud, and application teams; serve as technical resource for advanced service desk and security issues.
Required Qualifications
  • Hands‑on experience engineering enterprise security controls across cloud, network, and endpoint per NIST SP 800-53 and NIST SP 800-207 Zero Trust.
  • Experience with IAM, RBAC, PAM, and MFA, and integration with enterprise identity providers.
  • Experience with SIEM and EDR/XDR — centralized logging, continuous monitoring, threat detection, triage, containment, and forensic collection.
  • Experience with vulnerability management, NIST RMF risk analysis, secure-baseline hardening, and patch/mitigation coordination.
  • Experience securing AWS and Azure cloud/hybrid environments and supporting audit readiness, SOPs, RCA, and 24/7 operations.
Education
  • Bachelor’s degree in IT, Cybersecurity, or related field
Required Documents
  • Letter of Commitment
Join Our Team

At CMT Services, we believe that extraordinary results come from empowering exceptional people. If you're ready to lead innovative projects, solve complex challenges, and contribute to meaningful infrastructure development while advancing your career in a supportive, collaborative environment, we want to hear from you.

Disclaimer

By submitting your resume for this job posting, you authorize CMT Services, Inc. to forward your resume to all applicable internal and external managers, agencies, and recruitment personnel for review and consideration to hire.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Web Developer Security Engineer
Web Developer Security Engineer

CMT Services, Inc. • Washington

Hybrid
USD 120,000 - 160,000
Cybersecurity Engineer (SMA 5)
Cybersecurity Engineer (SMA 5)

E-Logic, Inc. • Washington

On-site
USD 140,000 - 190,000
Cybersecurity Engineer (SMA 5)
Cybersecurity Engineer (SMA 5)

E Logic • Washington

On-site
USD 150,000 - 190,000
Senior Microsoft Cloud Engineer
Senior Microsoft Cloud Engineer

CMT Services, Inc. • Washington

Hybrid
USD 140,000 - 190,000
Cybersecurity Engineer
Cybersecurity Engineer

All Native Group • Washington

Hybrid
USD 140,000 - 190,000
Cybersecurity Engineer - Washington DC
Cybersecurity Engineer - Washington DC

VetJobs • Washington

Hybrid
USD 120,000 - 180,000
Remote Zero-Trust Cybersecurity Engineer
Remote Zero-Trust Cybersecurity Engineer

CMT Services, Inc. • Washington

Hybrid
USD 110,000 - 150,000
Senior Microsoft Cloud Engineer (SMA 2)
Senior Microsoft Cloud Engineer (SMA 2)

E Logic • Washington

On-site
USD 140,000 - 200,000
null
Cybersecurity Engineer
Cybersecurity Engineer

All Native Group, The Federal Services Division of Ho-Chunk Inc. • Washington

Hybrid
USD 120,000 - 160,000
Lead Cyber Security Analysis SME
Lead Cyber Security Analysis SME

Xtreme Solutions Inc • Washington

On-site
USD 140,000 - 210,000