Cybersecurity Engineer - CBO

Innovim

Washington, Northern (District of Columbia, KY)

Hybrid

USD 90,000 - 107,000

Full time

32 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Innovim in Washington, DC is seeking a Cybersecurity Engineer to design, implement, and maintain enterprise security controls enforcing Zero Trust across cloud, network, and endpoints for a U.S. legislative branch agency.

The role requires deep knowledge of NIST SP 800-53/800-207, IAM/MFA, and vulnerability management, with hybrid on-site/remote work as needed. Citizenship or permanent residence is required to obtain a Public Trust.

Qualifications

  • Bachelor's degree in a related field or equivalent experience.
  • 8+ years hands-on cybersecurity engineering experience.
  • Experience with SIEM, EDR/XDR, IAM/MFA, and vulnerability management.
  • Knowledge of NIST SP 800-53, SP 800-207, and RMF.
  • U.S. citizenship or permanent residence with ability to obtain Public Trust.

Responsibilities

  • Implement and maintain enterprise security controls aligned with NIST SP 800-53 families.
  • Enforce Zero Trust Architecture per NIST SP 800-207 with least-privilege access.
  • Configure IAM, RBAC, PAM, and MFA across cloud, network, and endpoints.
  • Monitor security events with SIEM/EDR; assist with incident response.
  • Maintain centralized log collection, retention, and analysis.
  • Perform vulnerability scanning and coordinate patching.
  • Support cloud/security configurations for AWS/Azure; secure workloads.
  • Harden systems and apply segmentation to limit lateral movement.
  • Conduct RMF-based risk analysis and RCA for incidents.
  • Develop cybersecurity SOPs, baselines, and audit-ready docs; 24/7 ops.

Education

Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field

Tools

SIEM (Microsoft Sentinel | Splunk)
EDR/XDR (Microsoft Defender)
IAM/MFA
Vulnerability management (Tenable)

Job description

Location Washington, DC - hybrid; on-site as required by task assignment
Employment Type Full-time - contingent upon contract award
Salary Range $90,000 - $107,000
Clearance / Suitability Public Trust (Tier 2); U.S. citizenship or permanent residence required

Position Summary

The Cybersecurity Engineer designs, implements, and maintains enterprise security controls that enforce Zero Trust principles - identity-centric access, least-privilege enforcement, continuous monitoring, and threat detection - across cloud, network, and endpoint environments for a U.S. legislative branch agency. The role strengthens the organization's overall security posture and improves detection and response capabilities in alignment with NIST SP 800-53 and NIST SP 800-207.

Key Responsibilities
  • Implement and maintain enterprise security controls aligned with NIST SP 800-53 (AC, CM, SC, AU, IR, SI control families).
  • Enforce Zero Trust Architecture per NIST SP 800-207, including continuous verification, identity-centric security, and least-privilege access across cloud, network, and endpoint environments.
  • Configure and manage Identity and Access Management (IAM): authentication, authorization, role-based access control (RBAC), privileged access management (PAM), and multi-factor authentication (MFA).
  • Monitor, analyze, and respond to security events using enterprise tools (SIEM, EDR/XDR); support incident triage, containment, investigation, and remediation.
  • Maintain continuous monitoring capabilities - centralized log collection, correlation, and analysis with compliant log retention.
  • Conduct vulnerability scanning, assessment, and remediation across systems and applications; coordinate patching and mitigation.
  • Support cloud and application security (e.g., AWS, Azure): secure configuration, identity controls, and workload security.
  • Harden systems, applications, and cloud environments to secure configuration baselines; implement segmentation to limit lateral movement.
  • Perform risk analysis aligned with the NIST Risk Management Framework (RMF); conduct RCA for security incidents and control failures.
  • Develop and maintain cybersecurity SOPs, security baselines, and audit-ready documentation; support 24/7 security monitoring operations.
Required Qualifications
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field (equivalent experience considered).
  • Minimum 8 years of hands-on cybersecurity engineering experience.
  • Demonstrated experience with SIEM (e.g., Microsoft Sentinel or Splunk), EDR/XDR (e.g., Microsoft Defender), IAM/MFA, and vulnerability management (e.g., Tenable).
  • Working knowledge of NIST SP 800-53, NIST SP 800-207 Zero Trust, and the NIST Risk Management Framework.
  • S citizenship or permanent residence status; ability to obtain a Public Trust (Tier 2) determination.
Preferred Qualifications
  • CISSP, CySA+, GIAC (e.g., GCIH, GCIA), or CEH.
  • Microsoft (SC-200/AZ-500) or AWS security certifications.
  • Hands-on experience with Microsoft Sentinel, Microsoft Defender, and Tenable.sc.
  • Experience securing hybrid Active Directory / Entra ID and M365 GCC environments.
  • Prior experience supporting federal or Congressional / legislative branch environments.
Clearance, Suitability & Security

U.S. citizenship or permanent residence status is required. The selected candidate must be able to obtain and maintain a Public Trust (Tier 2) suitability determination and will undergo an FBI criminal background check and U.S. Capitol Police fingerprinting prior to starting work, in accordance with the contract's security requirements. Remote work is authorized; however, on-site presence at the customer's facilities in Washington, DC (and, as needed, data-center/computing facilities in Ashburn, VA and Manassas, VA) may be required based on task assignment. Local travel to these sites is non-reimbursable. Core hours are 9:00 AM-6:00 PM ET, Monday-Friday; occasional after-hours or weekend maintenance activity may be required.

Compensation

Salary Range: $90,000 - $107,000, commensurate with experience, education, and certifications. INNOVIM offers a comprehensive benefits package including health, dental, and vision coverage, retirement savings, paid time off, and professional development support.

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws.For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Network Engineer - CBO
Network Engineer - CBO

Innovim • Washington, Northern (KY)

Hybrid
USD 92,000 - 110,000
Cybersecurity Engineer (SMA 5)
Cybersecurity Engineer (SMA 5)

E-Logic, Inc. • Washington

On-site
USD 140,000 - 190,000
Senior Network Engineer - CBO
Senior Network Engineer - CBO

Innovim • Washington, Northern (KY)

Hybrid
USD 92,000 - 110,000
Health, dental, vision coverage
Professional development support
Retirement savings plan
Cybersecurity Engineer
Cybersecurity Engineer

CyberJobs.Com • Springfield (VA)

On-site
USD 130,000 - 140,000
Health, Dental, Vision
401(k) match
Paid time off (PTO)
+1
Senior Cyber Engineer (Senior DevSecOps Architect)
Senior Cyber Engineer (Senior DevSecOps Architect)

Defense Information Systems Agency • Washington

On-site
USD 144,000 - 187,000
Cybersecurity & Governance Engineer
Cybersecurity & Governance Engineer

CALIBRE Systems, Inc. • Washington

Hybrid
USD 125,000 - 145,000
Zero-Trust Cybersecurity Engineer - Hybrid DC
Zero-Trust Cybersecurity Engineer - Hybrid DC

Innovim • Washington, Northern (KY)

Hybrid
USD 90,000 - 107,000
Expert Cyber Security Engineer
Expert Cyber Security Engineer

Peraton • Chantilly (VA)

On-site
USD 146,000 - 234,000
Cybersecurity Implementation Engineer
Cybersecurity Implementation Engineer

CACI • Springfield (VA)

On-site
USD 94,000 - 198,000
Expert Cyber Security Engineer
Expert Cyber Security Engineer

Peraton • Springfield (VA)

On-site
USD 146,000 - 234,000