Cybersecurity Engineer (DoD Enterprise Security)

SHR CONSULTING GROUP, LLC

Arlington (VA)

On-site

USD 135,000 - 155,000

Full time

1 hour ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Medical, dental, vision coverage
401(k) with company match
Paid time off and holidays
Certification reimbursement & training

Job summary

SHR Consulting Group, LLC is seeking a Cybersecurity Engineer to support assessment, hardening, remediation, and reporting of cybersecurity posture across DoD enterprise systems in the National Capital Region, with on-site work in Arlington, VA. The role requires hands-on RMF activity, DISA STIG compliance, and experience with eMASS, ACAS, and other ESS tools.

You will develop RMF artifacts, support readiness inspections, and communicate findings to engineers, owners, and leadership.

Qualifications

  • Bachelor's degree in cybersecurity, information technology, computer science, engineering, or a related discipline.
  • 5+ years of progressively responsible cybersecurity engineering, security assessment, vulnerability management, or RMF experience in a DoD or federal enterprise environment.
  • Hands-on experience using eMASS to support RMF packages, security controls, assessment evidence, POA&Ms, and authorization activities.
  • Experience conducting technical assessments using DISA STIGs, ACAS, Axonius, Evaluate-STIG, Trellix, and/or comparable enterprise cybersecurity tools.
  • Experience supporting CCORI/CCRI/CORA-type inspections, cyber readiness assessments, or similar enterprise compliance initiatives.

Responsibilities

  • Perform technical cybersecurity assessments of servers, endpoints, applications, network devices, and other enterprise information systems using DISA STIGs, ACAS, Axonius, Evaluate-STIG, Trellix, and other ESS tools.
  • Analyze scan results, configuration findings, asset data, and evidence to identify vulnerabilities, misconfigurations, and remediation priorities.
  • Develop, maintain RMF artifacts in eMASS, including control statements, assessment evidence, POA&Ms, risk records, and remediation status.
  • Support readiness inspections and COOP activities with evidence collection, technical validation, and remediation tracking.
  • Coordinate with multiple teams to validate findings and resolve vulnerabilities within deadlines.

Skills

RMF knowledge
DISA STIG
eMASS
ACAS
Vulnerability assessment
Technical reporting
Communication to leadership

Education

Bachelor's degree in cybersecurity, IT, CS, or engineering

Tools

Axonius
Evaluate-STIG
Trellix
STIG Viewer
Nessus / Tenable

Job description

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

Cybersecurity Engineer (DoD Enterprise Security)

Arlington, VA, US

3 days ago Requisition ID: 1512

Salary Range: $135,000.00 To $155,000.00 Annually

SHR Consulting Group, LLC is a small business delivering enterprise IT, cybersecurity, and program management services to the Department of Defense and federal civilian agencies. We support mission-critical infrastructure at the Pentagon and across the National Capital Region, and we invest in our people through competitive compensation, professional certification support, and long-term career growth on stable, multi-year programs.

Position Summary

We are seeking a Cybersecurity Engineerto support the assessment, hardening, remediation, and reporting of cybersecurity posture across DoD enterprise systems. The role requires hands-on experience with RMF-related security artifacts, DISA STIG compliance, enterprise security tools, and clear communication with both technical personnel and program leadership. DISA identifies eMASS and ACAS among its supported cybersecurity services, while STIGs provide DoD configuration-hardening guidance.

Key Responsibilities
  • Perform technical cybersecurity assessments of servers, endpoints, applications, network devices, and other enterprise information systems using DISA STIGs, ACAS, Axonius, Evaluate-STIG, Trellix, and other approved Enterprise Security Services (ESS) tools.
  • Analyze scan results, configuration findings, asset inventory data, and security-control evidence to identify vulnerabilities, misconfigurations, compliance gaps, and remediation priorities.
  • Develop, maintain, and update RMF and authorization artifacts in eMASS, including control implementation statements, assessment evidence, POA&Ms, risk records, and remediation status.
  • Support Cyber Command Readiness Inspection/Operational Readiness Inspection activities, including CCORI-related preparation, evidence collection, technical validation, corrective-action tracking, and post-assessment remediation.
  • Support Cyber Hardening Mission activities by validating secure configurations, coordinating technical remediation, documenting exceptions, and tracking risk acceptance or mitigation actions.
  • Correlate ACAS vulnerability data, STIG assessment results, Axonius asset-discovery data, Trellix security telemetry, and other ESS outputs to provide a complete view of enterprise cyber risk.
  • Create data-driven reports, dashboards, trackers, and remediation metrics using advanced Microsoft Office tools, especially Excel formulas, pivot tables, lookups, data analysis functions, charts, and PowerPoint briefing materials.
  • Brief technical teams, system owners, ISSMs/ISSOs, program managers, and senior leadership on assessment results, cyber risk, trends, remediation progress, and decisions needed.
  • Coordinate with infrastructure, network, cloud, application, endpoint, and security operations teams to validate findings and resolve vulnerabilities within required timelines.
  • Maintain assessment artifacts and documentation in accordance with contract, organizational, DoD, and RMF requirements.
Required Qualifications
  • Bachelor’s degree in cybersecurity, information technology, computer science, engineering, or a related discipline; additional relevant experience may be substituted for education as permitted by the contract.
  • 5+ years of progressively responsible cybersecurity engineering, security assessment, vulnerability management, or RMF experience in a DoD or federal enterprise environment.
  • Demonstrated hands-on experience using eMASS to support RMF packages, security controls, assessment evidence, POA&Ms, and authorization activities.
  • Demonstrated experience conducting technical assessments using DISA STIGs, ACAS, Axonius, Evaluate-STIG, Trellix, and/or comparable enterprise cybersecurity tools.
  • Experience supporting CCORI/CCRI/CORA-type inspections, cyber readiness assessments, Cyber Hardening Mission efforts, or similar enterprise compliance and operational-risk initiatives. CCORI programs emphasize mission, threat, and vulnerability analysis in evaluating operational cyber risk.
  • Strong knowledge of vulnerability management, secure configuration validation, asset management, remediation verification, risk analysis, and cybersecurity reporting.
  • Advanced Microsoft Office proficiency, including Excel formulas, pivot tables, XLOOKUP/VLOOKUP, conditional logic, data normalization, trend analysis, and creation of executive-ready PowerPoint briefings.
  • Ability to communicate complex technical issues, risk impacts, and remediation recommendations clearly to engineers, system owners, program managers, and senior leaders.
  • Ability to work independently, manage competing priorities, maintain detailed records, and operate effectively in a mission-focused environment.
Preferred Qualifications
  • Experience with NIST RMF, NIST SP 800-53 controls, control assessments, security test procedures, POA&M management, and authorization-to-operate support.
  • Experience supporting DISA, Army, Navy, Air Force, Fourth Estate, or other DoD enterprise environments.
  • Familiarity with SCAP Compliance Checker, STIG Viewer, Tenable SecurityCenter/Nessus, Splunk, ServiceNow, Power BI, and vulnerability remediation workflow automation.
  • Experience developing cyber metrics for leadership, such as CAT I–III vulnerability trends, STIG compliance percentages, overdue remediation rates, asset accountability, and POA&M aging.
Education
  • Bachelor’s degree in cybersecurity, information technology, computer science, engineering, or a related discipline; additional relevant experience may be substituted for education as permitted by the contract.
Certifications
  • DoD 8570.01-M / DoD 8140 certification required.
Security Clearance
  • Active Secret clearancerequired at minimum; must be eligible to obtain and maintain TS/SCI.

On-site at the Pentagon Reservation and Government facilities within the National Capital Region, which for this program includes the Mark Center, Crystal Gateway, the Taylor Building, Raven Rock Mountain Complex, Fort Detrick, Fort Belvoir, Fort McNair, Fort Myer, and Naval Support Group Mechanicsburg, PA. Limited unclassified telework may be authorized in writing by the COR on a case-by-case basis in support of COOP scenarios. Occasional CONUS travel may be required.

  • Competitive salary commensurate with experience and clearance level
  • Comprehensive medical, dental, and vision coverage
  • 401(k) with company contribution
  • Paid time off and eleven federal holidays
  • Certification reimbursement and training support (DoD 8140 baseline and computing environment certifications)
  • Life and disability insurance

SHR Consulting Group, LLC is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.

The above salary range represents a general guideline; SHR considers a number of factors when determining the base salary offers such as the scope and responsibilities of the position, and the candidate's experience, education, skills and current market conditions.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Analyst
Cybersecurity Analyst

SHR Consulting Group • Arlington (VA)

On-site
USD 120,000 - 160,000
Medical Insurance
Dental Insurance
Vision Insurance
+7
Cybersecurity Engineer — DoD Enterprise Security
Cybersecurity Engineer — DoD Enterprise Security

S2i2, Inc • Washington

On-site
USD 110,000 - 120,000
Cybersecurity Engineer
Cybersecurity Engineer

S2i2, Inc • Washington

On-site
USD 110,000 - 120,000
Sr. Cyber Security Analyst
Sr. Cyber Security Analyst

P3S CORPORATION • Dayton (OH)

On-site
USD 95,000 - 120,000
DoD Cybersecurity Engineer — RMF & STIG Expert, Pentagon
DoD Cybersecurity Engineer — RMF & STIG Expert, Pentagon

SHR CONSULTING GROUP, LLC • Arlington (VA)

On-site
USD 135,000 - 155,000
Medical, dental, vision coverage
401(k) with company match
Paid time off and holidays
+1
Information Security Analyst
Information Security Analyst

CALIBRE Systems Inc • Washington

Hybrid
USD 80,000 - 90,000
Senior Cybersecurity Internal Controls Administrator
Senior Cybersecurity Internal Controls Administrator

Sev1Tech LLC • Fort Bragg (NC)

On-site
USD 90,000 - 125,000
Cybersecurity Systems Analyst, Sr.
Cybersecurity Systems Analyst, Sr.

TJ Consulting Group • Town of Texas (WI)

On-site
USD 120,000 - 122,000
PTO
Holiday Pay
401K with 4% match
+12
Cybersecurity Systems Analyst, Intermediate
Cybersecurity Systems Analyst, Intermediate

TJ Consulting Group • Tampa (FL)

On-site
USD 90,000 - 130,000
PTO
Holiday Pay
401K Match
+11
RMF Cybersecurity Analyst
RMF Cybersecurity Analyst

ASRC Federal • Quantico (VA)

Hybrid
USD 70,000 - 100,000
Health care
Dental
Vision
+4