Job Title: Cybersecurity Engineer Lead
Job Category: Engineering
Time Type: Full time
Minimum Clearance Required to Start: TS/SCI
Employee Type: Regular
Percentage of Travel Required: Up to 10%
Type of Travel: Local
* * *
The Opportunity:
Lead cybersecurity architecture development and implementation for complex Department of Defense intelligence, electronic warfare, and cyber systems.
As a Cybersecurity Engineer Lead, you will:
- Design and develop enterprise-level cybersecurity architectures for intelligence and mission systems operating across multiple security domains
- Lead Zero Trust architecture implementation and Identity, Credential, and Access Management (ICAM) solutions for defense systems
- Architect Cross Domain Solutions (CDS) and secure data transfer capabilities between unclassified, secret, and TS/SCI environments
- Develop cybersecurity strategies, policies, and technical standards to protect mission-critical systems
- Lead Risk Management Framework (RMF) activities and Authorization to Operate (ATO) efforts for complex systems
- Provide technical leadership and mentorship to cybersecurity engineering teams
- Interface with government program offices, Information System Security Managers (ISSMs), and Authorizing Officials
Responsibilities:
- Architect and implement Zero Trust security frameworks incorporating micro-segmentation, continuous verification, and least-privilege access controls
- Design secure system architectures that comply with NIST 800-53, NIST 800-171, DoD RMF, and Intelligence Community Directive (ICD) 503 requirements
- Develop security architecture artifacts including system security plans, security architecture diagrams, data flow diagrams, and threat models
- Lead security assessments, vulnerability analyses, penetration testing coordination, and security control validation activities
- Architect and validate Cross Domain Solutions (CDS) for Multi-Level Security (MLS) and secure information sharing across classification boundaries
- Implement Security Technical Implementation Guides (STIGs), secure configuration baselines, and automated compliance scanning solutions
- Design Identity and Access Management (IAM) solutions incorporating Multi-Factor Authentication (MFA), Role-Based Access Control (RBAC), and Attribute-Based Access Control (ABAC)
- Architect secure DevSecOps pipelines integrating continuous security validation, automated vulnerability scanning, and Infrastructure as Code ( IaC ) security controls
- Develop encryption strategies, Public Key Infrastructure (PKI) implementations, and cryptographic key management solutions
- Lead security architecture reviews, threat modeling sessions, and design review boards
- Develop cybersecurity roadmaps identifying modernization opportunities, emerging threats, and technology insertion strategies
- Provide technical guidance on security architecture decisions to program managers, system engineers, and development teams
- Support incident response planning, security event analysis, and continuous monitoring architectures
- Maintain current knowledge of emerging threats, attack vectors, and defensive technologies applicable to defense intelligence systems
Qualifications:
Required:
- Active Top Secret security clearance with SCI eligibility (required)
- Master's degree in Cybersecurity, Computer Engineering, Electrical Engineering, Electronics Engineering, or Mathematics with concentration in computer science
- 10 + years of professional experience with cybersecurity engineering and architecture
- Demonstrated experience architecting enterprise cybersecurity solutions for DoD or Intelligence Community systems
- Strong understanding of Zero Trust architecture principles and implementation strategies
- Proven experience with Risk Management Framework (RMF) processes including IATT, ATC, and ATO activities
- Experience designing and implementing Cross Domain Solutions (CDS) for multi-level security environments
- Deep knowledge of security frameworks including NIST 800-53, NIST 800-171, CNSSI 1253, and ICD 503
- Experience with Identity and Credential Access Management (ICAM) architectures and implementations
- Strong understanding of defense-in-depth strategies, network security architecture, and secure system design principles
- Experience with security assessment tools such as ACAS (Nessus), eMASS , and security automation platforms
- Demonstrated ability to lead technical teams and influence cybersecurity strategy
- Excellent technical writing and communication skills with ability to brief senior leadership
- IAM , IAT, or IASAE Level I certification per DoD 8570.01-M (or DoD 8140 equivalent)
Desired:
- CISSP (Certified Information Systems Security Professional) or CISM (Certified Information Security Manager) certification
- CCSP (Certified Cloud Security Professional) or cloud security architecture certificates (AWS Security, Azure Security)
- Experience with DoD Cybersecurity Maturity Model Certification (CMMC) requirements and implementation