Cybersecurity & Governance Engineer

CALIBRE Systems, Inc.

Washington (District of Columbia)

Hybrid

USD 125,000 - 145,000

Full time

40 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

CALIBRE Systems, Inc. is seeking a Cybersecurity and Governance Engineer to drive RMF/ATO activities and implement Federal security requirements across cloud and enterprise environments.

The role involves collaboration with Government system owners, ISSOs, and delivery teams to ensure artifacts and authorization packages meet federal standards. The candidate will lead security governance, continuous monitoring, vulnerability management, and audit readiness, ensuring secure design, logging, and

Qualifications

  • Familiarity with RMF/ATO processes and NIST control sets.
  • Experience producing authorization artifacts (SSP, SAR inputs, POA&M).
  • Knowledge of cloud security controls and audit readiness.

Responsibilities

  • Lead RMF lifecycle activities across federal information systems.
  • Develop and maintain authorization artifacts (SSP, POA&M).
  • Map controls to architectures and governance processes.
  • Support continuous monitoring and audit readiness.
  • Coordinate with government stakeholders and delivery teams.

Skills

RMF/ATO
NIST SP 800-53
Cloud security
Audit readiness
Vulnerability management
Incident response
Security governance
Communication with Government

Education

Master’s Degree in Information Technology

Tools

SAST/DAST tools

Job description

Category Information Technology

Job Location Washington, District of Columbia, United States

Tracking Code 5465

Position Type Full-Time/Regular

CALIBRE Systems, Inc., an employee-owned mission focused solutions and digital transformation company, is looking for a highly qualified Cybersecurity and Governance Engineer to support development of AI-enabled applications and reusable data products within customer’s existing environment. This position will be on-site, hybrid, or remote, at the discretion of the customer.

The role combines senior cybersecurity engineering, governance, risk, and compliance support with hands‑on implementation of Federal security requirements. The individual will lead Risk Management Framework (RMF) and Authority to Operate (ATO) activities, strengthen security controls across cloud and enterprise environments, support continuous monitoring, and ensure systems, artifacts, and processes align with Federal customer expectations and approved governance frameworks.

This role requires expertise in Federal cybersecurity governance and all steps of NIST 800-53 RMF. Specifically, the candidate must have proven experience in FISMA, continuous monitoring, security assessment and authorization (ATO), control implementation and validation, vulnerability and configuration management, audit logging, cloud security, security documentation, POA&M management, and stakeholder coordination with Government cybersecurity personnel.

The selected candidate will work closely with Government system owners, ISSOs, ISSMs, authorizing officials, program offices, and delivery teams to ensure cybersecurity solutions, governance artifacts, and authorization packages meet Federal requirements, mission needs, security/privacy expectations, audit readiness standards, and production sustainment objectives.

Responsibilities Include, But Are Not Limited To
  • Federal Cybersecurity Governance and RMF Support
  • Lead RMF lifecycle activities for Federal information systems, including categorization, control selection, implementation, assessment, authorization, and monitoring.
  • Develop, review, and maintain authorization artifacts, including SSPs, SAR inputs, POA&Ms, control implementation statements, and supporting evidence.
  • Map and validate NIST SP 800-53 controls against system architectures, security requirements, and Federal customer governance processes.
  • Support FISMA reporting, audit readiness, control assessments, and preparation for security reviews with Government stakeholders.
  • Advise program and technical teams on cybersecurity governance, compliance risk, and practical implementation of Federal security requirements.
  • Security Engineering and Cloud Control Implementation
  • Engineer and implement technical, operational, and management security controls across cloud, application, data, and enterprise environments.
  • Support identity and access management, audit logging, vulnerability management, configuration baselines, encryption, and secure system design.
  • Collaborate with cloud, DevSecOps, infrastructure, and application teams to embed security throughout the system lifecycle and deployment process.
  • Evaluate security architectures, data flows, dependencies, and inherited controls to identify risks, gaps, and compensating-control options.
  • Continuous Monitoring, Risk Management, and Delivery
  • Implement and support continuous monitoring processes, security metrics, control-health reporting, and evidence collection.
  • Track vulnerabilities, weaknesses, assessment findings, remediation activities, and POA&M status through closure.
  • Support incident response readiness, security operations coordination, and review of audit logs and access control activity.
  • Develop templates, standard operating procedures, user/admin guidance, knowledge-transfer materials, and transition artifacts.
  • Support security authorization and ATO inputs, including SSP updates, assessment evidence, risk acceptance materials, and POA&M items.
Required Skills
  • Creating cybersecurity documentation and authorization artifacts, including SSPs, SAR inputs, POA&Ms, control statements, assessment evidence, contingency plans, and RMF/ATO materials.
  • Managing and complying with Federal cybersecurity requirements, including RMF, NIST SP 800-53/800-37, FISMA, ATO, control assessment, and audit readiness.
  • Security control implementation, validation, and monitoring across all environments.
  • Cloud security controls, including IAM, encryption, logging, vulnerability management, configuration baselines, and inherited controls.
  • Full RMF lifecycle support, including categorization, implementation, and assessment
  • Vulnerability management, remediation tracking, POA&M management, security metrics, evidence collection, and finding closure.
  • Audit logging, access controls, security operations coordination, incident response readiness, and security activity review.
  • Clear communication of cybersecurity risks, requirements, findings, and remediation plans to Government and technical stakeholders.
Desired Skills: (optional)
  • Master’s Degree in Information Technology or related field
  • DevSecOps practices, CI/CD security integration, infrastructure-as-code validation, container security, and SAST/DAST tools.
  • Relevant certification such as CISSP, CISM, CISA, CRISC, CAP/CGRC, Security+, CCSP, AWS Security Specialty, or Azure Security Engineer.
  • SOPs, security templates, control evidence guidance, user/admin documentation, knowledge-transfer materials, and transition artifacts.

Salary range will be from $125k-$145k

  • Analytical, facilitation, and briefing skills to translate cybersecurity requirements into practical implementation guidance.

CALIBRE and its subsidiaries are an Equal Opportunity Employer and supports transitioning service members, veterans and individuals with disabilities. We offer a competitive salary and full benefits package.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Analyst
Information Security Analyst

CALIBRE Systems, Inc. • Washington

Hybrid
USD 89,000 - 110,000
Junior Cybersecurity GRC Analyst
Junior Cybersecurity GRC Analyst

Talanto • Northern (KY)

Hybrid
USD 5,500 - 12,000
Medical: Health plan options with HSA
Dental: PPO coverage
Vision: Annual exam allowance
+5
Cyber Security Engineer
Cyber Security Engineer

The Mission Essential Group, LLC • Fairfax (VA)

On-site
USD 135,000 - 155,000
Cybersecurity Engineer
Cybersecurity Engineer

LMI Government Consulting • Tysons (VA)

On-site
USD 102,000 - 170,000
Information Security Analyst
Information Security Analyst

Caliber Systems Inc. • Washington, Northern (KY)

Hybrid
USD 89,000 - 110,000
Senior Security Engineer
Senior Security Engineer

Peyton Resource Group • Bethesda (MD)

On-site
USD 150,000 - 210,000
Cybersecurity Engineer
Cybersecurity Engineer

LMI • Tysons (VA)

On-site
USD 140,000 - 170,000
Cybersecurity Engineer
Cybersecurity Engineer

GovCIO • Fort Meade (MD)

On-site
USD 193,000 - 213,000
Employee Assistance Program (EAP)
Corporate Discounts
Learning & Development opportunities
+4
Cybersecurity Analyst, RMF & ATO
Cybersecurity Analyst, RMF & ATO

JBS International • Los Angeles (CA)

Hybrid
USD 90,000 - 150,000
Cybersecurity Analyst, RMF & ATO
Cybersecurity Analyst, RMF & ATO

JBS International • Virginia Beach (VA)

Hybrid
USD 90,000 - 140,000