Senior Cyber Security Engineer

ASRC Federal

Ashburn (VA)

On-site

USD 120,000 - 190,000

Full time

7 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health insurance
401(k)
Education assistance

Job summary

ASRC Federal is seeking a Cybersecurity Engineer / ISSE for Operational Technology in Ashburn, VA. The role focuses on cybersecurity engineering, security validation, vulnerability scan readiness, and ATO evidence for UGS and OT systems in a government-focused environment.

You will collaborate across stakeholders, support lab validation, and contribute to field-alignment activities, with emphasis on lab security, documentation, and continuous monitoring responsibilities.

Qualifications

  • Bachelor’s degree in Cybersecurity, IT, CS, Engineering or related field.
  • 5–7 years of cybersecurity, security engineering, ISSE, vulnerability management, or security assessment experience.
  • Experience with RMF, ATO, POA&M, security control evidence, remediation, or continuous monitoring.
  • Experience with vulnerability scanning tools (Nessus) and SIEM/logging (Splunk).
  • Ability to document findings clearly for technical and program stakeholders.
  • Experience with DHS/CBP environments and federal cybersecurity standards preferred.

Responsibilities

  • Support cybersecurity engineering, ISSE activities for OT systems, lab validation, and documentation.
  • Assist with scan readiness, asset identification, and scope for Nessus scans.
  • Support SOC/Splunk readiness, telemetry sources, and monitoring requirements.
  • Validate firmware/software updates, vendor notes, and hash verification.
  • Document vulnerabilities, remediation actions, and retest results.
  • Contribute to lab test plans, validation packages, and Phase 2 handoffs.
  • Coordinate changes to maintain baselines and security posture.
  • Engage with stakeholders to secure integration of OT technologies.
  • Prepare security documentation, including checklists and evidence requests.
  • Assist security audits, assessments, and incident/event handling.

Skills

Analytical thinking
Troubleshooting
Communication
Cross-team coordination

Education

Bachelor's degree in Cybersecurity, IT, CS, Engineering

Tools

Tenable Nessus
Splunk

Job description

ASRC Federal is a leading government contractor furthering missions in space, public health and defense. As an Alaska Native owned corporation, our work helps secure an enduring future for our shareholders. Join our team and discover why we are a top veteran employer and Certified Great Place to Work™

Cybersecurity Engineer / ISSE – Operational Technology

Work location: Onsite (Ashburn, VA)

Clearance: Public Trust (successful completion of government background investigation)

Summary

The Cybersecurity Engineer / Information System Security Engineer (ISSE) will support cybersecurity engineering, security validation, vulnerability scan readiness, and ATO evidence activities for Unattended Ground Sensor (UGS) and operational technology systems. This role supports OIT-OpsTech lab validation efforts while also contributing to broader CBP cybersecurity, CSD coordination, and field-alignment activities.

The position will support security reviews for UGS devices and supporting infrastructure, including embedded systems, sensors, cameras, receivers, base stations, network-connected devices, and related management platforms. The Cybersecurity Engineer / ISSE will collaborate stakeholders to help ensure security considerations are incorporated into lab validation, documentation, and future field-alignment planning.

Responsibilities
  • Support cybersecurity engineering and ISSE activities for UGS and operational technology systems, with emphasis on lab validation, security readiness, and documentation.
  • Support CSD VAT/Nessus scan readiness, including asset identification, scan scope, credential availability, scan limitations, vendor constraints, and device impact considerations.
  • Support CSD SOC/Splunk readiness, including identification of available telemetry, log sources, logging limitations, monitoring requirements, and security-relevant events.
  • Support firmware/software update validation, security update review, vendor release note review, checksum/hash validation, and security impact tracking.
  • Document vulnerabilities, findings, limitations, remediation actions, compensating controls, and retest results in support of lab validation and ATO-related evidence.
  • Provide security input to lab test plans, validation packages, acceptance recommendations, and Phase 2 handoff materials.
  • Support configuration and change management by assessing whether proposed changes affect validated baselines, security posture, scanning requirements, monitoring, or field-alignment readiness.
  • Coordinate with stakeholders to support secure integration and validation of UGS technologies.
  • Support security-related documentation, including scan readiness checklists, security considerations, vulnerability tracking, and ATO evidence inputs.
  • Provide security guidance to lab team members and support security audits, assessments, and evidence requests as needed.
  • Support lab incident/security event handling by documenting security events, assessing validation impact, preserving evidence, and coordinating with appropriate stakeholders.
Qualifications
  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field; equivalent experience may be considered.
  • Minimum of 5–7 years of experience in cybersecurity, security engineering, ISSE, vulnerability management, or security assessment roles.
  • Experience supporting RMF, ATO, POA&M, security control evidence, vulnerability remediation, or continuous monitoring activities.
  • Experience with vulnerability scanning tools such as Tenable Nessus or equivalent.
  • Familiarity with SIEM/logging platforms such as Splunk and ability to identify useful telemetry/log sources.
  • Experience assessing or supporting network-connected devices, embedded systems, operational technology, IoT, cameras, sensors, or field technology environments.
  • Understanding of security hardening, firmware/software update validation, configuration baselines, change control, and risk documentation.
  • Ability to document technical findings, limitations, test results, and security recommendations clearly for technical and program stakeholders.
  • Ability to coordinate across cybersecurity, engineering, network, test, vendor, and program teams.
  • Strong analytical, troubleshooting, and communication skills.
  • Experience with DHS/CBP environments, NIST, FISMA, RMF, or federal cybersecurity requirements preferred.
Certifications
  • CompTIA Security+ or equivalent baseline cybersecurity certification required or strongly preferred.
  • CISSP, CISM, CISA, CASP+, CySA+, or equivalent preferred.
  • Tenable/Nessus, Splunk, vulnerability management, incident response, or continuous monitoring certifications are beneficial.
  • Operational technology, IoT security, or industrial/field technology security training is a plus.
Benefits

We invest in the lives of our employees, both in and out of the workplace, by providing competitive pay and benefits packages.

  • Benefits offered may include health care, dental, vision, life insurance; 401(k); education assistance; paid time off including PTO, holidays, and any other paid leave required by law.
  • The salary offered will depend on several factors including, but not limited to, relevant experience, skills, education, geographic location, internal equity, business needs, and other factors permitted by law. Posted pay ranges are a general guideline only and are not a guarantee of compensation or salary.
EEO Statement

ASRC Federal and its Subsidiaries are Equal Opportunity employers. All qualified applicants will receive consideration for employment without regard to race, gender, color, age, sexual orientation, gender identification, national origin, religion, marital status, ancestry, citizenship, disability, protected veteran status, or any other factor prohibited by applicable law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Security Engineer
Cyber Security Engineer

Marathon TS • Ashburn (VA)

On-site
USD 90,000 - 130,000
Senior Cyber Security Engineer
Senior Cyber Security Engineer

Cybersecurity Jobs • Ashburn (VA)

On-site
USD 105,000 - 115,000
Health care
Dental
Vision
+4
Senior Cyber Security Engineer
Senior Cyber Security Engineer

ASRC Federal Holding Company • Beltsville (MD)

Hybrid
USD 111,000 - 180,000
Health insurance
401(k)
Education assistance
+1
Senior Cyber Tools Architect/Engineer
Senior Cyber Tools Architect/Engineer

ASRC Federal • Quantico (VA)

On-site
USD 140,000 - 210,000
Health care
Dental
Vision
+4
OT Cybersecurity Engineer | ISSE & Lab Validation
OT Cybersecurity Engineer | ISSE & Lab Validation

ASRC Federal • Ashburn (VA)

On-site
USD 120,000 - 190,000
Health insurance
401(k)
Education assistance
Information System Security Engineer (ISSE)
Information System Security Engineer (ISSE)

Applied Research Solutions • Dayton (OH)

On-site
USD 90,000 - 130,000
Competitive benefits package
Award recognition programs
Expert Penetration Tester
Expert Penetration Tester

ASRC Federal • Washington

Hybrid
USD 140,000 - 190,000
Competitive pay and benefits
Senior Information System Security Officer (ISSO) – WSMR, New Mexico
Senior Information System Security Officer (ISSO) – WSMR, New Mexico

ASRC Federal • White Sands (NM)

On-site
USD 110,000 - 160,000
Health insurance
401(k)
Education assistance
+1
RMF Cybersecurity Analyst
RMF Cybersecurity Analyst

ASRC Federal • Virginia (IL), Northern (KY)

On-site
USD 90,000 - 120,000
Health care
Dental
Vision
+4
Senior ISSE – Air Force Systems (Hanscom AFB)
Senior ISSE – Air Force Systems (Hanscom AFB)

Applied Res • Bedford (MA), Northern (KY)

Hybrid
USD 178,000 - 195,000