{"schemaVersion":"jobsearcher.job.v1","id":"0573a31d3c8d113a6597b5a5","url":"https://jobsearcher.com/jobs/0573a31d3c8d113a6597b5a5","canonicalUrl":"https://jobsearcher.com/jobs/0573a31d3c8d113a6597b5a5","title":"Mid-Level Continuous Diagnostics and Mitigation (CDM) Engineer","description":"Description:\n\nK2United is an organization that houses two distinct, national, customer-facing brands tied together by a shared purpose: setting the standard for an extraordinary workplace. Through our brands, K2Share and CareerSafe, we provide advisory services in cyber risk management and online education for workforce readiness.\nOur four core values define how we show up every day:\nRespect Others - We lead with respect, building trust and connection.\nInternally Driven - We are relentlessly compelled to accomplish our objectives.\nCollaborative Innovation - We create by listening, sharing, and working together.\nClient Success - We hold our clients' mission as our own.\nWe believe in people who are accountable, curious, and motivated to make an impact that matters.\nOur programs make a meaningful difference. CareerSafe supports more than two million users each year, while K2Share delivers cybersecurity and IT solutions that strengthen federal agencies. As part of our team, you'll help solve complex challenges in a mission-driven, small-business environment that values professional growth, collaboration, and work-life balance.\nK2Share is seeking a CDM Engineer to support a federal health-sector client. In this role, you will implement, operate, and enhance the Continuous Diagnostics and Mitigation (CDM) program across a complex hybrid environment spanning on-premises, cloud, and third-party systems. Your work will improve enterprise visibility, strengthen cybersecurity posture, and help reduce operational risk by driving effective asset, configuration, and vulnerability management.\nYou'll support a large, hybrid enterprise environment of FIPS 199 Low and Moderate systems spanning on-premises, cloud, and third-party hosted services.\nThis position is remote first, with periodic on-site support in the Washington, DC metropolitan area as directed, and is contingent upon contract award.\nAbout You\nYou are a cybersecurity professional who thrives on building and improving enterprise security operations. You understand that effective vulnerability management is more than running scans. It requires collaboration, analysis, prioritization, and continuous improvement to help organizations make informed risk decisions.\nYou are comfortable working across hybrid environments, partnering with technical teams, system owners, and security stakeholders to improve visibility and reduce cyber risk. You enjoy solving complex operational challenges, communicating technical findings clearly, and helping organizations mature their continuous monitoring capabilities in alignment with federal cybersecurity standards.\nWhether responding to emerging vulnerabilities, improving scanning infrastructure, or supporting ongoing authorization efforts, you bring a proactive mindset, technical expertise, and a commitment to protecting mission-critical systems.\nYour Impact\nAs the CDM Engineer, you will play a key role in operating and advancing the client's Continuous Diagnostics and Mitigation program. You'll ensure security teams and system owners have the visibility and actionable intelligence needed to identify, prioritize, and remediate vulnerabilities across the enterprise.\nIn this role, you will:\nImplement, operate, and maintain Continuous Diagnostics and Mitigation (CDM) capabilities that strengthen enterprise cybersecurity posture.\nMaintain the CDM scanning infrastructure supporting client systems across on-premises, cloud, and hybrid environments.\nPartner with technical stakeholders to expand and mature CDM capabilities as the environment evolves through modernization and cloud adoption.\nSupport the transition to Ongoing Authorization by providing continuous monitoring and security visibility.\nDeliver continuous asset visibility and improve detection of vulnerabilities, configuration issues, unmanaged assets, and unauthorized software or hardware.\nManage enterprise vulnerability scanning infrastructure, including credentialed scanning across systems, devices, and applications.\nAnalyze vulnerability scan results, prioritize risk, and provide actionable remediation recommendations.\nMonitor the CISA Known Exploited Vulnerabilities (KEV) Catalog and other authoritative guidance to support timely remediation and compliance with applicable Binding Operational Directives.\nSupport enterprise asset inventory, configuration monitoring, and compliance reporting activities.\nCollaborate with the client and department stakeholders, system owners, administrators, and technical teams to improve security operations, optimize tools, and support incident response activities.\nContribute data and analysis supporting executive cybersecurity reporting, including weekly CIO dashboards and ad hoc vulnerability reports.\nProduce and maintain required CDM deliverables, including CDM Scan Results on the DHS-defined periodicity of no less than every three days, CDM Mitigation Procedures documenting mitigation steps and end-user mitigation activities when requested, and compliance reporting.\nRequirements:\n\nBachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field, or equivalent professional experience.\nFive or more years of experience supporting enterprise vulnerability management, Continuous Diagnostics and Mitigation (CDM), or security operations.\nExperience administering enterprise vulnerability scanning platforms and supporting credentialed scanning across large hybrid environments.\nWorking knowledge of the DHS Continuous Diagnostics and Mitigation (CDM) program, including asset management, configuration monitoring, reporting, and CDM dashboard concepts.\nFamiliarity with FISMA, FIPS 199, NIST SP 800-53 Rev. 5, Risk Management Framework (RMF), and continuous monitoring supporting Ongoing Authorization.\nExperience managing vulnerabilities in accordance with the CISA Known Exploited Vulnerabilities (KEV) Catalog and applicable CISA Binding Operational Directives.\nStrong analytical, communication, and collaboration skills with the ability to work effectively across technical and customer organizations.\nAbility to satisfy federal background investigation requirements and complete required onboarding before receiving system access.\nU.S. work authorization.\nPreferred Qualifications\nProfessional cybersecurity certification such as CISSP, CompTIA Security+, CySA+, or GIAC certifications (GCIH, GCIA, GMON).\nTenable platform certification (Tenable Certified Security Center Specialist or Nessus equivalent)\nExperience with enterprise vulnerability management tools such as Tenable.sc, Nessus, and related asset discovery, SIEM, EDR, or configuration management platforms.\nExperience securing AWS and/or Azure cloud environments, including cloud vulnerability and posture management.\nExperience supporting federal civilian agency continuous diagnostic and mitigation programs.\nExperience with scripting or automation using Python, PowerShell, or similar technologies to improve reporting and operational efficiency.\nBenefits\nWe're invested in the people who make our success possible. As a K2United employee, you'll enjoy a comprehensive benefits package designed to support your professional and personal well-being, including:\n401(k) with employer matching\nLow-cost medical coverage for employees and their families\nPaid time off\nPaid leave for jury duty, military service, voting, and other qualifying events\nWellness stipend, including fitness reimbursement\nTuition assistance\nCasual work environment\nTechnical training and certification support\nComplimentary access to CareerSafe online training courses for employees and their immediate family\nEqual Opportunity Employer\nK2United is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability, protected veteran status, or any other characteristic protected by applicable law.","company":"K2share","rawCompany":"k2share","city":"Denver","state":"CO","isRemote":false,"isActive":false,"createdAt":"2026-08-15T13:16:53.267Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Mid-Level Continuous Diagnostics and Mitigation (CDM) Engineer","description":"Description:\n\nK2United is an organization that houses two distinct, national, customer-facing brands tied together by a shared purpose: setting the standard for an extraordinary workplace. Through our brands, K2Share and CareerSafe, we provide advisory services in cyber risk management and online education for workforce readiness.\nOur four core values define how we show up every day:\nRespect Others - We lead with respect, building trust and connection.\nInternally Driven - We are relentlessly compelled to accomplish our objectives.\nCollaborative Innovation - We create by listening, sharing, and working together.\nClient Success - We hold our clients' mission as our own.\nWe believe in people who are accountable, curious, and motivated to make an impact that matters.\nOur programs make a meaningful difference. CareerSafe supports more than two million users each year, while K2Share delivers cybersecurity and IT solutions that strengthen federal agencies. As part of our team, you'll help solve complex challenges in a mission-driven, small-business environment that values professional growth, collaboration, and work-life balance.\nK2Share is seeking a CDM Engineer to support a federal health-sector client. In this role, you will implement, operate, and enhance the Continuous Diagnostics and Mitigation (CDM) program across a complex hybrid environment spanning on-premises, cloud, and third-party systems. Your work will improve enterprise visibility, strengthen cybersecurity posture, and help reduce operational risk by driving effective asset, configuration, and vulnerability management.\nYou'll support a large, hybrid enterprise environment of FIPS 199 Low and Moderate systems spanning on-premises, cloud, and third-party hosted services.\nThis position is remote first, with periodic on-site support in the Washington, DC metropolitan area as directed, and is contingent upon contract award.\nAbout You\nYou are a cybersecurity professional who thrives on building and improving enterprise security operations. You understand that effective vulnerability management is more than running scans. It requires collaboration, analysis, prioritization, and continuous improvement to help organizations make informed risk decisions.\nYou are comfortable working across hybrid environments, partnering with technical teams, system owners, and security stakeholders to improve visibility and reduce cyber risk. You enjoy solving complex operational challenges, communicating technical findings clearly, and helping organizations mature their continuous monitoring capabilities in alignment with federal cybersecurity standards.\nWhether responding to emerging vulnerabilities, improving scanning infrastructure, or supporting ongoing authorization efforts, you bring a proactive mindset, technical expertise, and a commitment to protecting mission-critical systems.\nYour Impact\nAs the CDM Engineer, you will play a key role in operating and advancing the client's Continuous Diagnostics and Mitigation program. You'll ensure security teams and system owners have the visibility and actionable intelligence needed to identify, prioritize, and remediate vulnerabilities across the enterprise.\nIn this role, you will:\nImplement, operate, and maintain Continuous Diagnostics and Mitigation (CDM) capabilities that strengthen enterprise cybersecurity posture.\nMaintain the CDM scanning infrastructure supporting client systems across on-premises, cloud, and hybrid environments.\nPartner with technical stakeholders to expand and mature CDM capabilities as the environment evolves through modernization and cloud adoption.\nSupport the transition to Ongoing Authorization by providing continuous monitoring and security visibility.\nDeliver continuous asset visibility and improve detection of vulnerabilities, configuration issues, unmanaged assets, and unauthorized software or hardware.\nManage enterprise vulnerability scanning infrastructure, including credentialed scanning across systems, devices, and applications.\nAnalyze vulnerability scan results, prioritize risk, and provide actionable remediation recommendations.\nMonitor the CISA Known Exploited Vulnerabilities (KEV) Catalog and other authoritative guidance to support timely remediation and compliance with applicable Binding Operational Directives.\nSupport enterprise asset inventory, configuration monitoring, and compliance reporting activities.\nCollaborate with the client and department stakeholders, system owners, administrators, and technical teams to improve security operations, optimize tools, and support incident response activities.\nContribute data and analysis supporting executive cybersecurity reporting, including weekly CIO dashboards and ad hoc vulnerability reports.\nProduce and maintain required CDM deliverables, including CDM Scan Results on the DHS-defined periodicity of no less than every three days, CDM Mitigation Procedures documenting mitigation steps and end-user mitigation activities when requested, and compliance reporting.\nRequirements:\n\nBachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field, or equivalent professional experience.\nFive or more years of experience supporting enterprise vulnerability management, Continuous Diagnostics and Mitigation (CDM), or security operations.\nExperience administering enterprise vulnerability scanning platforms and supporting credentialed scanning across large hybrid environments.\nWorking knowledge of the DHS Continuous Diagnostics and Mitigation (CDM) program, including asset management, configuration monitoring, reporting, and CDM dashboard concepts.\nFamiliarity with FISMA, FIPS 199, NIST SP 800-53 Rev. 5, Risk Management Framework (RMF), and continuous monitoring supporting Ongoing Authorization.\nExperience managing vulnerabilities in accordance with the CISA Known Exploited Vulnerabilities (KEV) Catalog and applicable CISA Binding Operational Directives.\nStrong analytical, communication, and collaboration skills with the ability to work effectively across technical and customer organizations.\nAbility to satisfy federal background investigation requirements and complete required onboarding before receiving system access.\nU.S. work authorization.\nPreferred Qualifications\nProfessional cybersecurity certification such as CISSP, CompTIA Security+, CySA+, or GIAC certifications (GCIH, GCIA, GMON).\nTenable platform certification (Tenable Certified Security Center Specialist or Nessus equivalent)\nExperience with enterprise vulnerability management tools such as Tenable.sc, Nessus, and related asset discovery, SIEM, EDR, or configuration management platforms.\nExperience securing AWS and/or Azure cloud environments, including cloud vulnerability and posture management.\nExperience supporting federal civilian agency continuous diagnostic and mitigation programs.\nExperience with scripting or automation using Python, PowerShell, or similar technologies to improve reporting and operational efficiency.\nBenefits\nWe're invested in the people who make our success possible. As a K2United employee, you'll enjoy a comprehensive benefits package designed to support your professional and personal well-being, including:\n401(k) with employer matching\nLow-cost medical coverage for employees and their families\nPaid time off\nPaid leave for jury duty, military service, voting, and other qualifying events\nWellness stipend, including fitness reimbursement\nTuition assistance\nCasual work environment\nTechnical training and certification support\nComplimentary access to CareerSafe online training courses for employees and their immediate family\nEqual Opportunity Employer\nK2United is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability, protected veteran status, or any other characteristic protected by applicable law.","datePosted":"2026-08-15T13:16:53.267Z","dateModified":"2026-08-15T13:16:53.267Z","hiringOrganization":{"@type":"Organization","name":"K2share","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Denver","addressRegion":"CO","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"0573a31d3c8d113a6597b5a5"},"url":"https://jobsearcher.com/jobs/0573a31d3c8d113a6597b5a5"}}