{"schemaVersion":"jobsearcher.job.v1","id":"3abfa6eaeb039b3268f511c7","url":"https://jobsearcher.com/jobs/3abfa6eaeb039b3268f511c7","canonicalUrl":"https://jobsearcher.com/jobs/3abfa6eaeb039b3268f511c7","title":"Cybersecurity Engineer","description":"POSITION DESCRIPTION:\n\nPioneering Evolution is seeking a Cybersecurity Engineer to support the security and compliance posture of SyncPoint — a DoD financial system of record operating in a Department of Defense Impact Level 4 (IL4) environment. This role is responsible for supporting the pursuit and maintenance of an Authority to Operate (ATO), implementing and validating NIST SP 800-171 and CMMC Level 2 controls, and serving as the technical security authority for the program.\n\nThis is an oversight and hands-on implementation role. The Cybersecurity Engineer will maintain the System Security Plan (SSP) and supporting compliance documentation, conduct gap assessments, implement technical controls, and work directly with developers, DevOps engineers, infrastructure teams, and program leadership to integrate security into system design and day-to-day operations, maintaining a continuously audit-ready NIST SP 800-171 and CMMC Level 2 compliance posture. The ability to work across compliance frameworks, cloud infrastructure, and software development workflows — rather than relying solely on automated scanning tools — is essential to this position.\n\nKey Responsibilities:\n\nATO Lifecycle Management\n\nSupport the ATO lifecycle for SyncPoint, including contributing to and maintaining the System Security Plan (SSP), security assessment documentation, and Plan of Action and Milestones (POA&M) in coordination with the Director of Technology, Platforms, and Implementation.\nMaintain continuous ATO posture through proactive control monitoring, evidence collection, and timely remediation of findings.\nServe as the technical point of contact for security assessors, authorizing officials, and compliance stakeholders throughout the ATO lifecycle.\nCoordinate security review and assessment activities across engineering, operations, and leadership teams.\n\nNIST SP 800-171 and CMMC Level 2 Compliance\n\nInterpret and apply NIST SP 800-171 security requirements, translating them into specific technical and administrative controls implemented within the SyncPoint environment.\nConduct security and compliance gap assessments, document deficiencies, develop remediation plans, and validate that controls have been appropriately implemented.\nMaintain and update the SSP, control implementation statements, policies, procedures, and supporting evidence artifacts on behalf of the Director of Technology, Platforms, and Implementation.\nCoordinate with the organization’s Managed Service Provider (MSP) to validate MSP-implemented controls, define the organizational/project boundary, and ensure control coverage is accurate and complete within the ATO boundary.\nMonitor DoD CMMC and NIST SP 800-171 program requirements and maintain the program’s ongoing compliance and assessment readiness.\n\nTechnical Security Implementation\n\nImplement and validate security controls across Linux and cloud infrastructure, including system hardening, configuration management, patching, and logging.\nConfigure and maintain identity and access management (IAM) controls including RBAC, least-privilege access, privileged access management, and service identities across Azure and application tiers.\nImplement and validate network segmentation, firewall rules, private connectivity, VPN configurations, and network access controls appropriate for IL4 environments.\nDeploy and manage security monitoring, logging, alerting, and audit trail capabilities; investigate and respond to security findings and incidents.\nSupport vulnerability management processes including scan configuration, finding triage, risk acceptance, and remediation tracking.\n\nCloud and Infrastructure Security\n\nImplement and validate cloud security controls within Microsoft Azure Government (and/or AWS GovCloud), including storage encryption, identity management, network security groups, private endpoints, and security posture management.\nReview and contribute to Infrastructure as Code (IaC) using Bicep or Terraform to ensure secure-by-default infrastructure provisioning.\nSupport DevSecOps practices including repository security, secrets management, branch protections, and secure CI/CD pipeline configuration.\nApply Managed Identity, RBAC/ABAC, and Zero Trust principles across cloud-hosted workloads and services.\n\nCUI Protection\n\nImplement and oversee secure handling, storage, transmission, and disposal of Controlled Unclassified Information (CUI) across all SyncPoint environments and processes.\nEnsure development and operational workflows do not expose CUI through logs, development tools, AI services, or unauthorized environments.\nSupport data classification, labeling, and access-control requirements consistent with CUI handling requirements.\n\nSecurity Engineering Collaboration\n\nWork directly with software developers, infrastructure engineers, and the DevOps team to integrate security requirements into application design, infrastructure provisioning, and deployment processes.\nProvide actionable security requirements and guidance that engineers can implement — not just compliance checklist items.\nUse scripting and command-line tools (Bash, PowerShell, Python, Azure CLI) for administration, evidence collection, and automated compliance checks.\nInvestigate and interpret logs, system configurations, vulnerability reports, and security findings; communicate risk clearly to leadership.\n\nTechnical Environment:\n Compliance: NIST SP 800-171, CMMC Level 2, RMF, ATO, CUI\n Cloud: Microsoft Azure Government, AWS GovCloud\n IAM: Azure AD / Entra ID, RBAC, ABAC, Managed Identity, PAM\n Infrastructure: Linux, Windows Server, Network Segmentation, VPN, Firewalls\n IaC: Bicep, Terraform\n Monitoring/SIEM: Microsoft Defender for Cloud, Microsoft Sentinel, Azure Monitor\n CI/CD Security: Azure DevOps, Git, secrets management, branch protections\n Scripting: Bash, PowerShell, Python, Azure CLI, AWS CLI\n Documentation: SSP, POA&M, policies, procedures, control implementation statements\n\nKey Competencies\n\nATO lifecycle support and RMF process expertise\nNIST SP 800-171 and CMMC Level 2 depth — both compliance and technical implementation\nHands-on security engineering across cloud, Linux, and application tiers\nCUI handling and DoD data protection requirements\nClear, credible communication of risk and compliance status to leadership\nPractical problem-solving orientation — builds solutions, not just findings reports\nEffective cross-functional collaboration with engineering, DevOps, MSP partners, and program leadership\n\nREQUIRED EXPERIENCE:\n\nBachelor’s degree in Cybersecurity, Information Systems, Computer Science, or a related technical discipline, or equivalent professional experience.\n5+ years of professional experience in cybersecurity, information assurance, or a closely related field.\nDemonstrated hands-on experience implementing and assessing NIST SP 800-171 controls; familiarity with CMMC Level 2 requirements and assessment processes.\nStrong working knowledge of fundamental security principles: least privilege, Zero Trust, defense in depth, IAM, encryption, network segmentation, vulnerability management, and system hardening.\nProficiency with Linux system administration including command-line tools, permissions, services, logging, patching, and OS-level security hardening.\nStrong networking fundamentals: IP addressing, subnetting, routing, firewalls, VPN/private connectivity, and network access controls.\nWorking knowledge of cloud security within Microsoft Azure and/or AWS, including IAM, network security, storage encryption, logging, monitoring, and security posture management.\nAbility to produce and maintain SSPs, control implementation statements, POA&Ms, policies, procedures, and compliance evidence packages.\nScripting proficiency in at least one of: Bash, PowerShell, Python, Azure CLI.\nStrong written and verbal communication skills; ability to explain technical security risk to leadership and translate compliance requirements into engineering tasks.\nDemonstrated ability to independently investigate technical security problems and develop practical solutions.\n\nRequired Certifications (One or More):\n\nThe following certifications are required, reflecting the ATO oversight responsibility and the DoD operating environment:\n\nCompTIA Security+ (DoD 8570/8140 IAT Level II baseline — minimum acceptable; required if no higher certification held)\nCISSP (Certified Information Systems Security Professional) — strongly preferred for candidates leading an ATO program\nCISM (Certified Information Security Manager) — acceptable alternative to CISSP for candidates with a compliance/governance focus\nCAP / CGRC (Certified Authorization Professional / Governance, Risk, and Compliance) — directly applicable to ATO and RMF activities; highly valued\nMicrosoft Certified: Cloud and AI Security Engineer Associate (SC-500) — required or expected to be obtained within 6 months of hire given the Azure Government operating environment\n\nNote: Candidates holding CISSP + CAP/CGRC or CISSP + SC-500 represent the strongest certification profile for this role. Candidates who hold a legacy AZ-500 certification (earned prior to its August 31, 2026 retirement) remain qualified, as the certification stays valid on their transcript until its individual renewal date.\n\nDESIRED EXPERIENCE:\n\nActive experience working within DoD RMF (Risk Management Framework) processes, including ATO package preparation and assessment coordination.\nDemonstrated experience obtaining or maintaining an ATO for a DoD system.\nExperience with DoD IL4 or IL5 environments.\nFamiliarity with DISA STIGs, SCAP tooling, and automated compliance scanning.\nExperience with Infrastructure as Code security review (Bicep, Terraform).\nExperience configuring and reviewing Azure Policy, Microsoft Defender for Cloud, Microsoft Sentinel, or equivalent security posture tools.\nFamiliarity with PIEE, Navy ERP, or DoD financial system environments.\nCASP+ (CompTIA Advanced Security Practitioner) — DoD 8570 IAT Level III; valued for technical depth.\nCCSP (Certified Cloud Security Professional) — valued for cloud-native security expertise.\n\nWHO WE ARE AND WHAT WE OFFER:\n\nIn addition to competitive salaries and opportunities for professional development and advancement, our employees enjoy a comprehensive range of benefits. To keep pace with the changing needs of our employees, we continually evaluate our benefit plans.\n\nPaid time off\n10 paid holidays\nMedical insurance\nDental insurance\nVision insurance\nLegal assistance\nCompany-paid life insurance and AD&D\nCompany-paid long-term and short-term disability insurance\nTuition reimbursement\n401(k) plan with company contribution\nContinuing Education Opportunities","company":"Pioneering Evolution","rawCompany":"pioneering evolution","city":"Arlington","state":"VA","isRemote":false,"isActive":false,"createdAt":"2026-09-02T08:19:08.592Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Cybersecurity Engineer","description":"POSITION DESCRIPTION:\n\nPioneering Evolution is seeking a Cybersecurity Engineer to support the security and compliance posture of SyncPoint — a DoD financial system of record operating in a Department of Defense Impact Level 4 (IL4) environment. This role is responsible for supporting the pursuit and maintenance of an Authority to Operate (ATO), implementing and validating NIST SP 800-171 and CMMC Level 2 controls, and serving as the technical security authority for the program.\n\nThis is an oversight and hands-on implementation role. The Cybersecurity Engineer will maintain the System Security Plan (SSP) and supporting compliance documentation, conduct gap assessments, implement technical controls, and work directly with developers, DevOps engineers, infrastructure teams, and program leadership to integrate security into system design and day-to-day operations, maintaining a continuously audit-ready NIST SP 800-171 and CMMC Level 2 compliance posture. The ability to work across compliance frameworks, cloud infrastructure, and software development workflows — rather than relying solely on automated scanning tools — is essential to this position.\n\nKey Responsibilities:\n\nATO Lifecycle Management\n\nSupport the ATO lifecycle for SyncPoint, including contributing to and maintaining the System Security Plan (SSP), security assessment documentation, and Plan of Action and Milestones (POA&M) in coordination with the Director of Technology, Platforms, and Implementation.\nMaintain continuous ATO posture through proactive control monitoring, evidence collection, and timely remediation of findings.\nServe as the technical point of contact for security assessors, authorizing officials, and compliance stakeholders throughout the ATO lifecycle.\nCoordinate security review and assessment activities across engineering, operations, and leadership teams.\n\nNIST SP 800-171 and CMMC Level 2 Compliance\n\nInterpret and apply NIST SP 800-171 security requirements, translating them into specific technical and administrative controls implemented within the SyncPoint environment.\nConduct security and compliance gap assessments, document deficiencies, develop remediation plans, and validate that controls have been appropriately implemented.\nMaintain and update the SSP, control implementation statements, policies, procedures, and supporting evidence artifacts on behalf of the Director of Technology, Platforms, and Implementation.\nCoordinate with the organization’s Managed Service Provider (MSP) to validate MSP-implemented controls, define the organizational/project boundary, and ensure control coverage is accurate and complete within the ATO boundary.\nMonitor DoD CMMC and NIST SP 800-171 program requirements and maintain the program’s ongoing compliance and assessment readiness.\n\nTechnical Security Implementation\n\nImplement and validate security controls across Linux and cloud infrastructure, including system hardening, configuration management, patching, and logging.\nConfigure and maintain identity and access management (IAM) controls including RBAC, least-privilege access, privileged access management, and service identities across Azure and application tiers.\nImplement and validate network segmentation, firewall rules, private connectivity, VPN configurations, and network access controls appropriate for IL4 environments.\nDeploy and manage security monitoring, logging, alerting, and audit trail capabilities; investigate and respond to security findings and incidents.\nSupport vulnerability management processes including scan configuration, finding triage, risk acceptance, and remediation tracking.\n\nCloud and Infrastructure Security\n\nImplement and validate cloud security controls within Microsoft Azure Government (and/or AWS GovCloud), including storage encryption, identity management, network security groups, private endpoints, and security posture management.\nReview and contribute to Infrastructure as Code (IaC) using Bicep or Terraform to ensure secure-by-default infrastructure provisioning.\nSupport DevSecOps practices including repository security, secrets management, branch protections, and secure CI/CD pipeline configuration.\nApply Managed Identity, RBAC/ABAC, and Zero Trust principles across cloud-hosted workloads and services.\n\nCUI Protection\n\nImplement and oversee secure handling, storage, transmission, and disposal of Controlled Unclassified Information (CUI) across all SyncPoint environments and processes.\nEnsure development and operational workflows do not expose CUI through logs, development tools, AI services, or unauthorized environments.\nSupport data classification, labeling, and access-control requirements consistent with CUI handling requirements.\n\nSecurity Engineering Collaboration\n\nWork directly with software developers, infrastructure engineers, and the DevOps team to integrate security requirements into application design, infrastructure provisioning, and deployment processes.\nProvide actionable security requirements and guidance that engineers can implement — not just compliance checklist items.\nUse scripting and command-line tools (Bash, PowerShell, Python, Azure CLI) for administration, evidence collection, and automated compliance checks.\nInvestigate and interpret logs, system configurations, vulnerability reports, and security findings; communicate risk clearly to leadership.\n\nTechnical Environment:\n Compliance: NIST SP 800-171, CMMC Level 2, RMF, ATO, CUI\n Cloud: Microsoft Azure Government, AWS GovCloud\n IAM: Azure AD / Entra ID, RBAC, ABAC, Managed Identity, PAM\n Infrastructure: Linux, Windows Server, Network Segmentation, VPN, Firewalls\n IaC: Bicep, Terraform\n Monitoring/SIEM: Microsoft Defender for Cloud, Microsoft Sentinel, Azure Monitor\n CI/CD Security: Azure DevOps, Git, secrets management, branch protections\n Scripting: Bash, PowerShell, Python, Azure CLI, AWS CLI\n Documentation: SSP, POA&M, policies, procedures, control implementation statements\n\nKey Competencies\n\nATO lifecycle support and RMF process expertise\nNIST SP 800-171 and CMMC Level 2 depth — both compliance and technical implementation\nHands-on security engineering across cloud, Linux, and application tiers\nCUI handling and DoD data protection requirements\nClear, credible communication of risk and compliance status to leadership\nPractical problem-solving orientation — builds solutions, not just findings reports\nEffective cross-functional collaboration with engineering, DevOps, MSP partners, and program leadership\n\nREQUIRED EXPERIENCE:\n\nBachelor’s degree in Cybersecurity, Information Systems, Computer Science, or a related technical discipline, or equivalent professional experience.\n5+ years of professional experience in cybersecurity, information assurance, or a closely related field.\nDemonstrated hands-on experience implementing and assessing NIST SP 800-171 controls; familiarity with CMMC Level 2 requirements and assessment processes.\nStrong working knowledge of fundamental security principles: least privilege, Zero Trust, defense in depth, IAM, encryption, network segmentation, vulnerability management, and system hardening.\nProficiency with Linux system administration including command-line tools, permissions, services, logging, patching, and OS-level security hardening.\nStrong networking fundamentals: IP addressing, subnetting, routing, firewalls, VPN/private connectivity, and network access controls.\nWorking knowledge of cloud security within Microsoft Azure and/or AWS, including IAM, network security, storage encryption, logging, monitoring, and security posture management.\nAbility to produce and maintain SSPs, control implementation statements, POA&Ms, policies, procedures, and compliance evidence packages.\nScripting proficiency in at least one of: Bash, PowerShell, Python, Azure CLI.\nStrong written and verbal communication skills; ability to explain technical security risk to leadership and translate compliance requirements into engineering tasks.\nDemonstrated ability to independently investigate technical security problems and develop practical solutions.\n\nRequired Certifications (One or More):\n\nThe following certifications are required, reflecting the ATO oversight responsibility and the DoD operating environment:\n\nCompTIA Security+ (DoD 8570/8140 IAT Level II baseline — minimum acceptable; required if no higher certification held)\nCISSP (Certified Information Systems Security Professional) — strongly preferred for candidates leading an ATO program\nCISM (Certified Information Security Manager) — acceptable alternative to CISSP for candidates with a compliance/governance focus\nCAP / CGRC (Certified Authorization Professional / Governance, Risk, and Compliance) — directly applicable to ATO and RMF activities; highly valued\nMicrosoft Certified: Cloud and AI Security Engineer Associate (SC-500) — required or expected to be obtained within 6 months of hire given the Azure Government operating environment\n\nNote: Candidates holding CISSP + CAP/CGRC or CISSP + SC-500 represent the strongest certification profile for this role. Candidates who hold a legacy AZ-500 certification (earned prior to its August 31, 2026 retirement) remain qualified, as the certification stays valid on their transcript until its individual renewal date.\n\nDESIRED EXPERIENCE:\n\nActive experience working within DoD RMF (Risk Management Framework) processes, including ATO package preparation and assessment coordination.\nDemonstrated experience obtaining or maintaining an ATO for a DoD system.\nExperience with DoD IL4 or IL5 environments.\nFamiliarity with DISA STIGs, SCAP tooling, and automated compliance scanning.\nExperience with Infrastructure as Code security review (Bicep, Terraform).\nExperience configuring and reviewing Azure Policy, Microsoft Defender for Cloud, Microsoft Sentinel, or equivalent security posture tools.\nFamiliarity with PIEE, Navy ERP, or DoD financial system environments.\nCASP+ (CompTIA Advanced Security Practitioner) — DoD 8570 IAT Level III; valued for technical depth.\nCCSP (Certified Cloud Security Professional) — valued for cloud-native security expertise.\n\nWHO WE ARE AND WHAT WE OFFER:\n\nIn addition to competitive salaries and opportunities for professional development and advancement, our employees enjoy a comprehensive range of benefits. To keep pace with the changing needs of our employees, we continually evaluate our benefit plans.\n\nPaid time off\n10 paid holidays\nMedical insurance\nDental insurance\nVision insurance\nLegal assistance\nCompany-paid life insurance and AD&D\nCompany-paid long-term and short-term disability insurance\nTuition reimbursement\n401(k) plan with company contribution\nContinuing Education Opportunities","datePosted":"2026-09-02T08:19:08.592Z","dateModified":"2026-09-02T08:19:08.592Z","hiringOrganization":{"@type":"Organization","name":"Pioneering Evolution","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Arlington","addressRegion":"VA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"3abfa6eaeb039b3268f511c7"},"url":"https://jobsearcher.com/jobs/3abfa6eaeb039b3268f511c7"}}