{"schemaVersion":"jobsearcher.job.v1","id":"c840b35c8dfa6589cb5dff40","url":"https://jobsearcher.com/jobs/c840b35c8dfa6589cb5dff40","canonicalUrl":"https://jobsearcher.com/jobs/c840b35c8dfa6589cb5dff40","title":"Cybersecurity Engineer","description":"Ashburn, VA onsitewith an opportunity to support mission-critical operational technology and defense mission systems. This role provides cybersecurity engineering across the CBP OTOC and the ISS OTOC build-out, integration, and operations, helping teams move from mission needs to secure architectures, vulnerability management, and RMF-aligned authorization activities.\r\nAtSherpa 6 , you will be part of a team that values both technical rigor and practical outcomes. The position includes agenerous PTO policyplus comprehensive benefits for you and your family, along with strong retirement savings support.\r\nResponsibilitiesProvide cybersecurity engineering support for integration, deployment, authorization, and sustainment of complex OTOC operational technology and mission systems.\r\nTranslate mission, operational, and system requirements into actionable cybersecurity requirements and secure system architectures.\r\nEvaluate system designs, architectures, configurations, interfaces, and dependencies to identify cybersecurity risks, vulnerabilities, and attack surfaces.\r\nIntegrate cybersecurity requirements into system design, development, testing, integration, deployment, and sustainment activities.\r\nProvide cybersecurity engineering guidance for applications, data platforms, tactical communications systems, mission networks, and authorized effectors.\r\nCollaborate with cross-functional engineering teams to resolve cybersecurity issues while maintaining mission performance, system availability, interoperability, and operational requirements.\r\nPerform vulnerability identification, analysis, prioritization, remediation, and tracking across applications, infrastructure, networks, and operational technology environments.\r\nAssess vulnerabilities in context of system architecture, mission impact, threat exposure, and operational risk.\r\nAnalyze security findings and translate technical vulnerabilities into clear, actionable risk information for system owners, engineers, and program leadership.\r\nDevelop and recommend risk mitigation strategies and support implementation of security controls and corrective actions.\r\nSupport incident response activities including identification, analysis, investigation, containment, remediation, and recovery for cybersecurity incidents affecting mission systems and OT environments.\r\nSupport post-incident analysis and lessons learned, incorporating findings into vulnerability management, security controls, system architecture, and risk mitigation activities.\r\nSupport incident response exercises, technical investigations, and recovery activities as required.\r\nSupport RMF activities across the system lifecycle, including security categorization, control implementation, assessment, remediation, and continuous monitoring.\r\nSupport development, maintenance, and execution of Authorization to Operate (ATO) activities and associated authorization artifacts.\r\nDevelop and maintain cybersecurity documentation, including risk assessments, security plans, POA&Ms, control assessments, vulnerability assessments, and ATO documentation.\r\nSupport cybersecurity assessments, audits, inspections, and technical reviews tied to system authorization and operational deployment.\r\nSupport continuous monitoring and ongoing authorization activities to ensure systems remain secure, compliant, operationally viable, and supportable.\r\nServe as a technical cybersecurity advisor across systems engineering, software, infrastructure, operations, cybersecurity, and program leadership.\r\nCommunicate cybersecurity risks, technical findings, and recommended courses of action to both technical and non-technical stakeholders.\r\nStay current with applicable cybersecurity standards, RMF requirements, vulnerability management practices, emerging threats, and relevant technologies, applying them to risk-informed security decisions.\r\nRequirementsMust possess existingDHS EODorDHS Suitabilityand be able to obtain and maintain suitability (as applicable).\r\n5+ yearsof experience in cybersecurity engineering, information security, systems engineering, vulnerability management, or a closely related technical field.\r\nBachelor’s degree in Cybersecurity, Computer Science, Information Systems, Systems Engineering, or a related technical discipline (equivalent directly relevant professional experience may be substituted).\r\nDemonstrated experience supporting mission-critical systems or environments with high availability, real-time communications, operational constraints, or other demanding performance requirements.\r\nDemonstrated experience with cybersecurity engineering, vulnerability management, risk assessment, and security architecture across complex systems, applications, infrastructure, networks, or operational technology environments.\r\nExperience supporting cybersecurity incident response, including incident analysis, investigation, containment, remediation, recovery, and post-incident activities.\r\nExperience applyingFISMA ,NISTcybersecurity standards and guidance, and theRMFto government information systems.\r\nExperience supporting systems through the security assessment and authorization/ATO lifecycle, including control implementation, assessment, remediation, authorization, and continuous monitoring.\r\nExperience developing and maintaining documentation such as System Security Plans (SSPs), POA&Ms, Security Assessment Reports (SARs), authorization evidence, system inventories, network diagrams, and data-flow diagrams.\r\nDemonstrated ability to analyze technical vulnerabilities and security findings, assess operational and mission impact, and develop risk-based remediation or mitigation strategies.\r\nExperience translating mission and operational requirements into cybersecurity requirements, security controls, and practical technical solutions.\r\nExperience working with system owners, engineers, authorizing officials, security leadership, program managers, and senior government stakeholders to resolve cybersecurity risks and support authorization decisions.\r\nAbility to communicate complex cybersecurity risks and technical findings clearly to both technical and non-technical audiences.\r\nPreferred QualificationsCybersecurity certification such asCISSP ,CISM ,Security+ ,GSEC , or equivalent (equivalent demonstrated cybersecurity experience may be considered where permitted).\r\nExperience with government security authorization, RMF, vulnerability management, and continuous monitoring platforms and tools.\r\nFamiliarity with security operations and monitoring technologies, including SIEM, EDR/XDR, IDS/IPS, threat intelligence, security analytics, and incident response platforms.\r\nFamiliarity with Zero Trust architecture and identity-centric security, including IAM, PAM, endpoint security, threat detection, and access control.\r\nExperience supporting incident response exercises, tabletop exercises, after-action reviews, and remediation activities.\r\nExperience with cloud security and hybrid infrastructure, including AWS, Azure, or other government-authorized cloud environments.\r\nExperience integrating cybersecurity into DevSecOps, software development, CI/CD, or automated security testing environments.\r\nExperience assessing software, hardware, third-party, and supply-chain cybersecurity risks.\r\nExperience supporting FISMA reporting, federal cybersecurity assessments, agency cybersecurity policies, governance processes, and compliance activities.\r\nExperience developing or reviewing security architectures, system boundaries, system interconnections, attack surfaces, threat models, and cybersecurity requirements.\r\nTechnology FocusRMF, Authorization to Operate (ATO), FISMA, NIST\r\nSystem Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), Security Assessment Reports (SARs)\r\nSalary, Travel, and ScreeningSalary range:USD120,000 - 160,000per year.\r\nTravel requirement:less than 10%.\r\nBackground screening/check/investigation:successful completion will/may be required as a condition of hire.\r\nBenefitsMedical coverage for you and your family\r\nDental and vision benefits\r\nHealth and wellness benefits\r\nGenerous retirement savings plan\r\nGenerous PTO policy\r\nReasonable accommodations:Sherpa 6 will make reasonable accommodations in compliance with the Americans with Disabilities Act of 1990.\r\nEqual opportunity:Sherpa 6 does not discriminate based on race, color, national origin, sex, religion age, disability, sexual orientation, gender identity, veteran status, height, weight, or marital status, and is an equal access/opportunity/affirmative action employer.#J-18808-Ljbffr","company":"Cybersecurity","rawCompany":"cybersecurity","city":"Ashburn","state":"VA","isRemote":false,"isActive":false,"createdAt":"2026-10-05T01:33:25.230Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541330","title":"Engineering Services","slug":"engineering-services"},{"code":"928110","title":"National Security","slug":"national-security"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Cybersecurity Engineer","description":"Ashburn, VA onsitewith an opportunity to support mission-critical operational technology and defense mission systems. This role provides cybersecurity engineering across the CBP OTOC and the ISS OTOC build-out, integration, and operations, helping teams move from mission needs to secure architectures, vulnerability management, and RMF-aligned authorization activities.\r\nAtSherpa 6 , you will be part of a team that values both technical rigor and practical outcomes. The position includes agenerous PTO policyplus comprehensive benefits for you and your family, along with strong retirement savings support.\r\nResponsibilitiesProvide cybersecurity engineering support for integration, deployment, authorization, and sustainment of complex OTOC operational technology and mission systems.\r\nTranslate mission, operational, and system requirements into actionable cybersecurity requirements and secure system architectures.\r\nEvaluate system designs, architectures, configurations, interfaces, and dependencies to identify cybersecurity risks, vulnerabilities, and attack surfaces.\r\nIntegrate cybersecurity requirements into system design, development, testing, integration, deployment, and sustainment activities.\r\nProvide cybersecurity engineering guidance for applications, data platforms, tactical communications systems, mission networks, and authorized effectors.\r\nCollaborate with cross-functional engineering teams to resolve cybersecurity issues while maintaining mission performance, system availability, interoperability, and operational requirements.\r\nPerform vulnerability identification, analysis, prioritization, remediation, and tracking across applications, infrastructure, networks, and operational technology environments.\r\nAssess vulnerabilities in context of system architecture, mission impact, threat exposure, and operational risk.\r\nAnalyze security findings and translate technical vulnerabilities into clear, actionable risk information for system owners, engineers, and program leadership.\r\nDevelop and recommend risk mitigation strategies and support implementation of security controls and corrective actions.\r\nSupport incident response activities including identification, analysis, investigation, containment, remediation, and recovery for cybersecurity incidents affecting mission systems and OT environments.\r\nSupport post-incident analysis and lessons learned, incorporating findings into vulnerability management, security controls, system architecture, and risk mitigation activities.\r\nSupport incident response exercises, technical investigations, and recovery activities as required.\r\nSupport RMF activities across the system lifecycle, including security categorization, control implementation, assessment, remediation, and continuous monitoring.\r\nSupport development, maintenance, and execution of Authorization to Operate (ATO) activities and associated authorization artifacts.\r\nDevelop and maintain cybersecurity documentation, including risk assessments, security plans, POA&Ms, control assessments, vulnerability assessments, and ATO documentation.\r\nSupport cybersecurity assessments, audits, inspections, and technical reviews tied to system authorization and operational deployment.\r\nSupport continuous monitoring and ongoing authorization activities to ensure systems remain secure, compliant, operationally viable, and supportable.\r\nServe as a technical cybersecurity advisor across systems engineering, software, infrastructure, operations, cybersecurity, and program leadership.\r\nCommunicate cybersecurity risks, technical findings, and recommended courses of action to both technical and non-technical stakeholders.\r\nStay current with applicable cybersecurity standards, RMF requirements, vulnerability management practices, emerging threats, and relevant technologies, applying them to risk-informed security decisions.\r\nRequirementsMust possess existingDHS EODorDHS Suitabilityand be able to obtain and maintain suitability (as applicable).\r\n5+ yearsof experience in cybersecurity engineering, information security, systems engineering, vulnerability management, or a closely related technical field.\r\nBachelor’s degree in Cybersecurity, Computer Science, Information Systems, Systems Engineering, or a related technical discipline (equivalent directly relevant professional experience may be substituted).\r\nDemonstrated experience supporting mission-critical systems or environments with high availability, real-time communications, operational constraints, or other demanding performance requirements.\r\nDemonstrated experience with cybersecurity engineering, vulnerability management, risk assessment, and security architecture across complex systems, applications, infrastructure, networks, or operational technology environments.\r\nExperience supporting cybersecurity incident response, including incident analysis, investigation, containment, remediation, recovery, and post-incident activities.\r\nExperience applyingFISMA ,NISTcybersecurity standards and guidance, and theRMFto government information systems.\r\nExperience supporting systems through the security assessment and authorization/ATO lifecycle, including control implementation, assessment, remediation, authorization, and continuous monitoring.\r\nExperience developing and maintaining documentation such as System Security Plans (SSPs), POA&Ms, Security Assessment Reports (SARs), authorization evidence, system inventories, network diagrams, and data-flow diagrams.\r\nDemonstrated ability to analyze technical vulnerabilities and security findings, assess operational and mission impact, and develop risk-based remediation or mitigation strategies.\r\nExperience translating mission and operational requirements into cybersecurity requirements, security controls, and practical technical solutions.\r\nExperience working with system owners, engineers, authorizing officials, security leadership, program managers, and senior government stakeholders to resolve cybersecurity risks and support authorization decisions.\r\nAbility to communicate complex cybersecurity risks and technical findings clearly to both technical and non-technical audiences.\r\nPreferred QualificationsCybersecurity certification such asCISSP ,CISM ,Security+ ,GSEC , or equivalent (equivalent demonstrated cybersecurity experience may be considered where permitted).\r\nExperience with government security authorization, RMF, vulnerability management, and continuous monitoring platforms and tools.\r\nFamiliarity with security operations and monitoring technologies, including SIEM, EDR/XDR, IDS/IPS, threat intelligence, security analytics, and incident response platforms.\r\nFamiliarity with Zero Trust architecture and identity-centric security, including IAM, PAM, endpoint security, threat detection, and access control.\r\nExperience supporting incident response exercises, tabletop exercises, after-action reviews, and remediation activities.\r\nExperience with cloud security and hybrid infrastructure, including AWS, Azure, or other government-authorized cloud environments.\r\nExperience integrating cybersecurity into DevSecOps, software development, CI/CD, or automated security testing environments.\r\nExperience assessing software, hardware, third-party, and supply-chain cybersecurity risks.\r\nExperience supporting FISMA reporting, federal cybersecurity assessments, agency cybersecurity policies, governance processes, and compliance activities.\r\nExperience developing or reviewing security architectures, system boundaries, system interconnections, attack surfaces, threat models, and cybersecurity requirements.\r\nTechnology FocusRMF, Authorization to Operate (ATO), FISMA, NIST\r\nSystem Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), Security Assessment Reports (SARs)\r\nSalary, Travel, and ScreeningSalary range:USD120,000 - 160,000per year.\r\nTravel requirement:less than 10%.\r\nBackground screening/check/investigation:successful completion will/may be required as a condition of hire.\r\nBenefitsMedical coverage for you and your family\r\nDental and vision benefits\r\nHealth and wellness benefits\r\nGenerous retirement savings plan\r\nGenerous PTO policy\r\nReasonable accommodations:Sherpa 6 will make reasonable accommodations in compliance with the Americans with Disabilities Act of 1990.\r\nEqual opportunity:Sherpa 6 does not discriminate based on race, color, national origin, sex, religion age, disability, sexual orientation, gender identity, veteran status, height, weight, or marital status, and is an equal access/opportunity/affirmative action employer.#J-18808-Ljbffr","datePosted":"2026-10-05T01:33:25.230Z","dateModified":"2026-10-05T01:33:25.230Z","hiringOrganization":{"@type":"Organization","name":"Cybersecurity","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Ashburn","addressRegion":"VA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"c840b35c8dfa6589cb5dff40"},"url":"https://jobsearcher.com/jobs/c840b35c8dfa6589cb5dff40"}}