Negotiable
Outside
Remote
USA
Summary: The Cybersecurity Engineer will lead the organization's cybersecurity strategy, ensuring robust protection against cyber threats. This role requires a blend of technical expertise and leadership skills to manage a team and oversee various cybersecurity initiatives. The position is primarily remote, with the option to report on-site if located near Reston, VA. A strong background in cybersecurity, risk management, and incident response is essential for success in this role.
Key Responsibilities:
- Developing, executing, and improving enterprise cybersecurity programs.
- Managing and mentoring a team of cybersecurity professionals.
- Overseeing threat detection, incident response, vulnerability management, and security monitoring.
- Architecting and implementing advanced security controls (identity & access, endpoint protection, cloud security, SIEM).
- Collaborating with IT, DevOps, and business stakeholders for security integration.
- Serving as a SME on regulatory compliance (NIST, CIS).
- Conducting risk assessments, penetration testing, and security audits.
- Reporting security posture and metrics to leadership.
- Staying updated on emerging cyber threats/tools/trends.
Key Skills:
- Bachelor's degree in Cybersecurity, Computer Science, or related field (or equivalent work experience).
- 5+ years of cybersecurity experience, with at least 2+ years in a leadership role.
- Expertise in network security, cloud security (AWS/Azure/Google Cloud Platform), identity management, endpoint security (Crowdstrike preferred), vulnerability management platforms (Qualys preferred) and SIEM platforms (Sumo Logic preferred).
- Strong understanding of risk management frameworks (NIST CSF, MITRE ATT&CK, FedRAMP).
- Proven track record of managing security incidents and implementing proactive defense strategies.
- Excellent communication, leadership, and stakeholder management skills.
- Must have the ability to obtain and maintain a Public Trust Security Clearance.
Salary (Rate): undetermined
City: undetermined
Country: USA
Working Arrangements: remote
IR35 Status: outside IR35
Seniority Level: undetermined
Industry: IT
Cybersecurity Engineer
Client: General Services Administration (GSA)
POP: 12+ months
Location: Remote; Must report on-site if local to Reston, VA
SCOPE
Cybersecurity Engineer to drive organization's cybersecurity strategy.
REQUIRED SKILLS
- Bachelor s degree in Cybersecurity, Computer Science, or related field (or equivalent work experience).
- 5+ years of cybersecurity experience, with at least 2+ years in a leadership role.
- Expertise in network security, cloud security (AWS/Azure/Google Cloud Platform), identity management, endpoint security (Crowdstrike preferred), vulnerability management platforms (Qualys preferred) and SIEM platforms (Sumo Logic preferred).
- Strong understanding of risk management frameworks (NIST CSF, MITRE ATT\&CK, FedRAMP).
- Proven track record of managing security incidents and implementing proactive defense strategies.
- Excellent communication, leadership, and stakeholder management skills.
- Must have the ability to obtain and maintain a Public Trust Security Clearance.
PREFERRED SKILLS
- Master s degree in Cybersecurity or related field.
- Industry certifications such as CISSP, CISM, CEH, OSCP, CCSP, or SANS GIAC.
- Experience with Zero Trust architecture and secure software development lifecycle (SSDLC).
- Familiarity with scripting languages (e.g., Python, etc.) for automation.
TASKS
- Developing, executing, and improving enterprise cybersecurity programs.
- Managing and mentoring a team of cybersecurity professionals.
- Overseeing threat detection, incident response, vulnerability management, and security monitoring.
- Architecting and implementing advanced security controls (identity & access, endpoint protection, cloud security, SIEM).
- Collaborating with IT, DevOps, and business stakeholders for security integration.
- Serving as a SME on regulatory compliance (NIST, CIS).
- Conducting risk assessments, penetration testing, and security audits.
- Reporting security posture and metrics to leadership.
- Staying updated on emerging cyber threats/tools/trends