Negotiable
Outside
Remote
USA
Summary: The Lead Cybersecurity Engineer will spearhead the organization's cybersecurity strategy, focusing on developing and enhancing enterprise cybersecurity programs. This role involves managing a team of cybersecurity professionals, overseeing various security functions, and ensuring compliance with regulatory standards. The position requires collaboration with IT and business stakeholders to integrate security measures effectively while staying abreast of emerging cyber threats.
Key Responsibilities:
- Developing, executing, and improving enterprise cybersecurity programs.
- Managing and mentoring a team of cybersecurity professionals.
- Overseeing threat detection, incident response, vulnerability management, and security monitoring.
- Architecting and implementing advanced security controls (identity & access, endpoint protection, cloud security, SIEM).
- Collaborating with IT, DevOps, and business stakeholders for security integration.
- Serving as a SME on regulatory compliance (NIST, CIS).
- Conducting risk assessments, penetration testing, and security audits.
- Reporting security posture and metrics to leadership.
- Staying updated on emerging cyber threats/tools/trends.
Key Skills:
- Bachelor's degree in Cybersecurity, Computer Science, or related field (or equivalent work experience).
- 5+ years of cybersecurity experience, with at least 2+ years in a leadership role.
- Expertise in network security, cloud security (AWS/Azure/Google Cloud Platform), identity management, endpoint security (Crowdstrike preferred), vulnerability management platforms (Qualys preferred) and SIEM platforms (Sumo Logic preferred).
- Strong understanding of risk management frameworks (NIST CSF, MITRE ATT&CK, FedRAMP).
- Proven track record of managing security incidents and implementing proactive defense strategies.
- Excellent communication, leadership, and stakeholder management skills.
- Must have the ability to obtain and maintain a Public Trust Security Clearance.
Salary (Rate): undetermined
City: Reston
Country: USA
Working Arrangements: remote
IR35 Status: outside IR35
Seniority Level: undetermined
Industry: IT
Title: Lead Cybersecurity Engineer
Location: Remote (Reston, VA) [Local to Reston, VA preferred but will accept remote candidates. Local candidates required to be onsite 4 days a week]
Duration: Long Term Contract
Job Summary:
Lead Cybersecurity Engineer to drive organization's cybersecurity strategy. Key responsibilities include: Developing, executing, and improving enterprise cybersecurity programs. Managing and mentoring a team of cybersecurity professionals. Overseeing threat detection, incident response, vulnerability management, and security monitoring. Architecting and implementing advanced security controls (identity & access, endpoint protection, cloud security, SIEM). Collaborating with IT, DevOps, and business stakeholders for security integration. Serving as a SME on regulatory compliance (NIST, CIS). Conducting risk assessments, penetration testing, and security audits. Reporting security posture and metrics to leadership. Staying updated on emerging cyber threats/tools/trends
Required Skills :
- Bachelor s degree in Cybersecurity, Computer Science, or related field (or equivalent work experience).
- 5+ years of cybersecurity experience, with at least 2+ years in a leadership role.
- Expertise in network security, cloud security (AWS/Azure/Google Cloud Platform), identity management, endpoint security (Crowdstrike preferred), vulnerability management platforms (Qualys preferred) and SIEM platforms (Sumo Logic preferred).
- Strong understanding of risk management frameworks (NIST CSF, MITRE ATT\&CK, FedRAMP).
- Proven track record of managing security incidents and implementing proactive defense strategies.
- Excellent communication, leadership, and stakeholder management skills.
- Must have the ability to obtain and maintain a Public Trust Security Clearance.
Preferred Skills:
- Master s degree in Cybersecurity or related field.
- Industry certifications such as CISSP, CISM, CEH, OSCP, CCSP, or SANS GIAC.
- Experience with Zero Trust architecture and secure software development lifecycle (SSDLC).
- Familiarity with scripting languages (e.g., Python, etc.) for automation.
Security Clearance: Able to obtain MBI