Negotiable
Outside
Remote
USA
Summary: The Lead Cybersecurity Engineer will spearhead the organization's cybersecurity strategy, focusing on developing and enhancing enterprise cybersecurity programs. This role involves managing a team of cybersecurity professionals, overseeing various security functions, and collaborating with IT and business stakeholders to ensure security integration. The position requires expertise in regulatory compliance and a proactive approach to threat management and incident response.
Key Responsibilities:
- Developing, executing, and improving enterprise cybersecurity programs.
- Managing and mentoring a team of cybersecurity professionals.
- Overseeing threat detection, incident response, vulnerability management, and security monitoring.
- Architecting and implementing advanced security controls (identity & access, endpoint protection, cloud security, SIEM).
- Collaborating with IT, DevOps, and business stakeholders for security integration.
- Serving as a SME on regulatory compliance (NIST, CIS).
- Conducting risk assessments, penetration testing, and security audits.
- Reporting security posture and metrics to leadership.
- Staying updated on emerging cyber threats/tools/trends.
Key Skills:
- Bachelor's degree in Cybersecurity, Computer Science, or related field (or equivalent work experience).
- 5+ years of cybersecurity experience, with at least 2+ years in a leadership role.
- Expertise in network security, cloud security (AWS/Azure/Google Cloud Platform), identity management, endpoint security (Crowdstrike preferred), vulnerability management platforms (Qualys preferred) and SIEM platforms (Sumo Logic preferred).
- Strong understanding of risk management frameworks (NIST CSF, MITRE ATT&CK, FedRAMP).
- Proven track record of managing security incidents and implementing proactive defense strategies.
- Excellent communication, leadership, and stakeholder management skills.
- Must have the ability to obtain and maintain a Public Trust Security Clearance.
Salary (Rate): undetermined
City: Reston
Country: USA
Working Arrangements: remote
IR35 Status: outside IR35
Seniority Level: Senior
Industry: IT
Detailed Description From Employer:
Title: Lead Cybersecurity Engineer
Location: Remote (Reston, VA) [Local to Reston, VA preferred but will accept remote candidates. Local candidates required to be onsite 4 days a week]
Duration: Long Term Contract
Job Summary:
Lead Cybersecurity Engineer to drive organization's cybersecurity strategy. Key responsibilities include: Developing, executing, and improving enterprise cybersecurity programs. Managing and mentoring a team of cybersecurity professionals. Overseeing threat detection, incident response, vulnerability management, and security monitoring. Architecting and implementing advanced security controls (identity & access, endpoint protection, cloud security, SIEM). Collaborating with IT, DevOps, and business stakeholders for security integration. Serving as a SME on regulatory compliance (NIST, CIS). Conducting risk assessments, penetration testing, and security audits. Reporting security posture and metrics to leadership. Staying updated on emerging cyber threats/tools/trends
Required Skills :
- Bachelor s degree in Cybersecurity, Computer Science, or related field (or equivalent work experience).
- 5+ years of cybersecurity experience, with at least 2+ years in a leadership role.
- Expertise in network security, cloud security (AWS/Azure/Google Cloud Platform), identity management, endpoint security (Crowdstrike preferred), vulnerability management platforms (Qualys preferred) and SIEM platforms (Sumo Logic preferred).
- Strong understanding of risk management frameworks (NIST CSF, MITRE ATT\&CK, FedRAMP).
- Proven track record of managing security incidents and implementing proactive defense strategies.
- Excellent communication, leadership, and stakeholder management skills.
- Must have the ability to obtain and maintain a Public Trust Security Clearance.
Preferred Skills:
- Master s degree in Cybersecurity or related field.
- Industry certifications such as CISSP, CISM, CEH, OSCP, CCSP, or SANS GIAC.
- Experience with Zero Trust architecture and secure software development lifecycle (SSDLC).
- Familiarity with scripting languages (e.g., Python, etc.) for automation.
Security Clearance: Able to obtain MBI