Skip to main content
SMX

Cyber Security Engineer (5462)

RemoteUnited States only
Published
Role
Security
Experience
Senior
Employment
Full-time
Company size
Mid-size
$103.1k–$171.8k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

U.S. citizen Cybersecurity engineer with 5+ years experience (3+ supporting federal cloud security) to support FedRAMP/DoD IL4–6 authorizations, audit readiness and automation of compliance evidence using GRC platforms, scripting and cloud services. Must obtain/maintain Secret+ clearance and work remotely supporting a Herndon, VA team. Hands-on AWS/Azure experience and knowledge of NIST SP 800-53, RMF, SSPs/POA&M/SARs required.

Core skills

FedRAMP / DoD authorization artifacts (SSP, POA&M, SAR)GRC automation

Required skills

FedRAMPNIST SP 800-53DoD IL4DoD IL5DoD IL6RMFSSPSAPSARPOA&MGRC platformsAPIsscriptingautomationAWSAzureIAMencryptionloggingconfiguration managementsecurity monitoringvulnerability managementeMASSNessusTenableSplunkPrisma Cloud

Optional skills

ParamifyPythonPowerShellREST APIsinfrastructure-as-codeDevSecOpspolicy-as-codecontinuous control validation

What you'll do

  • Provide cybersecurity engineering and compliance support for FedRAMP and DoD-authorized cloud environments, including IL4–6.
  • Advise partners and customers on federal and DoD security requirements, authorization strategies, control implementation, and audit readiness.
  • Develop, review, and maintain authorization documentation, including SSPs, SAPs, SARs, POA&Ms, FedRAMP appendices, policies, and supporting evidence.
  • Support system authorization and reauthorization activities across FedRAMP/RMF, including gap assessments, control validation, evidence development, and remediation planning.
  • Leverage GRC platforms, APIs, scripts, and automation to streamline compliance workflows, evidence collection, documentation updates, control testing, and reporting.
  • Develop repeatable and auditable processes that reduce manual compliance effort and improve the accuracy and consistency of authorization artifacts.
  • Collaborate with cloud engineering and DevOps teams to design, implement, and validate security controls across AWS, Azure, and hybrid environments.
  • Review system changes and significant change requests to assess security impact, identify documentation updates, and maintain authorization boundaries.
  • Coordinate with system owners, engineers, 3PAOs, Authorizing Officials, and government stakeholders to address findings and support authorization outcomes.
  • Support continuous monitoring, vulnerability management, POA&M updates, remediation tracking, and recurring compliance deliverables.
  • Evaluate security tooling and data sources to identify opportunities for automated control validation and compliance reporting.
  • Track evolving federal cybersecurity requirements and translate them into practical technical and operational actions.

What they require

  • U.S. citizenship with the ability to obtain and maintain a Secret or higher security clearance.
  • Bachelor’s degree in Information Security, Cybersecurity, Computer Science, or a related field, or equivalent practical experience.
  • Five or more years of cybersecurity experience, including at least three years supporting federal cloud security engineering, information assurance, RMF, or ISSO functions.
  • Knowledge of NIST SP 800-53 Rev. 5, FedRAMP Moderate and High, DoD IL4–6 overlays, RMF, and related federal compliance frameworks.
  • Experience developing and maintaining SSPs, POA&Ms, SARs, policies, control evidence, and other authorization artifacts.
  • Experience supporting authorization planning, gap assessments, audit readiness, control implementation, and remediation activities.
  • Hands-on experience with AWS, Azure, or hybrid cloud environments, including IAM, encryption, logging, configuration management, and security monitoring.
  • Experience using GRC platforms, APIs, scripting, or automation to improve compliance and security workflows.
  • Familiarity with tools such as eMASS, Paramify, Nessus/Tenable, Splunk, Prisma Cloud, or comparable solutions.
  • CISSP, CGRC/CAP, CISM, Security+, or similar cybersecurity certificate.

Benefits

  • health insurance
  • paid leave
  • retirement

SMX

SMX is a team of technical and domain experts supporting missions from national security initiatives for the DoD to compliant healthcare solutions, providing digital transformation, secure mission acceleration, insights, and practical solutions.

Government ContractingMid-size

Details

Visa sponsorshipNo
$103.1k–$171.8k/yr