Find Jobs
Find Jobs Near You – Available Work in Your Location
Skip to job details
PI
PingWind Inc.
Senior Cybersecurity Engineer / DevSecOps Engineer
Career Insights for Cyber Security Engineer
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Virginia data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Cyber Security Engineer designs systems that protect the security of large databases, including databases with customer information and patient files. Examines client computer systems, identifies weak points in security, develops and implements new systems, monitors and responds to security issues.
$113,393 / year median in Virginia
-3% projected decline
Job Description
Job Requirements Quantico, VA Top Secret/SCI Polygraph Unspecified Career Level not specified $92,000
PingWind.
- $127,000
Job Description Location:
Russell-Knox Building (RKB)Quantico, VA PWS Task Area:
PWS 2.7
OSI Cloud Cyber Support Required Clearance:
Active Top Secret Certifications:
Security+ CE or higher (for example, CASP+ CE or CISSP)Required Education:
High school diploma or GED.Required Experience:
Minimum of three (3) years of specialized cybersecurity engineering, Risk Management Framework, vulnerability management, or DevSecOps experience in Federal or DoW environments. Position Description Ailani Wind Joint Venture is seeking a Senior Cybersecurity Engineer / DevSecOps Engineer to engineer and sustain security controls for OSI cloud systems and development pipelines. The engineer supports access control, secure configuration, vulnerability management, security monitoring, RMF evidence, and continuous monitoring. This senior position integrates security testing and compliance into engineering and delivery workflows, develops technical security architecture and baselines, and works with system owners and technical teams to identify, prioritize, document, and remediate risk.Primary Responsibilities Typical Responsibilities/Tasks:
- Engineer, implement, and sustain cybersecurity controls for cloud systems, applications, user access, and DevSecOps environments.
- Implement, validate, and document DISA STIG and SRG requirements, secure configuration baselines, and configuration-control processes.
- Design and support vulnerability-scanning architecture, authenticated scans, findings analysis, remediation tracking, and continuous assessment.
- Analyze ACAS, HBSS, and related security-tool results; validate findings; assign risk; and develop and manage POA&Ms.
- Engineer and sustain SIEM, logging, alerting, audit, and security-monitoring capabilities and use them to investigate security events.
- Integrate automated security checks and testing into infrastructure-as-code, application build, CI/CD, and release pipelines.
- Develop and maintain secure architecture, network and data-flow diagrams, control implementation statements, baselines, and engineering records.
- Support
NIST RMF
activities from system categorization and control selection through assessment, authorization, and continuous monitoring.- Develop and maintain RMF artifacts, including the Body of Evidence, SSP, RAR, SAP inputs, scan evidence, and remediation records in eMASS.
- Coordinate with system owners, ISSMs/ISSOs, developers, cloud engineers, administrators, assessors, and Government stakeholders to resolve risk.
- Lead technical reviews, root-cause analysis, corrective actions, control improvements, and security guidance for delivery teams. Required Qualifications
- Demonstrated
NIST RMF
experience from system categorization through continuous monitoring and authorization maintenance.- Experience developing and maintaining RMF and authorization artifacts, including a Body of Evidence, SSP, RAR, SAP inputs, and POA&Ms.
- Hands-on experience using ACAS, HBSS, e
MASS, DISA
STIGs/SRGs, and vulnerability-management processes.- Experience implementing and auditing secure configuration baselines and integrating security testing into DevSecOps workflows.
- Knowledge of SIEM, centralized logging, access control, cloud security architecture, risk analysis, and continuous monitoring.
- Ability to translate findings into prioritized corrective actions and communicate technical risk clearly to engineering and Government stakeholders. Desired Qualifications
- Current CASP+ CE, CISSP, or comparable advanced cybersecurity certification.
- Experience securing AWS GovCloud, Cloud One, container, Kubernetes, and infrastructure-as-code environments.
- Experience with automated policy, code, dependency, container, infrastructure, and configuration security testing.
- Experience supporting DAF or AFOSI authorization packages, assessors, and continuous-monitoring programs.
- Experience providing technical leadership and mentoring cybersecurity and DevSecOps personnel.
PingWind.
com Our benefits include:
- Eleven Federal Holidays
- Paid Time Off accrued each pay period
- Parental Leave
- Three medical plan choices with generous employer contribution
- Dental and Vision Insurance
- Company paid Short-Term and Long-Term Disability
- Company paid Life and AD&D Insurance
- 401k with competitive matching and vesting schedule
- Continuing education assistance
- Short Term / Long Term Disability & Life Insurance
- Medical, Dependent Care and Commuter Flexible Spending Accounts
- Employee Assistance Program
- Wellness benefits include Calm Health app and WellHub gym subsidy (formerly GymPass)
- 529 College Savings Plan
- Legal Insurance
- Pet Insurance Salary Range $92
- 127K The pay range for this job is a general guideline only and not a guarantee of compensation or salary.