Cyber Security Engineer II
Job Description
ATTAINX INC is hiring a Cyber Security Engineer II to help secure and sustain CISA’s DocuSign environment. This role supports continuous monitoring, vulnerability remediation, security authorization activities, and controlled operational changes in a remote/hybrid setting with potential DHS CISA facility attendance.
Role Responsibilities
- Operate and secure DocuSign eSignature, Admin, Monitor, and related modules, while maintaining integrations with enterprise identity and collaboration platforms.
- Perform preventive, corrective, and perfective maintenance, including execution of approved change and patch management, emergency fixes, and vulnerability remediation.
- Monitor performance and forward security logs via DocuSign Monitor, maintaining dashboards, alerts, and supporting compliance evidence.
- Maintain POA&M documentation and remediation tracking, and support alignment with the Technical Reference Model and data loss prevention plans.
- Support secure data ingestion workflows, feature enablement, module activation, and operational readiness.
- Coordinate cutover planning and help desk readiness with CISA’s Technology Operations Center, providing Tier 1 support knowledge transfer.
- Help establish service level agreements, alerting procedures, and advisories with the Technology Operations Center.
- Maintain security and administrative SOPs, concepts of operations, governance artifacts, and user guidance, and support training, security authorization, and continuous improvement.
Required Qualifications
- Obtain and maintain a favorable DHS/CISA Entry on Duty or fitness determination, including completion of a background investigation appropriate to the position’s sensitivity and required access.
- Be authorized to work in the United States and meet DHS/CISA personnel and system access requirements.
- Be a US Citizen able to obtain a DHS CISA Docusign Public Trust clearance.
- Minimum 3-5 years of related cybersecurity or security engineering experience, including at least two (2) years supporting cloud or SaaS security operations.
- Bachelor’s degree in cybersecurity, computer science, information systems, engineering, or a related field (preferred), or equivalent education, training, and relevant experience.
- Experience with vulnerability remediation, patch and change management, security logging, alerting, and incident response coordination.
- Experience applying NIST SP 800-53 controls and maintaining security authorization evidence, continuous monitoring records, and Plans of Action and Milestones (POA&Ms).
- Knowledge of enterprise identity integration, role-based access, data loss prevention, and secure SaaS configuration.
- Experience creating operational procedures, security dashboards, and technical documentation. DocuSign administration or monitoring experience is preferred.
- A current ISC2 Certified Information Systems Security Professional (CISSP) or ISC2 Certified Cloud Security Professional (CCSP) certification is highly preferred.
Technologies
- DocuSign, DocuSign eSignature, DocuSign Admin, DocuSign Monitor
- NIST SP 800-53
- Plans of Action and Milestones (POA&Ms)
- Data loss prevention
- Role-based access
- Enterprise identity integration
- ISC2 CISSP, ISC2 CCSP
- Technical Reference Model
Salary and Location
- Salary: USD 115,000 - 128,000 per year
- Location: Herndon, VA (hybrid)
- Work model: Remote/Hybrid for DHS CISA; government facility attendance may be required
Work Schedule
- Days: Monday through Friday
- Hours: 8:00 a.m. to 5:00 p.m. Eastern Time
- Core availability: 9:00 a.m. to 3:00 p.m., excluding federal holidays
Benefits
- Paid vacation
- Medical, dental, and vision insurance
- Matching 401(k) plan
- Tuition/training reimbursement
- Long- and short-term disability coverage
Work Authorization and Other Details
- Work authorization: Must be authorized to work in the United States and meet DHS/CISA personnel and system access requirements.
- Non-essential functions: Other related duties as assigned.
Physical Demands and Work Environment
- Physical demands: Primarily computer-based work, reviewing technical materials, and communicating with team members and stakeholders. Essential functions may be performed with or without reasonable accommodation.
- Work environment: Primarily performed at an approved remote work location with reliable connectivity, a secure workspace, and appropriate protection of Government equipment and sensitive information. Remote work is subject to DHS and CISA approval.
- Schedule flexibility: Occasional work outside normal hours, including weekends and holidays, may be required for crisis response or critical IT issues.