Cybersecurity Engineer
Job Description
Nortex Cyber Solutions supports mission-critical information systems with security authorization, assessment, and continuous monitoring. This onsite role in Fort George G Meade, MD helps teams keep systems compliant with established governance while partnering with cybersecurity and engineering stakeholders to implement and validate security controls.
Responsibilities
- Support the full Risk Management Framework (RMF) lifecycle for information systems seeking or maintaining authorization.
- Develop, review, maintain, and update system security authorization packages and supporting bodies of evidence.
- Apply and interpret security controls and requirements in line with NIST SP 800-53 and DoD Instruction 8510.01 (RMF for DoD IT).
- Use security package management and governance tools such as eMASS and Xacta to develop, maintain, track, and manage authorization documentation.
- Scope and conduct assessments of systems undergoing accreditation/authorization or maintaining existing authorization.
- Support preparation, coordination, and approval of Interim Authorizations to Test (IATTs) for systems requiring testing prior to full authorization.
- Evaluate system configurations against DISA STIGs, CIS Benchmarks, and other security configuration standards.
- Conduct and analyze vulnerability assessments using ACAS/SecurityCenter and Nessus.
- Review vulnerability scan results, determine applicability and risk, track remediation, and support Plans of Action and Milestones (POA&Ms) as applicable.
- Collaborate with system engineers, developers, and other stakeholders to implement and validate security controls.
- Support automated solutions for continuous monitoring of security controls, vulnerabilities, configurations, and other requirements.
- Identify automation opportunities to improve RMF, evidence collection, assessment, and continuous monitoring processes.
- Appropriately leverage AI-enabled tools when beneficial, while maintaining sufficient cybersecurity and RMF expertise to understand, validate, and take responsibility for outcomes.
- Maintain organized, accurate, and traceable documentation linking security requirements, controls, assessment results, findings, remediation activities, and supporting evidence.
- Participate in Agile environments and work effectively within SAFe Agile processes.
- Communicate security risks, findings, and requirements clearly to cybersecurity and engineering stakeholders.
Requirements
- Active TS/SCI clearance with CI Polygraph required at time of hire.
- Ability to access required classified environments and security packages within NSA systems.
- Strong working knowledge of the DoD RMF and the complete authorization lifecycle.
- Strong knowledge of NIST SP 800-53 security and privacy controls and DoDI 8510.01.
- Experience developing, reviewing, and maintaining RMF authorization packages and supporting bodies of evidence.
- Hands-on experience with eMASS and/or Xacta.
- Strong understanding of DISA STIGs, CIS Benchmarks, system hardening, and security configuration requirements.
- Experience using ACAS/SecurityCenter and Nessus for vulnerability scanning, analysis, and remediation support.
- Experience scoping and conducting security assessments for systems undergoing or maintaining authorization.
- Knowledge of the IATT process and experience supporting systems requiring authorization for testing.
- Understanding of continuous monitoring requirements and approaches for validating security controls through the system lifecycle.
- Ability to work with technical teams to develop or implement automation supporting cybersecurity and continuous monitoring activities.
- Familiarity with SAFe Agile or similar Agile development environments.
- Strong written and verbal communication skills.
- Exceptional attention to detail, organization, documentation, and configuration management.
- Ability to maintain clear traceability across security requirements, implementation details, assessment procedures, findings, and supporting evidence.
Preferred Qualifications
- Experience supporting NSA, DoD, or Intelligence Community information systems.
- Experience working directly with system owners, ISSMs, ISSOs, security control assessors, and Authorizing Official representatives.
- Experience with continuous monitoring and automated security control validation.
- Experience integrating security activities into CI/CD or DevSecOps environments.
- Experience developing scripts, workflows, or automation to improve security assessment, evidence collection, vulnerability management, or compliance processes.
- Familiarity with AI-assisted cybersecurity or compliance workflows, with the technical expertise necessary to independently verify AI-generated outputs.
- Relevant cybersecurity certifications such as Security+, CISSP, CAP/CGRC, CASP+/SecurityX, or equivalent.
Benefits
- 100% Company-paid medical insurance for employees
- 100% Company-paid dental and vision insurance
- Competitive salary
- Generous 401k employer contribution with no required personal contribution and immediate vesting
- Generous PTO and parental leave
- Flexible work hours
Education & Experience
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical field preferred.
- 10+ years of relevant cybersecurity, information assurance, RMF, or systems security engineering experience.
- Equivalent combinations of education, certifications, and directly relevant experience may be considered.
Location & Clearance
- Location: Fort Meade, MD (onsite)
- Clearance required for start: Yes
- Clearance type: Top Secret/SCI with CI Polygraph
Physical Requirements
- Ability to remain seated and work at a computer for extended periods.
- Ability to occasionally lift up to 15 pounds.
- Ability to communicate effectively in person and through virtual collaboration tools.