Journeyman Cybersecurity Engineer
Job Description
Support a Department of State GMOS environment by designing, implementing, and validating secure IT solutions across physical, virtual, and cloud platforms.
Responsibilities
- Design and implement security solutions for physical data centers, virtual hosting environments, and cloud platforms using defense-in-depth and zero-trust principles
- Ensure operating environments, system configurations, and infrastructure deployments meet Department of State and DT physical and information security requirements
- Apply security best practices across the system development lifecycle while meeting DOS security policies, FISMA requirements, NIST 800-53 controls, and STIGs
- Build network security capabilities including high-availability load balancing, DDoS detection and mitigation, intrusion prevention systems, and web application firewalls
- Implement and configure FedRAMP-compliant cloud systems, coordinating with the DOS Cloud Computing Governance Board (CCGB) for data sovereignty and boundary protections
- Provide security expertise for infrastructure architecture, including security architecture reviews, threat modeling, and risk assessments
- Implement monitoring, logging, and alerting integrated with Enterprise Monitoring and SIEM platforms
- Use DevSecOps tooling to build and optimize CI/CD pipelines and automate security validation and vulnerability scanning with Ansible, Terraform, Jenkins, GitLab, and SonarQube
- Perform security assessments, vulnerability testing, and security control validation; produce technical reports with remediation recommendations
- Coordinate with infrastructure engineers, application developers, security analysts, and Government stakeholders to deliver secure technical solutions
Requirements
- Bachelor’s degree plus 4 years of experience in related fields (cybersecurity engineering, security architecture, systems security engineering, network security, or DevSecOps); equivalencies considered
- Active Top Secret Clearance
- Experience with security engineering, security architecture design, security controls implementation, and secure system design principles
- Knowledge of information security frameworks including NIST 800-53, FISMA, Risk Management Framework (RMF), and Federal security requirements
- Understanding of network security technologies including firewalls, IDS/IPS, load balancers, DDoS mitigation, and cloud security architectures (AWS, Azure)
- Proficiency with DevSecOps tooling: Ansible, Terraform, Jenkins, GitLab, SonarQube, and CI/CD pipeline security integration
Technologies
- Ansible
- Terraform
- Jenkins
- GitLab
- SonarQube
- CI/CD pipelines
- NIST 800-53
- FISMA
- Risk Management Framework (RMF)
- STIGs
- SIEM platforms
- Splunk
- ArcSight
- QRadar
- FedRAMP
- DOS Cloud Computing Governance Board (CCGB)
- AWS
- Azure
- IDS/IPS
- Load balancers
- DDoS mitigation
- Firewalls
- Intrusion prevention systems
- Web application firewalls
- Enterprise Monitoring infrastructure
Benefits
- Healthcare
- Wellness
- Financial
- Retirement
- Family support
- Continuing education
- Time off benefits
- Flexible time off benefit
- Robust learning resources
Additional information
- Location: Ashburn, VA (onsite)
- Pay range: USD 94,400 - 198,200 per year
- Job category: Engineering
- Time type: Full time
- Employee type: Regular
- Minimum clearance required to start: Top Secret
- Travel: Up to 10% local
Desired
- Prior experience supporting federal agencies, especially the Department of State
- Professional security certifications such as CompTIA Security+, CISSP, CEH, CCSP, or GIAC certifications
- Experience with FedRAMP authorization processes, STIGs, and SIEM platforms (Splunk, ArcSight, QRadar)
- Background in threat modeling methodologies, penetration testing, and vulnerability assessment tools
What you can expect: A culture of integrity, an environment of trust, and a focus on continuous growth.