Senior Cybersecurity Engineer
Senior
Cybersecurity Tools
Data Security
Dod Rmf
Endpoint Security
Engineer
Facilities Management
Information Security
Information Technology (IT)
InfoSec
Project Management
Risk Governance
Risk Management
Rmf
Rmf Ato
Security
Security Automation
Security Clearance
Security Compliance
Security Operations
Security Standards
Security Testing
Solution Architecture
Vulnerability Assessment
Job Description
Onsite in Tewksbury, MA, this Senior Cybersecurity Engineer role supports complex DoD systems by defining cybersecurity requirements and ensuring compliance through RMF/ATO documentation and evidence-ready architecture. If you value structured delivery, collaboration across engineering teams, and measurable progress through Agile, you will have a clear path to contribute technical security expertise while partnering with program stakeholders to align work with priorities.
What you’ll do
- Define system-level cybersecurity requirements and architect secure solutions across complex DoD environments.
- Analyze security data, test results, and assessment findings to identify risk, guide remediation, and validate outcomes.
- Prepare, maintain, and improve RMF/ATO documentation and other required cybersecurity compliance artifacts.
- Create cybersecurity architecture artifacts, strategies, implementation plans, and security policies that support secure integration.
- Lead or guide vulnerability assessments, A&A activities, and remediation validation.
- Collaborate with engineering and program teams to evaluate cybersecurity design alternatives and integrate security considerations into system design.
- Perform internal cybersecurity audits to verify control implementation and compliance.
- Support the development and testing of security controls across networks, databases, operating systems, applications, and hardware/software components.
- Champion Agile practices and serve as the team’s Scrum Master, facilitating ceremonies, removing impediments, and enabling predictable, iterative delivery.
- Maintain team-level Agile metrics, support backlog refinement, and work with the Product Owner to keep security work clearly defined and aligned with CDRL and program priorities. Deliver high-quality cybersecurity documentation, technical evidence, vulnerability responses, and security artifacts each sprint.
Required qualifications
- Bachelor’s degree in Cybersecurity, Computer Science, Engineering, or a related technical field, plus 5+ years of relevant experience.
- Strong understanding of cybersecurity principles and compliance requirements, including the DoD Risk Management Framework (RMF) as defined in NIST SP 800-37.
- Active and transferable U.S. government security clearance required on day one; U.S. Citizenship is required.
- Experience applying security controls, hardening standards, and vulnerability mitigation across operating systems, aligned to NSA (FIPS), NIST (SP 800), DISA STIGs, and USCYBERCOM.
- Hands-on experience with network and system security administration, including secure configuration and account management for Windows, Red Hat Enterprise Linux, and common network platforms (such as Cisco).
- Familiarity with vulnerability scanning tools (Nessus, OpenVAS, SCC) and the ability to interpret and apply results to remediation actions.
- Proficiency working with cybersecurity documentation, configuration files, and scripting or automation for evidence collection.
- Experience as a Scrum Master or Agile facilitator, including leading ceremonies, maintaining team metrics, removing impediments, and supporting iterative delivery.
- Hands-on experience as a Scrum Practitioner by writing/refining user stories, estimating security tasks, and delivering high-quality cybersecurity documentation and artifacts each sprint.
- Ability to collaborate closely with Product Owners, engineering teams, and stakeholders to maintain backlog clarity, prioritize work, and integrate security tasks into Agile planning cycles.
Preferred qualifications
- Familiarity with DoDI 8510.01 and its direction of RMF and ATO activities in DoD environments.
- Experience supporting U.S. Government contracts in roles such as Information Assurance Engineer, ISSO, or cybersecurity SME.
- Security-related network or operating system certifications or training (examples include Cisco, Microsoft, Red Hat).
- DoDI 8570.01 IAT/IAM/IASAE Level III compliant certification preferred; candidates not yet certified may be expected to obtain a qualifying credential within 12 months of hire.
- Experience serving as a Scrum Master or Agile facilitator, driving continuous improvement.
- Experience as a Scrum Practitioner contributing to backlog refinement, user story development, task decomposition, and delivery of high-quality cyber documentation or security artifacts.
- Ability to work independently with minimal supervision while coordinating across cross-functional teams.
Security clearance
- DoD Clearance: Secret
- Status requirement: Ability to obtain INTERIM U.S. government issued security clearance prior to start date is required.
- Citizenship: U.S. citizenship is required because only U.S. citizens are eligible for a security clearance.
Compensation and benefits
Salary range: USD 86,800 - 165,200 per year.
- Medical, dental, and vision
- Life insurance
- Short-term disability and long-term disability
- 401(k) match
- Flexible spending accounts
- Flexible work schedules
- Employee assistance program
- Employee Scholar Program
- Parental leave
- Paid time off
- Holidays