Ashburn, VA onsite with an opportunity to support mission-critical operational technology and defense mission systems. This role provides cybersecurity engineering across the CBP OTOC and the ISS OTOC build-out, integration, and operations, helping teams move from mission needs to secure architectures, vulnerability management, and RMF-aligned authorization activities.
At Sherpa 6, you will be part of a team that values both technical rigor and practical outcomes. The position includes a generous PTO policy plus comprehensive benefits for you and your family, along with strong retirement savings support.
Responsibilities
- Provide cybersecurity engineering support for integration, deployment, authorization, and sustainment of complex OTOC operational technology and mission systems.
- Translate mission, operational, and system requirements into actionable cybersecurity requirements and secure system architectures.
- Evaluate system designs, architectures, configurations, interfaces, and dependencies to identify cybersecurity risks, vulnerabilities, and attack surfaces.
- Integrate cybersecurity requirements into system design, development, testing, integration, deployment, and sustainment activities.
- Provide cybersecurity engineering guidance for applications, data platforms, tactical communications systems, mission networks, and authorized effectors.
- Collaborate with cross-functional engineering teams to resolve cybersecurity issues while maintaining mission performance, system availability, interoperability, and operational requirements.
- Perform vulnerability identification, analysis, prioritization, remediation, and tracking across applications, infrastructure, networks, and operational technology environments.
- Assess vulnerabilities in context of system architecture, mission impact, threat exposure, and operational risk.
- Analyze security findings and translate technical vulnerabilities into clear, actionable risk information for system owners, engineers, and program leadership.
- Develop and recommend risk mitigation strategies and support implementation of security controls and corrective actions.
- Support incident response activities including identification, analysis, investigation, containment, remediation, and recovery for cybersecurity incidents affecting mission systems and OT environments.
- Support post-incident analysis and lessons learned, incorporating findings into vulnerability management, security controls, system architecture, and risk mitigation activities.
- Support incident response exercises, technical investigations, and recovery activities as required.
- Support RMF activities across the system lifecycle, including security categorization, control implementation, assessment, remediation, and continuous monitoring.
- Support development, maintenance, and execution of Authorization to Operate (ATO) activities and associated authorization artifacts.
- Develop and maintain cybersecurity documentation, including risk assessments, security plans, POA&Ms, control assessments, vulnerability assessments, and ATO documentation.
- Support cybersecurity assessments, audits, inspections, and technical reviews tied to system authorization and operational deployment.
- Support continuous monitoring and ongoing authorization activities to ensure systems remain secure, compliant, operationally viable, and supportable.
- Serve as a technical cybersecurity advisor across systems engineering, software, infrastructure, operations, cybersecurity, and program leadership.
- Communicate cybersecurity risks, technical findings, and recommended courses of action to both technical and non-technical stakeholders.
- Stay current with applicable cybersecurity standards, RMF requirements, vulnerability management practices, emerging threats, and relevant technologies, applying them to risk-informed security decisions.
Requirements
- Must possess existing DHS EOD or DHS Suitability and be able to obtain and maintain suitability (as applicable).
- 5+ years of experience in cybersecurity engineering, information security, systems engineering, vulnerability management, or a closely related technical field.
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Systems Engineering, or a related technical discipline (equivalent directly relevant professional experience may be substituted).
- Demonstrated experience supporting mission-critical systems or environments with high availability, real-time communications, operational constraints, or other demanding performance requirements.
- Demonstrated experience with cybersecurity engineering, vulnerability management, risk assessment, and security architecture across complex systems, applications, infrastructure, networks, or operational technology environments.
- Experience supporting cybersecurity incident response, including incident analysis, investigation, containment, remediation, recovery, and post-incident activities.
- Experience applying FISMA, NIST cybersecurity standards and guidance, and the RMF to government information systems.
- Experience supporting systems through the security assessment and authorization/ATO lifecycle, including control implementation, assessment, remediation, authorization, and continuous monitoring.
- Experience developing and maintaining documentation such as System Security Plans (SSPs), POA&Ms, Security Assessment Reports (SARs), authorization evidence, system inventories, network diagrams, and data-flow diagrams.
- Demonstrated ability to analyze technical vulnerabilities and security findings, assess operational and mission impact, and develop risk-based remediation or mitigation strategies.
- Experience translating mission and operational requirements into cybersecurity requirements, security controls, and practical technical solutions.
- Experience working with system owners, engineers, authorizing officials, security leadership, program managers, and senior government stakeholders to resolve cybersecurity risks and support authorization decisions.
- Ability to communicate complex cybersecurity risks and technical findings clearly to both technical and non-technical audiences.
Preferred Qualifications
- Cybersecurity certification such as CISSP, CISM, Security+, GSEC, or equivalent (equivalent demonstrated cybersecurity experience may be considered where permitted).
- Experience with government security authorization, RMF, vulnerability management, and continuous monitoring platforms and tools.
- Familiarity with security operations and monitoring technologies, including SIEM, EDR/XDR, IDS/IPS, threat intelligence, security analytics, and incident response platforms.
- Familiarity with Zero Trust architecture and identity-centric security, including IAM, PAM, endpoint security, threat detection, and access control.
- Experience supporting incident response exercises, tabletop exercises, after-action reviews, and remediation activities.
- Experience with cloud security and hybrid infrastructure, including AWS, Azure, or other government-authorized cloud environments.
- Experience integrating cybersecurity into DevSecOps, software development, CI/CD, or automated security testing environments.
- Experience assessing software, hardware, third-party, and supply-chain cybersecurity risks.
- Experience supporting FISMA reporting, federal cybersecurity assessments, agency cybersecurity policies, governance processes, and compliance activities.
- Experience developing or reviewing security architectures, system boundaries, system interconnections, attack surfaces, threat models, and cybersecurity requirements.
Technology Focus
- RMF, Authorization to Operate (ATO), FISMA, NIST
- System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), Security Assessment Reports (SARs)
Salary, Travel, and Screening
Salary range: USD 120,000 - 160,000 per year.
Travel requirement: less than 10%.
Background screening/check/investigation: successful completion will/may be required as a condition of hire.
Benefits
- Medical coverage for you and your family
- Dental and vision benefits
- Health and wellness benefits
- Generous retirement savings plan
- Generous PTO policy
Reasonable accommodations: Sherpa 6 will make reasonable accommodations in compliance with the Americans with Disabilities Act of 1990.
Equal opportunity: Sherpa 6 does not discriminate based on race, color, national origin, sex, religion age, disability, sexual orientation, gender identity, veteran status, height, weight, or marital status, and is an equal access/opportunity/affirmative action employer.