Cybersecurity Engineer
Listed on 2026-09-12
-
IT/Tech
Cybersecurity, Information Security & Data Protection
If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.
Cybersecurity EngineerArlington, VA, US
2 days ago Requisition
Salary Range: $ To $ Annually
POSITION
DESCRIPTION:
Pioneering Evolution is seeking a Cybersecurity Engineer to support the security and compliance posture of SyncPoint — a DoD financial system of record operating in a Department of Defense Impact Level 4 (IL4) environment. This role is responsible for supporting the pursuit and maintenance of an Authority to Operate (ATO), implementing and validating NIST SP 800-171 and CMMC Level 2 controls, and serving as the technical security authority for the program.
This is an oversight and hands‑on implementation role. The Cybersecurity Engineer will maintain the System Security Plan (SSP) and supporting compliance documentation, conduct gap assessments, implement technical controls, and work directly with developers, Dev Ops engineers, infrastructure teams, and program leadership to integrate security into system design and day‑to‑day operations, maintaining a continuously audit‑ready NIST SP 800-171 and CMMC Level 2 compliance posture.
The ability to work across compliance frameworks, cloud infrastructure, and software development workflows — rather than relying solely on automated scanning tools — is essential to this position.
Key Responsibilities:
ATO Lifecycle Management
- Support the ATO lifecycle for SyncPoint, including contributing to and maintaining the System Security Plan (SSP), security assessment documentation, and Plan of Action and Milestones (POA&M) in coordination with the Director of Technology, Platforms, and Implementation.
- Maintain continuous ATO posture through proactive control monitoring, evidence collection, and timely remediation of findings.
- Serve as the technical point of contact for security assessors, authorizing officials, and compliance stakeholders throughout the ATO lifecycle.
- Coordinate security review and assessment activities across engineering, operations, and leadership teams.
NIST SP 800-171 and CMMC Level 2 Compliance
- Interpret and apply NIST SP 800-171 security requirements, translating them into specific technical and administrative controls implemented within the SyncPoint environment.
- Conduct security and compliance gap assessments, document deficiencies, develop remediation plans, and validate that controls have been appropriately implemented.
- Maintain and update the SSP, control implementation statements, policies, procedures, and supporting evidence artifacts on behalf of the Director of Technology, Platforms, and Implementation.
- Coordinate with the organization’s Managed Service Provider (MSP) to validate MSP-implemented controls, define the organizational/project boundary, and ensure control coverage is accurate and complete within the ATO boundary.
- Monitor DoD CMMC and NIST SP 800-171 program requirements and maintain the program’s ongoing compliance and assessment readiness.
Technical Security Implementation
- Implement and validate security controls across Linux and cloud infrastructure, including system hardening, configuration management, patching, and logging.
- Configure and maintain identity and access management (IAM) controls including RBAC, least‑privilege access, privileged access management, and service identities across Azure and application tiers.
- Implement and validate network segmentation, firewall rules, private connectivity, VPN configurations, and network access controls appropriate for IL4 environments.
- Deploy and manage security monitoring, logging, alerting, and audit trail capabilities; investigate and respond to security findings and incidents.
- Support vulnerability management…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).