Cyber Risk Mitigation Engineer; VA ESOM
Listed on 2026-09-25
-
IT/Tech
Cybersecurity, Disaster Recovery IT
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Cyber Risk Mitigation Engineer (VA ESOM) based in United States.
This role focuses on strengthening cyber resilience and protecting application recovery capabilities across a federal technology environment. You will identify vulnerabilities, security dependencies, and cyber risks that could affect recovery and operational continuity. The position combines cybersecurity engineering, incident response, resilience planning, and security architecture to evaluate how systems respond to disruptive threats. You will design and support recovery exercises covering scenarios such as ransomware, destructive attacks, compromised credentials, and data corruption.
Working closely with application owners, engineers, and program leadership, you will translate technical findings into practical and measurable mitigation actions. This is a high-impact opportunity to help strengthen secure recovery processes and reduce the risk of reinfection, unauthorized access, and continued compromise.
- Identify cyber threats, vulnerabilities, and security dependencies that could affect application recovery and resilience.
- Develop tabletop exercise scenarios addressing ransomware, destructive attacks, compromised credentials, data corruption, and loss of trusted services.
- Define cyber-focused exercise objectives, assumptions, injects, expected decisions, and evaluation criteria.
- Evaluate coordination and alignment between information system contingency plans and incident response plans.
- Assess backup protection, privileged access, credential recovery, logging, network controls, clean recovery environments, and system reconstitution capabilities.
- Evaluate whether recovery procedures adequately reduce the risk of reinfection, unauthorized access, or continued compromise.
- Document cybersecurity findings and clearly distinguish confirmed weaknesses from assumptions requiring additional technical validation.
- Develop actionable mitigation recommendations with defined owners, priorities, and measurable completion criteria.
- Support restoration, failover, and recovery testing used to validate security improvements and resilience capabilities.
- Brief application owners, engineering teams, and program leadership on significant cyber recovery risks, findings, and mitigation progress.
- Collaborate with technical and program stakeholders to improve cyber recovery processes and strengthen operational resilience.
- Contribute to additional responsibilities aligned with customer requirements, business needs, and program priorities.
- Master's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical discipline.
- 10 years of relevant professional experience; additional relevant experience may be substituted for the required education on a year-for-year basis.
- Demonstrated experience in cybersecurity engineering, incident response, cyber resilience, security architecture, or a related discipline.
- Strong knowledge of identity and access management, network and endpoint security, logging, malware containment, backup protection, and secure system restoration.
- Ability to assess complex recovery environments, identify security weaknesses, and translate technical findings into practical mitigation strategies.
- Experience developing or supporting cybersecurity exercises, recovery testing, and resilience validation.
- Preferred: experience applying NIST SP 800-34, NIST SP 800-84, or NIST SP 800-53 contingency planning controls.
- Preferred: experience with ransomware recovery, clean-room restoration, privileged access recovery, or cyber recovery vaults.
- Preferred: experience…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).