More jobs:
Senior Cybersecurity Engineer Security Clearance
Job in
McLean, Fairfax County, Virginia, USA
Listed on 2026-07-20
Listing for:
Helios HR
Full Time
position Listed on 2026-07-20
Job specializations:
-
IT/Tech
Cybersecurity
Job Description & How to Apply Below
Job Title:
Senior Cybersecurity Engineer
Type of Employment:
Full Time + benefits
Location:
McLean, VA (Onsite)
Clearance:
Active Top Secret Job Overview:
We are seeking a highly skilled Cybersecurity Engineer (CSE) with extensive experience in air-gapped and classified container platforms, CI/CD pipelines, security automation, and federal cybersecurity requirements. The ideal candidate will possess hands-on expertise in Kubernetes, Open Shift, registry management, security test automation, and the implementation of cybersecurity controls in compliance with federal standards like NIST 800-53, DISA STIGs, and RMF/ATO workflows.
Required Clearance
• Top Secret minimum Required Skills
• 12 years of experience and a Masters degree. Degree can be substituted for 6 additional years of applicable experience
• IAT/IAM Level 3 Certification in compliance with DoD 8570/8140 guidelines
• Extensive experience working with Kubernetes, Open Shift, RKE2, and container registry management in air-gapped and classified environments.
• Deep understanding of CI/CD pipeline architectures, especially in disconnected networks.
• Expertise in federal cybersecurity frameworks, such as NIST 800-53, DISA STIGs, RMF, and ATO processes.
• Familiarity with security testing tools (SAST, DAST, IAST, IaC) and automated compliance validation.
• Proven track record of enforcing Zero Trust principles, PKI management, and network segmentation in a classified environment.
• Strong ability to map pipeline artifacts to RMF/ATO controls and support security operations during incidents.
• Extensive experience in cybersecurity design and architecture. Required Work Experience
A) Air-Gapped / Classified Container Platforms (Kubernetes/Open Shift/RKE2)
• Designing a Disconnected Cluster
• Design and manage a multi-container Open Shift hosted platform in an air-gapped enclave.
• Expertise in cross-domain CI/CD, blue-green testing, and platform deployment within disconnected environments.
• Familiar with image/helm/chart mirroring, FIPS 140 validated crypto, OS hardening (e.g., Alpine), and SELinux enforcing.
• Registry and Artifact Governance
• Maintain and govern a disconnected container registry, ensuring content sources, image signing, SBOMs, and vulnerability gating.
• Familiarity with tools such as Cosign, Syft, Grype, Trivy, OCI level attestations, and curated repository promotions.
• Admission Control & Policy Enforcement
• Enforce security baselines and policies without internet dependencies using tools like OPA Gatekeeper, Kyverno, and image provenance verification.
• Cluster Multi-Tenancy in SCIFs
• Implement RBAC, namespace isolation, and mTLS for mixed-sensitivity workloads within a SCIF (Sensitive Compartmented Information Facility).
• Patching and CVE Response Offline
• Manage critical Kubernetes CVEs in air-gapped enclaves through risk triage, change windows, and mirrored updates.
B) CI/CD & Security Test Automation (Disconnected)
• Pipeline Architecture for Classified Enclaves
• Design CI/CD pipelines to build, test, sign, scan, and promote containers across Dev ? Test ? Prod in closed networks.
• Familiarity with Git Lab/Jenkins runners, artifact promotion, and “compliance as code” practices.
• Automated Security Testing Coverage
• Implement automated tests for SAST, DAST, IAST, SCA, and IaC scanning within CI/CD pipelines.
• Ensure pipeline failures persist if discrepancies are detected.
• Evidence Generation for RMF
• Generate RMF/ATO evidence via automated pipeline outputs, mapping artifacts to NIST controls.
• Knowledge of OSCAL output, control mappings, and integration with evidence stores like eMASS.
• Promotion Gates & Provenance
• Ensure artifacts meet quality and security criteria (e.g., reproducible builds, signed/provenanced artifacts, passing STIG checks) before promotion to higher environments.
• Testing for Platform + App Security Regressions
• Implement tests for platform upgrade regressions using tools like kube-bench, kube-hunter, and e2e integration suites.
C) Federal Cybersecurity Requirements (RMF/ATO, STIGs, CNSS, FedRAMP)
• RMF Tailoring in Containerized Systems
• Tailor NIST 800-53 controls for…
Position Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×