×
Register Here to Apply for Jobs or Post Jobs. X

Senior Cybersecurity Engineer - RMF​/ISSE Lead

Job in Sterling, Loudoun County, Virginia, 22170, USA
Listing for: CACI International Inc
Full Time position
Listed on 2026-07-10
Job specializations:
  • IT/Tech
    Cybersecurity, Systems Engineer, Network Security
Salary/Wage Range or Industry Benchmark: 103800 - 218100 USD Yearly USD 103800.00 218100.00 YEAR
Job Description & How to Apply Below

Job Overview

Senior Cybersecurity Engineer – RMF/ISSE Lead

Full time. Up to 10% local travel.

We are seeking a hands‑on Senior Cybersecurity Engineer to lead the security posture of our division’s family of Electronic Warfare systems. In this role, you will implement, maintain, and adapt comprehensive security measures to protect customer data, systems, and networks. Your work will ensure security is integrated throughout the system lifecycle, from design through operations, supporting the mission while maintaining a strong defensive posture.

In addition to your technical contributions, you will manage, guide, and mentor a small team of Security Engineers dedicated to supporting various security projects. This role requires strong leadership skills, deep understanding of security engineering principles, and the ability to foster a collaborative and innovative work environment.

This is an opportunity to make a direct impact on national security by leading cybersecurity operations for mission‑critical defense systems while developing the next generation of security professionals.

Responsibilities
  • Team Leadership and Management
    Lead, mentor, and manage a team of 3-5 Security Engineers. Oversee project timelines, ensure delivery of high-quality security solutions, conduct performance evaluations, and provide ongoing professional development opportunities.
  • Security Architecture & Engineering
    Lead the design and documentation of secure system architectures across web applications, application stacks, Web Application Firewalls (WAFs), Intrusion Detection/Prevention Sensors (IDS/IPS), antimalware technologies, and Advanced Persistent Threat (APT) prevention. Define security requirements and integrate capabilities across all SDLC phases (initiation, acquisition/development, implementation, operations/maintenance, disposition) following NIST 800-64 Rev. 2 guidelines.
  • RMF Process Execution
    Manage and execute Risk Management Framework (RMF) activities (Steps 1–6), performing ISSO/ISSE functions to guide systems from initial categorization through Authorization to Operate (ATO). Direct team efforts in supporting DoD or IC acquisition programs resulting in IATT and/or ATO.
  • Security Documentation & Compliance
    Develop, maintain, and review Assessment & Authorization (A&A) documentation using Xacta, eMASS, or equivalent tools (SSP, SCTM, BoE). Ensure hardware and software comply with Government Security Certification Officer (SCO) requirements and meet NIST SP 800-53, ICD 503, and CNSSI 1253 standards.
  • Continuous Monitoring & Vulnerability Management
    Implement continuous monitoring (Con Mon) activities and lead security audits using IC and DoD approved scanning tools:
    Nessus/ACAS, SCAP/SCC, STIG Viewer, Nmap, and additional vulnerability assessment platforms.
  • Incident Response
    Direct incident response activities and participate in on‑call rotation for security incidents.
Qualifications
  • Required Experience
    • Bachelor’s degree in computer science, cybersecurity, engineering, information technology, or related field (or equivalent experience)
    • 10+ years with demonstrated ISSE/ISSO responsibilities, preferably within the Intelligence Community or DoD environment
    • Experience achieving IATT and/or ATO on DoD or IC acquisition programs
    • People management or team leadership experience
  • Clearance & Certifications
    • Current active TS/SCI eligibility
    • DoD 8570/8140 IASAE Level III (e.g., CISSP)
  • Technical Expertise
    • RMF processes, NIST SP 800-53, NIST 800-64 Rev. 2
    • Experience integrating security across all SDLC phases
    • Network protocols (TCP/IP, DNS, HTTP/HTTPS), VPNs, IDS/IPS, firewalls, DMZ configurations
    • Hands‑on Linux/Unix experience
    • Web applications, application stacks, WAFs, and application‑layer security controls
    • A&A tracking tools (Xacta or eMASS), SCAP/SCC, vulnerability assessment tools (Nessus, ACAS, Tenable)
What You Can Expect

A culture of integrity:
At CACI, we place character and innovation at the center of everything we do. As a valued team member, you’ll be part of a high‑performing group dedicated to our customer’s missions and driven by a higher purpose – to ensure the safety of our nation.

An environment of trust: CACI values the unique…

Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary