Cyber Security Engineer DoS CSS
Listed on 2026-10-02
-
IT/Tech
Cybersecurity, Information Security & Data Protection
We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. One Zero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance.
Additional details are available on our website:
Position Title:
Cyber Security Engineer
Location:
Remote; must reside within the National Capital Region (NCR).
Work Schedule:
Full-time, 40 hours per week. Must be available during Department core hours of 9:00 a.m. – 3:00 p.m. ET, Monday – Friday, and flex working hours as needed to meet CST day-to-day and emergent requirements. No work is performed on Federal holidays or during Government closures. Participates in a rotating on-call schedule supporting 24x7x365 availability of the vulnerability and compliance scanning platforms.
Employment Type:
Full-Time, Exempt (W-2), contingent upon Call Order award
Clearance:
Secret
The Cyber Security Engineer supports daily operation of the Tenable and Wiz vulnerability and compliance scanning platforms and serves as the program's Dev Sec Ops security engineer. The engineer deploys agents, executes and schedules scans, triages and distributes results to ISSOs, and works with development teams to ensure static analysis, dependency, container image, and infrastructure-as-code security checks are implemented in CI/CD/CM pipelines and captured as authorization evidence.
Key Responsibilities- Operate Tenable andWiz day to day: scan execution and scheduling, Nessus Agent deployment and health, asset onboarding, grouping and tagging per CA configuration standards, and quality review of results.
- Distribute vulnerability and compliance scan results to ISSOs within 5 business days of scan completion; produce remediation tracking reports and metrics; support iPost application groupings.
- Participate in the on-call rotation and support platform backups, patching, and troubleshooting under direction of the Cyber Security Engineer III.
- Triage vulnerability, KEV, CVE, and STIG scan results; assist ISSOs in prioritizing critical and high findings to Department and BOD timelines.
- Ensure applicable pipeline security controls (SAST, dependency scanning, container image scanning, and infrastructure-as-code checks) are implemented in Dev Sec Ops CI/CD/CM pipelines; document the controls for the SSP and capture scan reports in the Evidence Index (RMF Step
3). - Analyze code and pipeline findings for security weaknesses and verify that mitigation strategies are validated and sustained across the system lifecycle.
- Perform risk identification and IT governance assessments throughout the CI/CD/CM pipeline; brief ISSOs on pipeline risks.
- Support hardened-build verification for development and production systems and ad-hoc scanning requests.
- Support agent, data ingest and sharing, and pipeline integration efforts.
- Maintain scanning SOPs and runbooks; provide Tenable/Wiz evidence for control demonstrations during RMF Step 4.
- Five (5)+ years of cybersecurity or systems engineering experience, including two (2)+ years operating Tenable, Wiz, or a comparable enterprise vulnerability management platform.
- Hands-on experience with CI/CD tooling (Git Lab CI, Jenkins, Azure Dev Ops, or Git Hub Actions) and at least one SAST/SCA or container scanning tool (e.g., Sonar Qube, Fortify, Snyk, Trivy, Anchore, Prisma).
- Scripting proficiency (Python, Power…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).