Today
Top Secret/SCI
Unspecified
Full Scope Polygraph
IT - Security
Washington, DC (On-Site/Office)
Momentum Engineering, Inc., a Woman-Owned Small Business (WOSB), fosters an employee-centric culture. Our strength lies in our people. With a high percentage of employees holding advanced degrees in engineering, computer science, and related disciplines, we bring deep technical expertise to every mission. Our team includes professionals with security clearances and full-scope polygraphs, ensuring trusted, secure support for the most sensitive national security initiatives. Additionally, our workforce is equipped with industry-leading certifications, demonstrating a commitment to continuous learning and excellence. Most importantly, our exceptional employee retention rate reflects a culture of professional growth, mission focus, and dedication-ensuring long-term stability and expertise for our customers' critical needs.
Job Summary
Primary Responsibilities
Required Qualifications
Desired Qualifications
Exempt hourly position. 11 paid holidays, minimum of 3 weeks PTO, company sponsored group medical plan, company paid dental, vision, life insurance, and STD/LTD plans. Salary is dependent upon the candidate's experience and qualifications.
Job Summary
- The Cyber Security Subject Matter Expert (SME) will play a key role in ensuring the security and compliance of enterprise production applications within a cloud-based environment
- The SME will work closely with the Development, Cloud, and DevSecOps teams, as well as the Information System Security Officer (ISSO), Information System Security Manager (ISSM), and Security Control Assessor (SCA), to support the full lifecycle of system authorization activities-including achieving and maintaining Authority to Operate (ATO) or Authority to Connect (ATC)
- The ideal candidate will provide expert guidance on cybersecurity architecture, coordinate CONOPS and design reviews, drive remediation of security findings, and develop cybersecurity standards and frameworks across the program-rooted in Zero Trust principles
Primary Responsibilities
- ATO/ATC Support:
- Lead and coordinate efforts to obtain and maintain ATO/ATC for production systems, ensuring compliance with applicable security frameworks.
- Collaboration Across Teams:
- Partner with Development, Cloud, and DevSecOps teams to integrate security throughout the SDLC and CI/CD pipelines, ensuring secure-by-design implementations.
- Architecture & CONOPS Coordination:
- Review and contribute to system architectures, data flows, and Concept of Operations (CONOPS) documents to ensure alignment with Zero Trust principles and organizational security policies.
- Security Findings Management:
- Support and track the remediation of vulnerabilities and deficiencies identified through scans, assessments, and audits; create and manage Plans of Action & Milestones (POA&Ms) as required.
- Cybersecurity Standards Development:
- Develop and maintain enterprise cybersecurity standards, guidelines, and best practices to ensure consistent implementation of security controls across all program systems.
- Continuous Monitoring:
- Support ongoing assessment and authorization (A&A) activities, including risk assessments, configuration management, and continuous monitoring reporting.
- Zero Trust Implementation:
- Guide teams in applying Zero Trust Architecture (ZTA) principles-identity-centric access control, micro-segmentation, least privilege, and continuous validation-to all system designs and processes.
Required Qualifications
- Must have active Top Secret/SCI clearance
- Bachelor's Degree in Computer Science, Cybersecurity, Information Systems, or related field (or equivalent experience)
- 5+ years of progressive experience in cybersecurity, with at least 3 years supporting federal ATO/ATC processes
- In-depth knowledge of NIST RMF, FedRAMP, and Zero Trust Architecture frameworks
- Experience collaborating with ISSOs, ISSMs, SCAs, and engineering teams
- Familiarity with AWS cloud environments and DevSecOps pipelines
- Strong technical understanding of network security, IAM, encryption, and vulnerability management.
- Excellent communication and coordination skills
Desired Qualifications
- CISSP, CISM, CAP, or equivalent cybersecurity certification
- Experience with containerized applications, infrastructure as code (IaC), and continuous compliance tools
Exempt hourly position. 11 paid holidays, minimum of 3 weeks PTO, company sponsored group medical plan, company paid dental, vision, life insurance, and STD/LTD plans. Salary is dependent upon the candidate's experience and qualifications.
group id: 91159622