user avatar

Cyber Security Project Engineer

Darkhorse Geospatial LLC

Posted today

Job Requirements

Herndon, VA
Intel Agency (NSA, CIA, FBI, etc) Full Scope Polygraph
Mid Level Career (5+ yrs experience)
$150,000 - $225,000

Job Description

Cyber Security Project Engineer
Darkhorse Geospatial · On-site (Herndon, VA) · Full-time · SME / Expert / Manager levels
About the Role
Darkhorse Geospatial is hiring Cyber Security Project Engineers to support a federal cloud security program spanning four commercial cloud service providers — Amazon Web Services, Google Cloud, Oracle Cloud, and Microsoft Azure. You'll own security assessment, compliance, change management, and continuous monitoring end-to-end: reviewing bodies of evidence, running risk analysis on scan findings, facilitating technical exchange meetings with CSPs, and translating NIST RMF and ICD 503 into practical engineering decisions. Work sits at the intersection of hands-on technical assessment and policy — you'll partner with SCAs, common control providers, cloud providers, and other contractor teams to keep the mission moving without cutting security corners.
What You'll Do
• Assess cloud infrastructure and cloud services (AWS, GCP, Oracle Cloud, Azure) for security gaps and weaknesses against industry standards
• Review CSP body of evidence packages for completeness and accuracy
• Analyze security scan findings (Rapid7, Nessus, Qualys) and perform risk analysis on critical/high findings
• Monitor and close Plan of Action and Milestone (POA&M) items
• Support security control assessments — prepare packages for SCAs and work alongside them through the assessment cycle
• Conduct information system security engineering activities
• Facilitate technical exchange meetings (TEMs) with cloud service providers to review cloud service architectures
• Sustain and evolve standard operating procedures against program objectives
• Advise Sponsor leadership on cloud security services and emerging risk
• Develop and maintain program metrics — assessment completion rates, finding remediation timelines, compliance status dashboards
• Provide project/program management support — planning, task tracking, milestone management, resource coordination (Manager role)
• Prepare periodic program highlights, status reports, and leadership briefings
Core Skills We're Looking For
• Demonstrated experience conducting security assessments of cloud infrastructure and cloud services
• Hands-on experience designing, implementing, assessing, or reviewing systems on AWS, GCP, Oracle Cloud, or Azure
• Experience facilitating TEMs with cloud service providers to review architectures
• Continuous monitoring experience — scan analysis for critical/high findings with Rapid7, Nessus, and/or Qualys
• POA&M lifecycle experience (monitoring through closure)
• Compliance-tool experience: Xacta 360, RSA Archer, or Risk Vision
• Working knowledge of the common control provider concept within the NIST Risk Management Framework
• Security control assessment experience — working with SCAs and preparing security packages
• Information system security engineering experience
• Experience with cross-domain technology and common architecture designs
• Project management fundamentals — planning, task tracking, milestone management, resource coordination
• Experience developing program metrics, KPIs, and compliance dashboards
• Strong written and oral communication — technical reports, program highlights, status briefings, leadership communications
Nice to Have
• Experience with the Sponsor's or an IC element's A&A process
• Creating or reviewing A&A body of evidence documentation in a cloud security environment
• Identifying, implementing, or reviewing information security controls
• Hands-on Xacta 360 experience
• Familiarity with Sponsor's A&A tools
Level Guidance
• SME — Deep specialist across one or more CSPs; leads assessments and mentors the team on hard technical calls
• Expert — Senior individual contributor; owns assessment workstreams end-to-end across multiple CSPs
• Manager — Program management focus; owns planning, milestones, metrics, and leadership communications across the team
Qualifications
• Bachelor's degree in Computer Science, Information Systems, Cyber Security, Engineering, or related field (or equivalent experience)
• U.S. Citizenship required
• Active TS/SCI with Polygraph required
• Willingness to complete Select Contractor Screening Program (SCSP) medical screening if assigned to a designated High Risk Role
group id: 91074849