user avatar

Cybersecurity Risk & Authorization Engineer - DAOR 3

NineFX, Inc.

Posted today

Job Requirements

Fort Meade, MD
Top Secret/SCI Full Scope Polygraph
Mid Level Career (5+ yrs experience)
Salary not specified
Join Premium to unlock estimated salaries

Job Description

We are seeking a Cybersecurity Risk & Authorization Engineer (DAOR 3) to support enterprise‑level Cybersecurity and risk‑management activities for complex IT environments. In this role, you will identify security requirements, evaluate and validate controls, and guide systems through secure development and authorization processes in alignment with federal information‑assurance standards.


Responsibilities
• Identify Cybersecurity requirements and verify implementation of appropriate security controls
• Conduct security risk assessments, analyses, and ongoing risk‑management activities for systems and network operations
• Support security‑control assessments, configuration‑management processes, and Cybersecurity awareness initiatives
• Ensure Cybersecurity considerations are integrated throughout development, deployment, and lifecycle risk‑management efforts, with focus on infrastructure protection and defensive IT strategies
• Collaborate with customers, IT teams, and senior leadership to drive enterprise Cybersecurity and risk‑management objectives
• Contribute to the design and refinement of security architectures
• Support secure integration of legacy systems into modernized IT environments
• Assist acquisition, RDT&E, and deployment activities by embedding Cybersecurity controls into operational system designs
• Prepare comprehensive authorization documentation, including risk assessments, POA&M development, and recommendations aligned with organizational and federal requirements


Core Capabilities
• Analyze Cybersecurity controls for systems entering operational deployment
• Develop risk assessments, POA&Ms, and authorization packages aligned with RMF and ICD 503
• Identify and enforce enterprise security requirements and compliance with policies and controls
• Coordinate effectively across customers, stakeholders, and leadership to achieve secure mission outcomes
• Support secure legacy‑system integration within current IT environments


Qualifications
• Active TS/SCI with Full Scope Polygraph (must already be held - no sponsorships)
• Eight (8) years of experience as an IT Risk Assessor, System Security Engineer, ISSM, or Delegated Authorizing Official (DAO)
• Bachelor’s degree in Computer Science, IT Engineering, or related field; may substitute four (4) additional years of experience
• IAM Level III: CISM, CISSP (or Associate), GSLC, or CCISO


Required Knowledge
• System‑security design principles
• Defense‑in‑depth / defense‑in‑breadth strategies
• Engineering lifecycle processes
• Information‑domain and cross‑domain solutions
• Controlled interfaces
• Identification, authentication, and authorization
• Systems integration
• ICD 503, NIST RMF
• Intrusion detection, incident handling, contingency planning
• Configuration management and change control
• Auditing processes
• Security‑authorization workflows
• Core Cybersecurity principles: confidentiality, integrity, availability, non‑repudiation, access control
• Security‑testing methodologies


Why Join Us
You will play a direct role in securing critical national‑level systems, shaping enterprise Cybersecurity architectures, and guiding high‑impact programs through rigorous authorization and deployment—where your expertise directly strengthens mission resilience and defensive capabilities.
group id: 91093879

Similar Jobs


Job Category
IT - Security
Clearance Level
Top Secret/SCI
Employer
NineFX, Inc.