Job Requirements
Ashburn, VA
Public Trust Polygraph Unspecified
Career Level not specified
$120,000 - $160,000
Job Description
Location: Ashburn, VA (onsite)
Travel Requirement: Less than 10%
Security Clearance: Must possess existing DHS EOD or DHS Suitability
The Cybersecurity Engineer supports the U.S. Customs and Border Protection (CBP) Operational Technology Operations Center (OTOC) and the build-out, integration, and operation of the Office of Information and Technology (OIT) ISS OTOC. This position will provide cybersecurity engineering, vulnerability management, incident response (IR), risk assessment, and Risk Management Framework (RMF) support for complex operational technology (OT) and mission systems.
This role is intended for a cybersecurity professional who can operate at the intersection of mission requirements, OT, systems engineering, software, infrastructure, and cybersecurity. The engineer will be responsible for translating operational and technical requirements into practical security requirements, identifying and assessing vulnerabilities, determining security and mission risk, and helping engineering and program teams make informed decisions throughout the system lifecycle.
The successful candidate will bring strong experience in vulnerability management, IR, and cybersecurity engineering, combined with a working knowledge of RMF, Authorization to Operate (ATO) processes, cybersecurity requirements, and mission/operational technology environments.
Duties and Responsibilities
Cybersecurity Engineering & Architecture
Vulnerability & Risk Management
Incident Response & Security Operations
RMF & Authorization
Mission & Cross-Functional Cybersecurity Support
Standards, Threats & Cybersecurity Practices
Requirements
Preferred Qualifications
About Sherpa 6:
At Sherpa 6 we love to solve problems and provide the best solutions for our customers. Our approach to a problem is to find a user-focused and design-driven solution that is simple yet functional and effective. We are a group of enthusiastic forward-thinkers who are excited to build amazing solutions with bleeding-edge technology. We hire people who are forward thinkers, passionate about what they do, love to collaborate and want to constantly learn. We enjoy what we do and we're not afraid to put the extra effort in to accomplish the mission; call us Sherpas. As a Service-Disabled Veteran Owned Small Business, we know what it means to serve. We have made it our mission to be the leaders in solutions that protect and give our Warfighters the edge they need when put into harm's way.
Background Screening/Check/Investigation:
Successful completion of a background screening/check/investigation will/may be required as a condition of hire.
ADA:
Sherpa 6 will make reasonable accommodations in compliance with the Americans with Disabilities Act 1990.
EEO/AA:
Sherpa 6 does not discriminate based on race, color, national origin, sex, religion age, disability, sexual orientation, gender identity, veteran status, height, weight, or marital status in employment or the provision of services and is an equal access/opportunity/affirmative action employer.
Benefits:
We offer a competitive benefits package, covering the cost of medical for you and your family; we also offer dental, vision, health and wellness benefits and a generous retirement savings plan. We believe that our employees can manage their workload and their personal life, therefore we extend a generous PTO policy. This allows our employees to balance their lives as they see fit.
Salary Range
The proposed salary range is reflective across all Sherpa 6 locations, years of experience, and skill levels. Salary negotiations will be based on a host of factors including but not limited to your geographic location, prior experience, relevant skills, education, and certifications.
Salary Description
$120,000-$160,000
Travel Requirement: Less than 10%
Security Clearance: Must possess existing DHS EOD or DHS Suitability
The Cybersecurity Engineer supports the U.S. Customs and Border Protection (CBP) Operational Technology Operations Center (OTOC) and the build-out, integration, and operation of the Office of Information and Technology (OIT) ISS OTOC. This position will provide cybersecurity engineering, vulnerability management, incident response (IR), risk assessment, and Risk Management Framework (RMF) support for complex operational technology (OT) and mission systems.
This role is intended for a cybersecurity professional who can operate at the intersection of mission requirements, OT, systems engineering, software, infrastructure, and cybersecurity. The engineer will be responsible for translating operational and technical requirements into practical security requirements, identifying and assessing vulnerabilities, determining security and mission risk, and helping engineering and program teams make informed decisions throughout the system lifecycle.
The successful candidate will bring strong experience in vulnerability management, IR, and cybersecurity engineering, combined with a working knowledge of RMF, Authorization to Operate (ATO) processes, cybersecurity requirements, and mission/operational technology environments.
Duties and Responsibilities
Cybersecurity Engineering & Architecture
- Provide cybersecurity engineering support for the integration, deployment, authorization, and sustainment of complex OTOC operational technology and mission systems.
- Translate mission, operational, and system requirements into actionable cybersecurity requirements and secure system architectures.
- Evaluate system designs, architectures, configurations, interfaces, and dependencies to identify cybersecurity risks, vulnerabilities, and attack surfaces.
- Integrate cybersecurity requirements into system design, development, testing, integration, deployment, and sustainment activities.
- Provide cybersecurity engineering guidance for applications, data platforms, tactical communications systems, mission networks, and authorized effectors.
- Collaborate with cross-functional engineering teams to resolve cybersecurity issues while maintaining mission performance, system availability, interoperability, and operational requirements.
Vulnerability & Risk Management
- Perform vulnerability identification, analysis, prioritization, remediation, and tracking across applications, infrastructure, networks, and operational technology environments.
- Assess vulnerabilities in the context of system architecture, mission impact, threat exposure, and operational risk.
- Analyze security findings and translate technical vulnerabilities into clear, actionable risk information for system owners, engineers, and program leadership.
- Develop and recommend risk mitigation strategies and work with engineering teams to implement appropriate security controls and corrective actions.
- Track security deficiencies and remediation activities through resolution, ensuring risks are appropriately mitigated, accepted, or otherwise managed.
Incident Response & Security Operations
- Support the identification, analysis, investigation, containment, remediation, and recovery of cybersecurity incidents affecting mission systems and operational technology environments.
- Collaborate with cybersecurity operations, engineering, and program teams to assess the technical and operational impact of security incidents and implement appropriate corrective actions.
- Support post-incident analysis and lessons learned, incorporating findings into vulnerability management, security controls, system architecture, and risk mitigation activities.
- Support incident response exercises, technical investigations, and recovery activities as required.
RMF & Authorization
- Support Risk Management Framework (RMF) activities throughout the system lifecycle, including security categorization, control implementation, assessment, remediation, and continuous monitoring.
- Support the development, maintenance, and execution of Authorization to Operate (ATO) activities and associated authorization artifacts.
- Develop and maintain cybersecurity documentation, including risk assessments, security plans, POA&Ms, control assessments, vulnerability assessments, and ATO documentation.
- Support cybersecurity assessments, audits, inspections, and technical reviews associated with system authorization and operational deployment.
- Support continuous monitoring and ongoing authorization activities to ensure systems remain secure, compliant, operationally viable, and supportable.
Mission & Cross-Functional Cybersecurity Support
- Serve as a technical cybersecurity advisor to systems engineering, software, infrastructure, operations, cybersecurity, and program leadership teams.
- Provide cybersecurity expertise throughout the system lifecycle, from requirements definition and architecture through integration, authorization, deployment, and sustainment.
- Work closely with engineering and program teams to incorporate cybersecurity considerations into technical and operational decision-making.
- Communicate cybersecurity risks, technical findings, and recommended courses of action to both technical and non-technical stakeholders.
Standards, Threats & Cybersecurity Practices
- Stay current with applicable cybersecurity standards, RMF requirements, vulnerability management practices, emerging threats, and cybersecurity technologies relevant to mission and operational technology environments.
- Apply evolving cybersecurity practices and threat information to support risk-informed security decisions and system protection.
Requirements
- Current DHS Suitability or the ability to obtain and maintain suitability.
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Systems Engineering, or a related technical discipline. Equivalent directly relevant professional experience may be substituted for the degree requirement.
- 5+ years of experience in cybersecurity engineering, information security, systems engineering, vulnerability management, or a closely related technical field.
- Demonstrated experience supporting mission-critical systems or environments with high availability, real-time communications, operational constraints, or other demanding performance requirements.
- Demonstrated experience with cybersecurity engineering, vulnerability management, risk assessment, and security architecture across complex systems, applications, infrastructure, networks, or operational technology environments.
- Experience supporting cybersecurity incident response, including incident analysis, investigation, containment, remediation, recovery, and post-incident activities.
- Experience applying FISMA, NIST cybersecurity standards and guidance, and the Risk Management Framework (RMF) to government information systems.
- Experience supporting systems through the security assessment and authorization/ATO lifecycle, including security control implementation, assessment, remediation, authorization, and continuous monitoring.
- Experience developing and maintaining System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), Security Assessment Reports (SARs), control implementation statements, security assessments, authorization evidence, system inventories, network diagrams, and data-flow diagrams.
- Demonstrated ability to analyze technical vulnerabilities and security findings, assess their operational and mission impact, and develop risk-based remediation or mitigation strategies.
- Experience translating mission and operational requirements into cybersecurity requirements, security controls, and practical technical solutions.
- Experience working with system owners, engineers, authorizing officials, security leadership, program managers, and senior government stakeholders to resolve cybersecurity risks and support authorization decisions.
- Ability to communicate complex cybersecurity risks and technical findings clearly to both technical and non-technical audiences.
Preferred Qualifications
- Cybersecurity certification such as CISSP, CISM, Security+, GSEC, or equivalent. Equivalent demonstrated cybersecurity experience may be considered in lieu of certification, where permitted.
- Experience with government security authorization, RMF, vulnerability management, and continuous monitoring platforms and tools.
- Familiarity with security operations and monitoring technologies, including SIEM, EDR/XDR, IDS/IPS, threat intelligence, security analytics, and incident response platforms.
- Familiarity with Zero Trust architecture and identity-centric security, including identity and access management (IAM), privileged access management (PAM), endpoint security, threat detection, and access control.
- Experience supporting incident response exercises, tabletop exercises, after-action reviews, and remediation activities.
- Experience with cloud security and hybrid infrastructure, including AWS, Azure, or other government-authorized cloud environments.
- Experience integrating cybersecurity into DevSecOps, software development, CI/CD, or automated security testing environments.
- Experience assessing software, hardware, third-party, and supply-chain cybersecurity risks.
- Experience supporting FISMA reporting, federal cybersecurity assessments, agency cybersecurity policies, governance processes, and compliance activities.
- Experience developing or reviewing security architectures, system boundaries, system interconnections, attack surfaces, threat models, and cybersecurity requirements.
About Sherpa 6:
At Sherpa 6 we love to solve problems and provide the best solutions for our customers. Our approach to a problem is to find a user-focused and design-driven solution that is simple yet functional and effective. We are a group of enthusiastic forward-thinkers who are excited to build amazing solutions with bleeding-edge technology. We hire people who are forward thinkers, passionate about what they do, love to collaborate and want to constantly learn. We enjoy what we do and we're not afraid to put the extra effort in to accomplish the mission; call us Sherpas. As a Service-Disabled Veteran Owned Small Business, we know what it means to serve. We have made it our mission to be the leaders in solutions that protect and give our Warfighters the edge they need when put into harm's way.
Background Screening/Check/Investigation:
Successful completion of a background screening/check/investigation will/may be required as a condition of hire.
ADA:
Sherpa 6 will make reasonable accommodations in compliance with the Americans with Disabilities Act 1990.
EEO/AA:
Sherpa 6 does not discriminate based on race, color, national origin, sex, religion age, disability, sexual orientation, gender identity, veteran status, height, weight, or marital status in employment or the provision of services and is an equal access/opportunity/affirmative action employer.
Benefits:
We offer a competitive benefits package, covering the cost of medical for you and your family; we also offer dental, vision, health and wellness benefits and a generous retirement savings plan. We believe that our employees can manage their workload and their personal life, therefore we extend a generous PTO policy. This allows our employees to balance their lives as they see fit.
Salary Range
The proposed salary range is reflective across all Sherpa 6 locations, years of experience, and skill levels. Salary negotiations will be based on a host of factors including but not limited to your geographic location, prior experience, relevant skills, education, and certifications.
Salary Description
$120,000-$160,000
group id: 91099474