Senior Cybersecurity Engineer

Posted today

bcmcllcArlington (VA)
Information Security AnalystsComputer Systems Design Services

SENIORITY

Lead

Apply

About the role

BCMC is supporting a U.S. Government customer to provide onsite incident response to civilian Government agencies and critical asset owners who experience cyber‐attacks, offering immediate investigation and resolution. Contract personnel perform investigations to characterize the severity of breaches, develop mitigation plans, and assist with the restoration of services. We are seeking a Senior Cybersecurity Engineer (Controls & Assessment Lead) to support this critical customer mission.ResponsibilitiesLead security controls assessment and implementation for technology integration pilotsEstablish risk frameworks for pilot design and execution activitiesEnsure compliance with federal security requirements (NIST, FISMA, FedRAMP)Conduct security assessments of proposed technology insertionsDefine security boundaries and controls for pilot environmentsCoordinate with RMF and security teams on authorization activitiesEnsure pilots maintain security posture and avoid becoming security liabilitiesAssess security readiness for scaling pilots into productionDevelop security metrics for measuring pilot and production outcomesLead security governance review processes and decision pointsEnsure alignment with CISA Zero Trust Strategy and security architectureConduct risk assessments for technology insertions across federated environmentsSupport continuous monitoring and security validation of integrated capabilitiesProvide security guidance to development and operations teamsDocument security controls, procedures, and compliance evidenceRequired Skills and ClearancesU.S. CitizenshipActive TS/SCI clearanceAbility to obtain Department of Homeland Security (DHS) Entry on Duty (EOD) Suitability10+ years of experience in cybersecurity engineering or security architectureExpert knowledge of federal security frameworks (NIST 800‐53, RMF, FISMA)Experience leading security assessments and authorization activitiesStrong understanding of risk management and security controls implementationExperience with security compliance in operational environmentsKnowledge of Zero Trust architecture and implementation principlesExperience assessing security of AI/ML and emerging technologiesStrong analytical and problem‐solving skillsExcellent documentation and communication abilitiesDesired SkillsITIL, PMP, or similar operations/project management certificationExperience with CISA programs or similar federal cybersecurity operationsBackground in security assessment of malware analysis platformsExperience with cloud security assessment and authorizationKnowledge of critical infrastructure security requirementsExperience with continuous monitoring and automated compliance toolsFamiliarity with DevSecOps and security automation practicesBackground in penetration testing or vulnerability assessmentRequired EducationBS in Cyber Security, Computer Science, or related degree; Master's degree preferred, or HS Diploma and 7+ years of directly relevant experience.Desired CertificationsDoD 8140 IAT Level IIICAP, CRISCBenefitsExtremely competitive salary95% employer paid for employee medical, dental, & vision coverages100% employer paid for employee life, STD & LTD disability coverages401k with company match and profit sharingFlexible Spending Account (FSA) for dependent & health care11 standard holidays & 3 weeks of annual leave #J-18808-Ljbffr

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this

Senior Cybersecurity Engineer Jobs at bcmcllc | David Careers