Position Summary The Cybersecurity Expert serves as the lead technical authority for information systems security engineering, automation, and architecture. This individual designs, implements, and operationalizes automated GRC frameworks, Compliance-as-Code (CaC), Policy-as-Code (PaC), and Infrastructure-as-Code (IaC) solutions aligned with Zero Trust and DoD Cybersecurity Risk Management Construct.
Key Responsibilities
Serve as lead technical resource for designing, developing, implementing, and operationalizing the automated GRC framework (PWS Section 5.7).
Design and implement a four-layer automation architecture:
Translate complex regulatory requirements (RMF, NIST SP 800-53, DISA STIGs) and architectural diagrams into functional, automated, and operational code.
Integrate and configure AWS-native security services (Audit Manager, Security Hub, Config, CloudTrail, CloudWatch) for continuous monitoring and automated evidence collection.
Support development of real-time Compliance Scoring Dashboards and RESTful APIs.
Participate in solution analysis and architectural reviews to ensure compliance with DoD regulations, Zero Trust principles, and DSCA policies.
Provide technical guidance to ISSMs, ISSOs, and other stakeholders on the security posture and operational function of automated systems.
Required Qualifications
Active SECRET clearance.
Bachelor’s degree from an accredited institution in Information Technology, Computer Science, Engineering, or related technical discipline.
Must possess one of the following certifications:
AWS Certified DevOps Engineer – Professional or AWS Certified Solutions Architect – Professional
AWS Certified Security – Specialty
ISC² CISSP (preferably with ISSEP or ISSAP concentration)
Twelve (12) years of demonstrated experience in systems engineering and cybersecurity, with at least seven (7) years focused on security automation, cloud engineering, and architecture.
Five (5) years of experience serving as a lead technical authority on enterprise-level projects responsible for designing and implementing security solutions (not just assessing them).
Five (5) years of experience translating complex regulatory requirements (RMF, NIST, DISA STIGs) and architectural diagrams into functional, automated, and operational code.
Flexible work from home options available.
Numbers & Facts
Location
Arlington, VA
Job Type
Full-time
Skills
Amazon Web Services (AWS)unmatched
Analysis Skillsunmatched
Application Programming Interface (API)unmatched
Architectural Servicesunmatched
Auditingunmatched
Automationunmatched
CISSP - Certified Information Systems Security Professionalunmatched
Cloud Architectureunmatched
Computer Scienceunmatched
Configuration Managementunmatched
Defense Information Systems Agency (DISA)unmatched
DevOpsunmatched
ISSAP - Information Systems Security Architecture Professionalunmatched
ISSEP - Information Systems Security Engineering Professionalunmatched
Information Systems Security Engineering (ISSE)unmatched
Information Technology & Information Systemsunmatched
Internet Securityunmatched
Maintain Complianceunmatched
Project Designunmatched
Protective Servicesunmatched
REST (Representational State Transfer)unmatched
Regulatory Complianceunmatched
Regulatory Requirementsunmatched
Reporting Dashboardsunmatched
Risk Managementunmatched
Secret Clearanceunmatched
Security Auditingunmatched
Software Engineeringunmatched
System Operationsunmatched
Systems Engineeringunmatched
Technical Leadershipunmatched
Technical/Engineering Designunmatched
U.S. National Institute of Standards and Technology (NIST)unmatched
United States Department of Defense (DoD)unmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.