Cybersecurity Engineer- CBP
Ashburn, IL - USA
Job Summary
Location: Ashburn VA (onsite)
Travel Requirement: Less than 10%
Security Clearance: Must possess existing DHS EOD or DHS Suitability
The Cybersecurity Engineer supports the U.S. Customs and Border Protection (CBP) Operational Technology Operations Center (OTOC) and the build-out integration and operation of the Office of Information and Technology (OIT) ISS OTOC. This position will provide cybersecurity engineering vulnerability management incident response (IR) risk assessment and Risk Management Framework (RMF) support for complex operational technology (OT) and mission systems.
This role is intended for a cybersecurity professional who can operate at the intersection of mission requirements OT systems engineering software infrastructure and cybersecurity. The engineer will be responsible for translating operational and technical requirements into practical security requirements identifying and assessing vulnerabilities determining security and mission risk and helping engineering and program teams make informed decisions throughout the system lifecycle.
The successful candidate will bring strong experience in vulnerability management IR and cybersecurity engineering combined with a working knowledge of RMF Authorization to Operate (ATO) processes cybersecurity requirements and mission/operational technology environments.
Duties and Responsibilities
Cybersecurity Engineering & Architecture
- Provide cybersecurity engineering support for the integration deployment authorization and sustainment of complex OTOC operational technology and mission systems.
- Translate mission operational and system requirements into actionable cybersecurity requirements and secure system architectures.
- Evaluate system designs architectures configurations interfaces and dependencies to identify cybersecurity risks vulnerabilities and attack surfaces.
- Integrate cybersecurity requirements into system design development testing integration deployment and sustainment activities.
- Provide cybersecurity engineering guidance for applications data platforms tactical communications systems mission networks and authorized effectors.
- Collaborate with cross-functional engineering teams to resolve cybersecurity issues while maintaining mission performance system availability interoperability and operational requirements.
Vulnerability & Risk Management
- Perform vulnerability identification analysis prioritization remediation and tracking across applications infrastructure networks and operational technology environments.
- Assess vulnerabilities in the context of system architecture mission impact threat exposure and operational risk.
- Analyze security findings and translate technical vulnerabilities into clear actionable risk information for system owners engineers and program leadership.
- Develop and recommend risk mitigation strategies and work with engineering teams to implement appropriate security controls and corrective actions.
- Track security deficiencies and remediation activities through resolution ensuring risks are appropriately mitigated accepted or otherwise managed.
Incident Response & Security Operations
- Support the identification analysis investigation containment remediation and recovery of cybersecurity incidents affecting mission systems and operational technology environments.
- Collaborate with cybersecurity operations engineering and program teams to assess the technical and operational impact of security incidents and implement appropriate corrective actions.
- Support post-incident analysis and lessons learned incorporating findings into vulnerability management security controls system architecture and risk mitigation activities.
- Support incident response exercises technical investigations and recovery activities as required.
RMF & Authorization
- Support Risk Management Framework (RMF) activities throughout the system lifecycle including security categorization control implementation assessment remediation and continuous monitoring.
- Support the development maintenance and execution of Authorization to Operate (ATO) activities and associated authorization artifacts.
- Develop and maintain cybersecurity documentation including risk assessments security plans POA&Ms control assessments vulnerability assessments and ATO documentation.
- Support cybersecurity assessments audits inspections and technical reviews associated with system authorization and operational deployment.
- Support continuous monitoring and ongoing authorization activities to ensure systems remain secure compliant operationally viable and supportable.
Mission & Cross-Functional Cybersecurity Support
- Serve as a technical cybersecurity advisor to systems engineering software infrastructure operations cybersecurity and program leadership teams.
- Provide cybersecurity expertise throughout the system lifecycle from requirements definition and architecture through integration authorization deployment and sustainment.
- Work closely with engineering and program teams to incorporate cybersecurity considerations into technical and operational decision-making.
- Communicate cybersecurity risks technical findings and recommended courses of action to both technical and non-technical stakeholders.
Standards Threats & Cybersecurity Practices
- Stay current with applicable cybersecurity standards RMF requirements vulnerability management practices emerging threats and cybersecurity technologies relevant to mission and operational technology environments.
- Apply evolving cybersecurity practices and threat information to support risk-informed security decisions and system protection.
- Current DHS Suitability or the ability to obtain and maintain suitability.
- Bachelors degree in Cybersecurity Computer Science Information Systems Systems Engineering or a related technical discipline. Equivalent directly relevant professional experience may be substituted for the degree requirement.
- 5 years of experience in cybersecurity engineering information security systems engineering vulnerability management or a closely related technical field.
- Demonstrated experience supporting mission-critical systems or environments with high availability real-time communications operational constraints or other demanding performance requirements.
- Demonstrated experience with cybersecurity engineering vulnerability management risk assessment and security architecture across complex systems applications infrastructure networks or operational technology environments.
- Experience supporting cybersecurity incident response including incident analysis investigation containment remediation recovery and post-incident activities.
- Experience applying FISMA NIST cybersecurity standards and guidance and the Risk Management Framework (RMF) to government information systems.
- Experience supporting systems through the security assessment and authorization/ATO lifecycle including security control implementation assessment remediation authorization and continuous monitoring.
- Experience developing and maintaining System Security Plans (SSPs) Plans of Action and Milestones (POA&Ms) Security Assessment Reports (SARs) control implementation statements security assessments authorization evidence system inventories network diagrams and data-flow diagrams.
- Demonstrated ability to analyze technical vulnerabilities and security findings assess their operational and mission impact and develop risk-based remediation or mitigation strategies.
- Experience translating mission and operational requirements into cybersecurity requirements security controls and practical technical solutions.
- Experience working with system owners engineers authorizing officials security leadership program managers and senior government stakeholders to resolve cybersecurity risks and support authorization decisions.
- Ability to communicate complex cybersecurity risks and technical findings clearly to both technical and non-technical audiences.
Preferred Qualifications
- Cybersecurity certification such as CISSP CISM Security GSEC or equivalent. Equivalent demonstrated cybersecurity experience may be considered in lieu of certification where permitted.
- Experience with government security authorization RMF vulnerability management and continuous monitoring platforms and tools.
- Familiarity with security operations and monitoring technologies including SIEM EDR/XDR IDS/IPS threat intelligence security analytics and incident response platforms.
- Familiarity with Zero Trust architecture and identity-centric security including identity and access management (IAM) privileged access management (PAM) endpoint security threat detection and access control.
- Experience supporting incident response exercises tabletop exercises after-action reviews and remediation activities.
- Experience with cloud security and hybrid infrastructure including AWS Azure or other government-authorized cloud environments.
- Experience integrating cybersecurity into DevSecOps software development CI/CD or automated security testing environments.
- Experience assessing software hardware third-party and supply-chain cybersecurity risks.
- Experience supporting FISMA reporting federal cybersecurity assessments agency cybersecurity policies governance processes and compliance activities.
- Experience developing or reviewing security architectures system boundaries system interconnections attack surfaces threat models and cybersecurity requirements.
About Sherpa 6:
At Sherpa 6 we love to solve problems and provide the best solutions for our customers. Our approach to a problem is to find a user-focused and design-driven solution that is simple yet functional and effective. We are a group of enthusiastic forward-thinkers who are excited to build amazing solutions with bleeding-edge technology. We hire people who are forward thinkers passionate about what they do love to collaborate and want to constantly learn. We enjoy what we do and were not afraid to put the extra effort in to accomplish the mission; call us Sherpas. As a Service-Disabled Veteran Owned Small Business we know what it means to serve. We have made it our mission to be the leaders in solutions that protect and give our Warfighters the edge they need when put into harms way.
Background Screening/Check/Investigation:
Successful completion of a background screening/check/investigation will/may be required as a condition of hire.
ADA:
Sherpa 6 will make reasonable accommodations in compliance with the Americans with Disabilities Act 1990.
EEO/AA:
Sherpa 6 does not discriminate based on race color national origin sex religion age disability sexual orientation gender identity veteran status height weight or marital status in employment or the provision of services and is an equal access/opportunity/affirmative action employer.
Benefits:
We offer a competitive benefits package covering the cost of medical for you and your family; we also offer dental vision health and wellness benefits and a generous retirement savings plan. We believe that our employees can manage their workload and their personal life therefore we extend a generous PTO policy. This allows our employees to balance their lives as they see fit.
Salary Range
The proposed salary range is reflective across all Sherpa 6 locations years of experience and skill levels. Salary negotiations will be based on a host of factors including but not limited to your geographic location prior experience relevant skills education and certifications.
Required Experience:
IC
About Company
Sherpa 6 is a Veteran-Owned full-service engineering firm and the answer for all your design, development, and engineering needs.