Avatar for Innovim
Innovim
Actively Hiring
IT solutions provider for business and scientific processes

Cybersecurity Engineer - CBO

Posted: 1 week ago• Recruiter recently active
Job Location
Remote Work Policy

In office - WFH flexibility

Visa Sponsorship

Not Available

RelocationAllowed
Skills
Splunk
CompTIA Security+
Vulnerability Management
SIEM
NIST SP 800-53
NIST Risk Management Framework
Microsoft Sentinel
Microsoft Defender
EDR/XDR
Tenable
NIST SP 800-207 Zero Trust
IAM/MFA
DoD 8140/8570 IAT/IAM

About the job

Location Washington, DC — hybrid; on-site as required by task assignment

Employment Type Full-time — contingent upon contract award

Salary Range $90,000 – $107,000

Clearance / Suitability Public Trust (Tier 2); U.S. citizenship or permanent residence required

Position Summary

The Cybersecurity Engineer designs, implements, and maintains enterprise security controls that enforce Zero Trust principles — identity-centric access, least-privilege enforcement, continuous monitoring, and threat detection — across cloud, network, and endpoint environments for a U.S. legislative branch agency. The role strengthens the organization's overall security posture and improves detection and response capabilities in alignment with NIST SP 800-53 and NIST SP 800-207.

Key Responsibilities

  • Implement and maintain enterprise security controls aligned with NIST SP 800-53 (AC, CM, SC, AU, IR, SI control families).
  • Enforce Zero Trust Architecture per NIST SP 800-207, including continuous verification, identity-centric security, and least-privilege access across cloud, network, and endpoint environments.
  • Configure and manage Identity and Access Management (IAM): authentication, authorization, role-based access control (RBAC), privileged access management (PAM), and multi-factor authentication (MFA).
  • Monitor, analyze, and respond to security events using enterprise tools (SIEM, EDR/XDR); support incident triage, containment, investigation, and remediation.
  • Maintain continuous monitoring capabilities — centralized log collection, correlation, and analysis with compliant log retention.
  • Conduct vulnerability scanning, assessment, and remediation across systems and applications; coordinate patching and mitigation.
  • Support cloud and application security (e.g., AWS, Azure): secure configuration, identity controls, and workload security.
  • Harden systems, applications, and cloud environments to secure configuration baselines; implement segmentation to limit lateral movement.
  • Perform risk analysis aligned with the NIST Risk Management Framework (RMF); conduct RCA for security incidents and control failures.
  • Develop and maintain cybersecurity SOPs, security baselines, and audit-ready documentation; support 24/7 security monitoring operations.

Required Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field (equivalent experience considered).
  • Minimum 8 years of hands-on cybersecurity engineering experience.
  • Demonstrated experience with SIEM (e.g., Microsoft Sentinel or Splunk), EDR/XDR (e.g., Microsoft Defender), IAM/MFA, and vulnerability management (e.g., Tenable).
  • Working knowledge of NIST SP 800-53, NIST SP 800-207 Zero Trust, and the NIST Risk Management Framework.
  • CompTIA Security+ (DoD 8140/8570 IAT/IAM) required; higher-level certification preferred.
  • S. citizenship or permanent residence status; ability to obtain a Public Trust (Tier 2) determination.

Preferred Qualifications

  • CISSP, CySA+, GIAC (e.g., GCIH, GCIA), or CEH.
  • Microsoft (SC-200/AZ-500) or AWS security certifications.
  • Hands-on experience with Microsoft Sentinel, Microsoft Defender, and Tenable.sc.
  • Experience securing hybrid Active Directory / Entra ID and M365 GCC environments.
  • Prior experience supporting federal or Congressional / legislative branch environments.

Clearance, Suitability & Security

U.S. citizenship or permanent residence status is required. The selected candidate must be able to obtain and maintain a Public Trust (Tier 2) suitability determination and will undergo an FBI criminal background check and U.S. Capitol Police fingerprinting prior to starting work, in accordance with the contract's security requirements. Remote work is authorized; however, on-site presence at the customer's facilities in Washington, DC (and, as needed, data-center/computing facilities in Ashburn, VA and Manassas, VA) may be required based on task assignment. Local travel to these sites is non-reimbursable. Core hours are 9:00 AM–6:00 PM ET, Monday–Friday; occasional after-hours or weekend maintenance activity may be required.

Compensation

Salary Range: $90,000 – $107,000, commensurate with experience, education, and certifications. INNOVIM offers a comprehensive benefits package including health, dental, and vision coverage, retirement savings, paid time off, and professional development support.

About the company

Innovim company logo

Innovim

Actively Hiring
IT solutions provider for business and scientific processes51-200 Employees
Learn more about Innovim image

Funding

AMOUNT RAISED
$2M
FUNDED OVER
1 round
Round
S
$2000000
Seed - Apr 2020

Similar Jobs

Archesys company logo
Archesys
Improving the government services that impact everyday lives
Astranis company logo
Astranis
Building next-generation internet satellites to get the world online
Wynd Labs company logo
Wynd Labs
Making AI Data Accessible. Building a suite of products powered by Grass
C3 AI company logo
C3 AI
C3 AI is a leading enterprise AI software provider for accelerating digital transformation
Mercor company logo
Mercor
Mercor is at the intersection of labor markets and AI research
SentiLink company logo
SentiLink
Find Us On: Forbes Fintech 50 list - we've even made history! First to go live with eCBSV
Orb company logo
Orb
Next-generation billing platform for usage-based pricing