Cybersecurity Engineer Journeyman

Arlington, VA, US • Posted 1 day ago • Updated 5 hours ago
Full Time
On-site
Fitment

Dice Job Match Score™

✨ Finding the perfect fit...

Job Details

Skills

  • Cyber Security
  • FOCUS
  • Security Operations
  • Testing
  • DoD
  • DevSecOps
  • Security Controls
  • Firewall
  • Intrusion Detection
  • SIEM
  • Dynamic Testing
  • Penetration Testing
  • Continuous Integration
  • Continuous Delivery
  • Threat Modeling
  • OWASP
  • Strong Authentication
  • Authorization
  • RBAC
  • Encryption
  • Data Security
  • Incident Management
  • Collaboration
  • Auditing
  • Documentation
  • Configuration Management
  • Computer Science
  • Software Security
  • Software Development
  • Code Review
  • Security QA
  • Unix
  • Linux
  • Operating Systems
  • Git
  • Network
  • TCP/IP
  • HTTP
  • HTTPS
  • Regulatory Compliance
  • Java
  • Application Servers
  • Spring Framework
  • Spring Security
  • Web Services
  • Hibernate
  • SSO
  • Identity Management
  • SAML
  • LDAP
  • Access Control
  • HP
  • Fortify
  • Proxies
  • Burp Suite
  • Security Engineering
  • JavaScript
  • Node.js
  • Scripting
  • DevOps
  • Vagrant
  • Progress Chef
  • Gradle
  • Jenkins
  • Caching
  • Database
  • Agile
  • Scrum
  • Research
  • Security Clearance
  • Application Service Management
  • Oracle ASM
  • Management
  • Recruiting
  • Training
  • Office Administration
  • Inventory

Summary

The Cybersecurity Engineer Journeyman designs, implements, and manages application and infrastructure security solutions across an enterprise IT environment, with a focus on aligning with DoD and NIST requirements and integrating security throughout the DevSecOps lifecycle. They work closely with development, infrastructure, and security operations teams to embed secure architecture, controls, and testing into CI/CD pipelines while maintaining compliance and documentation standards. This role combines hands-on engineering, threat modeling, and incident response expertise with governance and training responsibilities to strengthen the organization's overall security posture.

Key Responsibilities
  • Design and implement secure application and infrastructure architectures that comply with DoD and NIST security requirements, including Zero Trust principles, while integrating security into DevSecOps practices.
  • Develop, configure, and manage security controls and tooling such as firewalls, intrusion detection/prevention systems, SIEM platforms, and identity and access management solutions to protect enterprise applications and services.
  • Embed secure coding practices into the software development lifecycle, including static and dynamic analysis, manual and automated code reviews, and penetration testing activities integrated into CI/CD pipelines.
  • Lead application threat modeling, risk and vulnerability assessments, and remediation activities across web and distributed applications, ensuring coverage of OWASP Top 10 and other relevant attack vectors.
  • Implement and maintain strong authentication and authorization mechanisms (including RBAC), encryption and hashing, key management, and data protection measures for APIs, web services, and backend components.
  • Monitor and analyze security events and logs, coordinate incident response procedures, and collaborate with development, network, and corporate security teams to investigate and resolve security incidents and weaknesses.
  • Define, maintain, and enforce application security best practices, policies, and standards; perform security audits and maintain compliance documentation for internal and external stakeholders.
  • Evaluate, select, and recommend application security tools and technologies (e.g., static analysis tools, intercepting proxies, configuration management and automation tools) to improve coverage, efficiency, and developer experience.
  • Train developers and other team members on secure code development techniques, common vulnerabilities, secure use of frameworks and libraries, and enterprise security protocols.

Required Qualifications
  • Bachelor's Degree in Computer Science, Engineering, or other technical discipline, or equivalent relevant experience.
  • 5-10 years of experience as an Application Security Developer, Application Security Analyst, or equivalent role with direct responsibility for securing web and distributed applications.
  • Demonstrated hands-on experience implementing and reviewing application security controls and practices across the full software development lifecycle, including architecture review, secure design, code review, and integrated security testing.
  • Strong experience working with Unix/Linux operating systems and modern source code management tools such as Git in a collaborative development environment.
  • Solid knowledge of network, system, and application-layer security concepts, including common attack methods and mitigation techniques across TCP/IP, HTTP/HTTPS, and related protocols.
  • Ability to communicate complex security issues, risks, and remediation recommendations clearly to developers, architects, and non-technical stakeholders.
  • Eligibility to obtain and maintain any required background investigations and to work in a federal or similar high-compliance environment, with appropriate citizenship as specified by the client.

Preferred Qualifications
  • Expertise with Java application server technologies such as Spring Framework, Spring Security, Web Services, REST, and Hibernate.
  • In-depth experience with single sign-on and identity management technologies, including SAML, LDAP, and related federation and access control solutions.
  • Hands-on experience with static code analysis tools (e.g., HP Fortify), intercepting proxies (e.g., Burp Suite), and security engineering in JavaScript, NodeJS, or other scripting languages.
  • Familiarity with DevOps/automation tooling such as Vagrant, Chef, Rake, Gradle, Jenkins, and cache databases, along with experience in Agile/Scrum development environments; experience with Axiomatics or similar ABAC platforms is a plus.

Compensation Ranges

Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.

EEO Requirements

It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.

All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment.

Physical Requirements

The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, "light office duties' or "lifting up to 50 pounds" or "some travel" required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions.

Disclaimer

The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10184228
  • Position Id: 4da20408e80448f0f0778987df41ad47
  • Posted 1 day ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Washington, District of Columbia

Today

Full-time

Washington, District of Columbia

Today

Full-time

Remote or Washington, District of Columbia

Today

Full-time

USD 140,000.00 - 160,000.00 per year

Tysons, Virginia

Today

Full-time

USD 158,050.00 - 193,325.00 per year

Search all similar jobs