Talent.com
Senior Cybersecurity Engineer - Compliance & Risk Management

Senior Cybersecurity Engineer - Compliance & Risk Management

Human Resources Research OrganizationAlexandria, VA, USA
30+ days ago
Job type
  • Full-time
  • Quick Apply
Job description

Senior Cybersecurity Engineer - Compliance & Risk Management

The Human Resources Research Organization (HumRRO) is a non-profit leader in developing high-impact services and products in the arenas of employment, military, student testing, and professional credentialing and licensure. We work with federal and state government agencies, private sector organizations, and professional associations.

About the Organization

As a non-profit, HumRRO is dedicated to work that contributes to science and society. Our employees enjoy a highly collaborative and supportive environment that fosters innovation, ethical practice, and outstanding customer service. Our core operational staff includes Industrial-Organizational Psychologists, Educational Researchers, and Behavioral Science Consultants. We are committed to supporting a diverse workforce and to practicing equity and inclusion for all staff.

About the Job

We are seeking a Senior Cybersecurity Engineer to lead our enterprise compliance and security programs across federal, state, and private sector engagements. This role manages multiple compliance frameworks including CMMC, FedRAMP, SCRM, NIST 800-171 / 53, and ISO 27001 : 2022 regulatory requirements. You will work on compliance standards across hybrid cloud environments while leading a team of junior engineers conducting vulnerability assessments and security scanning operations. A significant portion of this role involves creating security documentation, developing compliance policies, responding to time-critical security requirements from clients, and managing third-party compliance audits.

As a Senior Cybersecurity Engineer, you will :

  • Lead enterprise cybersecurity compliance programs (CMMC, FedRAMP, SCRM, NIST frameworks, ISO 27001 : 2022)
  • Manage monthly compliance reporting and KPI dashboards for executive leadership
  • Coordinate third-party compliance audits (NIST 800-171, CMMC, ISO 27001, FedRAMP) and remediation activities
  • Maintain compliance evidence catalogs and SaaS compliance implementation controls
  • Evaluate and implement security controls across software applications and cloud platforms AWS, Azure, and Office 365
  • Oversee Risk Management Framework (RMF) processes for government contract organizations as well as applications in the DoD space (ATO / IATT / IATO documentation)
  • Conduct weekly Plan of Action and Milestone (POA&M) reviews and monthly security assessments
  • Develop and maintain security policies, procedures, and technical standards
  • Lead vulnerability management programs & conduct security assessments and penetration testing coordination
  • Manage business continuity of operations (COOP) program including disaster recovery and crisis management plans
  • Lead incident response and security event investigation
  • Mentor and manage junior cybersecurity engineers and analysts
  • Interface with federal agencies, auditors, and compliance assessors
  • Work with system architects for security requirements on existing cloud workloads, cloud migrations and / or hybrid environments
  • Facilitate and oversee completion of all customers' cyber security questionnaires and qualifications with time-critical deadlines
  • Coordinate with HumRRO Contracts Division on written responses to RFPs regarding IT security, controls, data privacy and regulatory compliance
  • Assist with implementation and administration of cybersecurity supply chain risk management (C-SCRM) program
  • Develop compliance documentation and security narratives for proposals
  • Support business development with technical security expertise
  • Serve as subject matter expert on internal security controls and regulations

Minimum Requirements :

  • US Citizen with ability to obtain / maintain security clearance
  • Work on-site at Alexandria VA (Up to 2 remote days possible after probation period)
  • Bachelor's degree in Cybersecurity, Computer Science, or equivalent field. Work experience may be considered in lieu of degree
  • 7+ years of cybersecurity engineering and compliance experience
  • 5+ years of enterprise experience managing Risk and Compliance efforts including multiple regulatory and standard security frameworks
  • Existing Security+ certification or the ability to obtain within 6 months (CISSP, CCSP, or CISM preferred)
  • Deep expertise in NIST 800-171, 800-53, RMF, and DoD compliance frameworks
  • Hands-on experience with CMMC and FedRAMP authorization processes
  • Proficiency in Office 365 security configuration and management
  • Experience with vulnerability scanning tools (e.g. ACAS, Nessus, Rapid7, Qualys or equivalent)
  • Strong analytical and information gathering skills with ability to work multiple tasks simultaneously under short deadlines
  • Excellent communication skills for stakeholder engagement
  • Preferred :

  • Active DoD clearance
  • Experience in the nonprofit sector managing IT or related activities
  • CMMC Certified Professional (CCP) or CMMC Certified Assessor (CCA)
  • Experience with FedRAMP 3PAO assessments
  • Knowledge of Supply Chain Risk Management (SCRM) frameworks
  • AWS certifications (Solutions Architect, Security Specialty preferred)
  • Experience with DevSecOps pipeline integration and IAC
  • CISSP, CCSP, CISM, or CISSP-ISSAP certifications
  • Knowledge of DoD STIG implementation and automated compliance tools
  • Federal contracting and audit experience
  • Experience with Atlassian suite (Jira, Confluence)
  • Experience with eMASS package development and continuous monitoring activities
  • Experience with STIG implementation and SCAP compliance validation
  • Experience with bi-annual COOP testing and crisis management plan development
  • Leadership experience managing technical teams
  • People Management Experience is a plus
  • The anticipated salary for this role is $100,000 to $155,000. Specific salary offers are based on candidate qualifications and experience.

    Benefits :

  • Health, dental and vision insurance
  • Life insurance equal to 2x annual salary
  • Retirement plan with company matching
  • Paid professional development and certification maintenance
  • Tuition reimbursement
  • 12 weeks of paid parental leave
  • Generous paid time off and 10 paid holidays
  • All qualified applications will receive consideration without regard to race, color, religion, sex, national origin, age, marital status, sexual orientation, veteran status, medical condition, or disability. EEO / Vet / Disabled.

    Named one of "50 Great Places to Work" by Washingtonian magazine and one of "Top Workplaces" by The Washington Post.

    Create a job alert for this search

    Senior Cybersecurity Engineer • Alexandria, VA, USA

    Related jobs
    Cybersecurity Engineer

    Cybersecurity Engineer

    Barrow Wise ConsultingMD, USA
    Full-time
    Quick Apply
    Enjoy problem-solving, need a venue to display your creativity, and emerging technologies pique your interest; if so, Barrow Wise Consulting, LLC is for you. As a multi-disciplined leader, you under...Show moreLast updated: 30+ days ago
    • Promoted
    Cybersecurity Threat Response Engineer

    Cybersecurity Threat Response Engineer

    PremeraWashington, DC, United States
    Full-time
    Workforce Classification : • •Hybrid • •Join Our Team : Do Meaningful Work and Improve People’s Lives • •Our purpose, to improve customers’ lives by making healthcare work better, is far from ordinary.Work...Show moreLast updated: 13 days ago
    Cybersecurity Engineer

    Cybersecurity Engineer

    Interactive Process Technology LLCFort Belvoir, VA, USA
    Full-time
    Quick Apply
    IPTA's Technology Solutions Team is passionate about providing our customers with technical solutions that satisfy their business needs. Through collaborative interactions with customers, team membe...Show moreLast updated: 30+ days ago
    • Promoted
    Cyber Security Engineer

    Cyber Security Engineer

    ALTA IT ServicesSpringfield, VA, US
    Full-time
    Job Title : Cyber Security Engineer Location : Springfield, VA Type : Contract To Hire Compensation : Contractor Work Model : Onsite Hours : Add the job’s scheduled days and times (delete if not needed) ...Show moreLast updated: 29 days ago
    Cybersecurity Engineer

    Cybersecurity Engineer

    Diligent Consulting IncDC Metro, DC, US
    Full-time
    Quick Apply
    Security Engineer (Contingent Upon Award) Hiring Company : Diligent Consulting Inc.Government Publishing Office (GPO) Location : Washington, D. Hybrid / On-site) Remote : Must reside within commuting dis...Show moreLast updated: 30+ days ago
    Cybersecurity SME (TS / SCI w / FS Poly Req.)

    Cybersecurity SME (TS / SCI w / FS Poly Req.)

    August SchellHerndon, VA, US
    Full-time
    Quick Apply
    A TS / SCI with FULL SCOPE POLYGRAPH IS REQUIRED FOR THIS ROLE Who we are.August Schell offers 30 years of experience in providing our customers innovative solutions and engineering services to...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    Cybersecurity Architect / Engineer

    Cybersecurity Architect / Engineer

    LeidosGreat Falls, VA, US
    Full-time
    Join us in improving and shaping the future of smart mobility with a group of intelligent, motivated, and dedicated individuals! The Leidos Surface Transportation group focuses on improving transpo...Show moreLast updated: 4 hours ago
    Senior Cybersecurity Engineer

    Senior Cybersecurity Engineer

    RPI Group IncDahlgren, VA, US
    Full-time
    Quick Apply
    Dahlgren, VA Reports to : Contract Task Lead / Cybersecurity Lead Position Summary : RPI Group, Inc.Senior Cybersecurity Engineer for an opportunity to support our Navy customer at Dahlgren NSWC, VA....Show moreLast updated: 30+ days ago
    Cybersecurity Senior Analyst - Odenton, MD - Onsite

    Cybersecurity Senior Analyst - Odenton, MD - Onsite

    Gandiva InsightsMD, United States
    Full-time
    Quick Apply
    Title : Cybersecurity Senior Analyst Location : Odenton, MD Show moreLast updated: 4 days ago
    Cybersecurity Lead

    Cybersecurity Lead

    BTIQuantico, VA, US
    Full-time
    Quick Apply
    Business Technology Integrators (BTI), A Service -Disable Veteran Owned Small Business with over 25 years of experience delivering innovative IT Solutions to the Federal Government, is seeking a...Show moreLast updated: 12 days ago
    Cybersecurity Risk Management Analyst – Component Level

    Cybersecurity Risk Management Analyst – Component Level

    Evolver FederalSpringfield, VA, USA
    Full-time
    Quick Apply
    Cybersecurity Risk Management Analyst - Component Level.Federal client in Springfield, VA in managing all aspects of cybersecurity risk and compliance including, but not limited to developing and m...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    Senior Manager, Technology Change Risk Oversight

    Senior Manager, Technology Change Risk Oversight

    Capital OnePimmit, VA, US
    Full-time +1
    Senior Manager, Technology Change Risk Oversight Capital One is one of the fastest growing organizations in the world today, powered by our passion for our customers. We are serious about technology...Show moreLast updated: 22 hours ago
    Senior Trellix Cybersecurity Engineer / RMF ISSO – TS / SCI

    Senior Trellix Cybersecurity Engineer / RMF ISSO – TS / SCI

    ZTI Solutions, LLCFalls Church, Virginia, United States
    Full-time +1
    Quick Apply
    Senior Trellix Cybersecurity Engineer / RMF ISSO – TS / SCI.Active TS / SCI Clearance Required.Bachelor's Degree in Computer Science or related field. On-Site at Suffolk Building (no remote / hybrid optio...Show moreLast updated: 30+ days ago
    Cybersecurity Risk Management Analyst

    Cybersecurity Risk Management Analyst

    Evolver FederalSpringfield, VA, USA
    Full-time
    Quick Apply
    Cybersecurity Risk Management Analyst.Federal client in Springfield, VA in managing all aspects of cybersecurity risk and compliance including, but not limited to : maintaining an accurate FISMA Inv...Show moreLast updated: 30+ days ago
    • Promoted
    Forescout Cybersecurity Engineer

    Forescout Cybersecurity Engineer

    Phase2 TechnologyWashington, DC, United States
    Full-time +1
    On our expert team, you\'ll perform work focused on implementing and operating next generation security solutions for government and commercial clients. You\'ll perform hands-on evaluation, implemen...Show moreLast updated: 13 days ago
    • Promoted
    • New!
    Senior Manager, Risk Guide- Enterprise Services Risk

    Senior Manager, Risk Guide- Enterprise Services Risk

    Capital OneArnold, MD, US
    Full-time +1
    Senior Manager, Risk Guide- Enterprise Services Risk Senior Manager, Risk Guide- Enterprise Services Risk The Enterprise Services Risk organization is expanding with a focus on attracting innovativ...Show moreLast updated: 16 hours ago
    Cybersecurity Engineer II

    Cybersecurity Engineer II

    BAM Technologies, LLCArlington, VA, US
    Full-time
    Quick Apply
    Cybersecurity Engineer II BAM is a dynamic, multi-disciplinary firm with leading-edge skills in information technology, software development and applied research. Serving government and commercial m...Show moreLast updated: 16 days ago
    Cybersecurity Engineer (SOAR) [JOB ID 20250924]

    Cybersecurity Engineer (SOAR) [JOB ID 20250924]

    Phoenix CyberWashington, DC, US
    Full-time
    Quick Apply
    Phoenix Cyber is looking for Cybersecurity Engineers to join our client delivery team.This is a remote, work-from-home position with the possibility of minimal travel within the continent...Show moreLast updated: 10 days ago