CyberSecurity Engineer III
PMAT · San Diego, California, United States · $160K–$180K/yr
Software Development · 51-200 employees
About the role
The CyberSecurity Engineer III will design, deploy, and maintain secure infrastructure for Secret and Top Secret mission-critical environments. They will collaborate with cross-functional teams to remediate vulnerabilities, manage compliance, and support the accreditation lifecycle of government systems.
What they look for
Requirements
Candidates must have at least five years of experience in infrastructure or systems engineering and hold an active TS/SCI clearance. A bachelor's or master's degree in a STEM field is required, along with proficiency in virtualization, Linux/Windows administration, and security compliance frameworks.
Full description
At PMAT, we work on mission critical systems that directly support the warfighter, designing, building, and securing modern digital capabilities across cloud, data, and software environments. Our teams tackle complex, real-world challenges where delivery matters more than theory, and innovation is driven by curiosity, collaboration, and purpose.
In this role, you’ll contribute to secure infrastructure and cybersecurity capabilities supporting government and Intelligence Community mission environments, working alongside engineers and operators to deliver resilient, forward-leaning solutions in support of national defense.
About the role: PMAT is seeking a CyberSecurity Engineer III to support the design, deployment, security, administration, and sustainment of Secret and Top Secret mission-critical environments supporting government and Intelligence Community customers. In this role, you will work across on-premises cloud, virtualization, Linux and Windows systems, network infrastructure, automation, and compliance-driven security architectures. You will collaborate with infrastructure, cybersecurity, engineering, and mission stakeholders to maintain secure and reliable environments, resolve technical challenges, remediate vulnerabilities, and support systems throughout the development, accreditation, and operational lifecycle.
Responsibilities:
- Support the design and administration of secure Secret and Top Secret infrastructure stacks in on-premises and private cloud environments.
- Support the design and administration of large-scale VMware ESXi and vSAN virtualization platforms.
- Deploy, configure, administer, and maintain RHEL 6/7/8 and Windows Server 2019/2022 systems.
- Implement and remediate security controls in accordance with NIST SP 800-53 Revision 4 and Revision 5 requirements and DISA Security Technical Implementation Guides.
- Support the automation of system builds, patching, configuration, and hardening using Ansible, Jenkins, PDQ, WSUS, and related tools.
- Support vulnerability identification, tracking, and remediation efforts using ACAS, Nessus, Splunk, and other cybersecurity tools to reduce system attack surfaces.
- Support enterprise services and technologies, including Active Directory, databases, Veeam, Horizon, Atlassian Suite, YUM repositories, and monitoring platforms.
- Support the design and administration of LAN/WAN and virtualized network backbones, including troubleshooting complex routing issues involving OSPF and BGP.
- Collaborate across engineering, cybersecurity, program, and mission teams to troubleshoot issues and implement secure infrastructure solutions.
- Support accreditation efforts, including Authorization to Operate packages, compliance documentation, control validation, and security audits.
About Us: PMAT is an innovative small business founded with a passion for developing forward-leaning solutions from exceptional people that increase the mission's capability. We focus on designing and building impactful digital solutions that utilize modern cloud, data, and software concepts. Our passion is working on complex and progressive challenges such as edge platform computing, containerizing legacy platforms, distributed data platforms, or heterogeneous data analysis.
We recruit, retain, and foster a team motivated to pursue passions, investigate new ways of doing things, and embody an innovative and entrepreneurial spirit. We believe in being curious about every element of a problem and experiment relentlessly. We foster continuous learning in an environment that encourages positive collaboration and expands our capabilities. We tap into collective intelligence, acknowledging that the most brilliant people may not be in the room. Above all else, we believe that delivering and demonstrating is more potent than a sheet of paper. We are passionate about mission-centric design and delivering effective capabilities to and for the warfighter.
Whether you’re an experienced engineer or just beginning your career, you’ll work alongside experts who are committed to solving mission-critical problems. If you’re passionate about using your skills to make a real difference, apply today and become part of a team that’s shaping the future of defense technology!
Required Skills and Experience:
- Five or more years of experience in infrastructure engineering, systems administration, network engineering, or a closely related technical field.
- Experience administering VMware ESXi and vSAN virtualization environments.
- Experience deploying, configuring, administering, and maintaining RHEL and Windows Server environments.
- Experience supporting infrastructure automation using Ansible, Terraform, or related automation and Infrastructure as Code technologies.
- Experience implementing or remediating security controls in accordance with DISA STIGs and NIST SP 800-53 requirements.
- Strong understanding of on-premises cloud architectures, enterprise virtualization, and secure data center operations.
- Experience identifying, tracking, and remediating vulnerability backlogs in classified, regulated, or compliance-driven environments.
- Experience supporting Department of Defense, Intelligence Community, government mission systems, or similarly regulated environments.
- Ability to work effectively with infrastructure, networking, cybersecurity, software, and mission stakeholders in a classified environment.
Preferred Skills and Experience:
- Prior experience supporting the Intelligence Community or national-level organizations.
- Experience supporting LAN/WAN environments, routing, switching, OSPF, or BGP.
- Experience with ACAS, Splunk, Nessus, Veeam, Horizon, Dell Wyse, or related enterprise infrastructure technologies.
- Experience serving as a technical lead, mentoring junior engineers, or coordinating technical work across multiple teams.
- Familiarity with DevSecOps workflows and tools in classified or restricted environments.
- Experience supporting ATO packages, security control assessments, compliance documentation, or cybersecurity audits.
- Experience with Jenkins, PDQ, WSUS, Active Directory, Atlassian Suite, YUM repositories, databases, or enterprise monitoring platforms.
Education and Certification Requirements:
- Bachelor’s or master’s degree in a STEM field.
- CompTIA Security+ certification or obtain within 12 months from hire.
- CompTIA Network+ certification or obtain within 12 months from hire.
- ITIL Foundation certification.
- Additional DoD 8570 or DoD 8140 certifications are a plus.
Citizenship and Clearance requirements:
- US Citizenship required
- No dual citizenship
- Active TS w/ SCI eligibility and obtain maintain SCI
Location/Address:
- PMAT Office at Hancock Street, San Diego, CA
- Option for Flexible/Hybrid Schedule
Travel & Passport:
- Travel estimated at 10%
- CONUS travel for customer engagement, technical coordination, system support, or mission requirements
Work Environment: PMAT offices as needed. In some cases, work in a government facility may be required. Travel may be required for customer engagement, team coordination, and potentially for business development.
PMAT is an equal-opportunity employer. We believe in hiring a diverse workforce and sustaining an inclusive, people-first culture. We are committed to non-discrimination on any protected basis, such as disability and veteran status, or any other basis covered under applicable law.
#CJ