Pioneering Evolution LLC

Cybersecurity Engineer

Pioneering Evolution LLC Arlington, Virginia, United States · $100K–$153K/yr

Software Development · 51-200 employees

6 h ago
security Senior (5-10 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Cybersecurity Engineer will manage the Authority to Operate (ATO) lifecycle and ensure continuous compliance with NIST SP 800-171 and CMMC Level 2 standards. This role involves hands-on implementation of security controls, collaboration with engineering teams, and maintaining system security documentation for DoD financial systems.

What they look for

Cybersecurity NIST SP 800-171 CMMC Level 2 ATO lifecycle management Risk Management Framework Cloud security Azure Government Linux administration Identity and access management Network security Vulnerability management Infrastructure as Code Bash PowerShell Python Zero Trust

Requirements

Candidates must have at least 5 years of professional experience in cybersecurity and a bachelor's degree in a technical discipline. Proficiency in cloud security, Linux administration, and scripting, along with relevant certifications like Security+, CISSP, or CGRC, is required.

Benefits

Paid time off Paid holidays Medical insurance Dental insurance Vision insurance Legal assistance Life insurance AD&D insurance Long-term disability insurance Short-term disability insurance Tuition reimbursement 401(k) plan Continuing education opportunities

Full description

POSITION DESCRIPTION:

Pioneering Evolution is seeking a Cybersecurity Engineer to support the security and compliance posture of SyncPoint — a DoD financial system of record operating in a Department of Defense Impact Level 4 (IL4) environment. This role is responsible for supporting the pursuit and maintenance of an Authority to Operate (ATO), implementing and validating NIST SP 800-171 and CMMC Level 2 controls, and serving as the technical security authority for the program.

This is an oversight and hands-on implementation role. The Cybersecurity Engineer will maintain the System Security Plan (SSP) and supporting compliance documentation, conduct gap assessments, implement technical controls, and work directly with developers, DevOps engineers, infrastructure teams, and program leadership to integrate security into system design and day-to-day operations, maintaining a continuously audit-ready NIST SP 800-171 and CMMC Level 2 compliance posture. The ability to work across compliance frameworks, cloud infrastructure, and software development workflows — rather than relying solely on automated scanning tools — is essential to this position.

Key Responsibilities:

ATO Lifecycle Management

  • Support the ATO lifecycle for SyncPoint, including contributing to and maintaining the System Security Plan (SSP), security assessment documentation, and Plan of Action and Milestones (POA&M) in coordination with the Director of Technology, Platforms, and Implementation.
  • Maintain continuous ATO posture through proactive control monitoring, evidence collection, and timely remediation of findings.
  • Serve as the technical point of contact for security assessors, authorizing officials, and compliance stakeholders throughout the ATO lifecycle.
  • Coordinate security review and assessment activities across engineering, operations, and leadership teams.

NIST SP 800-171 and CMMC Level 2 Compliance

  • Interpret and apply NIST SP 800-171 security requirements, translating them into specific technical and administrative controls implemented within the SyncPoint environment.
  • Conduct security and compliance gap assessments, document deficiencies, develop remediation plans, and validate that controls have been appropriately implemented.
  • Maintain and update the SSP, control implementation statements, policies, procedures, and supporting evidence artifacts on behalf of the Director of Technology, Platforms, and Implementation.
  • Coordinate with the organization’s Managed Service Provider (MSP) to validate MSP-implemented controls, define the organizational/project boundary, and ensure control coverage is accurate and complete within the ATO boundary.
  • Monitor DoD CMMC and NIST SP 800-171 program requirements and maintain the program’s ongoing compliance and assessment readiness.

Technical Security Implementation

  • Implement and validate security controls across Linux and cloud infrastructure, including system hardening, configuration management, patching, and logging.
  • Configure and maintain identity and access management (IAM) controls including RBAC, least-privilege access, privileged access management, and service identities across Azure and application tiers.
  • Implement and validate network segmentation, firewall rules, private connectivity, VPN configurations, and network access controls appropriate for IL4 environments.
  • Deploy and manage security monitoring, logging, alerting, and audit trail capabilities; investigate and respond to security findings and incidents.
  • Support vulnerability management processes including scan configuration, finding triage, risk acceptance, and remediation tracking.

Cloud and Infrastructure Security

  • Implement and validate cloud security controls within Microsoft Azure Government (and/or AWS GovCloud), including storage encryption, identity management, network security groups, private endpoints, and security posture management.
  • Review and contribute to Infrastructure as Code (IaC) using Bicep or Terraform to ensure secure-by-default infrastructure provisioning.
  • Support DevSecOps practices including repository security, secrets management, branch protections, and secure CI/CD pipeline configuration.
  • Apply Managed Identity, RBAC/ABAC, and Zero Trust principles across cloud-hosted workloads and services.

CUI Protection

  • Implement and oversee secure handling, storage, transmission, and disposal of Controlled Unclassified Information (CUI) across all SyncPoint environments and processes.
  • Ensure development and operational workflows do not expose CUI through logs, development tools, AI services, or unauthorized environments.
  • Support data classification, labeling, and access-control requirements consistent with CUI handling requirements.

Security Engineering Collaboration

  • Work directly with software developers, infrastructure engineers, and the DevOps team to integrate security requirements into application design, infrastructure provisioning, and deployment processes.
  • Provide actionable security requirements and guidance that engineers can implement — not just compliance checklist items.
  • Use scripting and command-line tools (Bash, PowerShell, Python, Azure CLI) for administration, evidence collection, and automated compliance checks.
  • Investigate and interpret logs, system configurations, vulnerability reports, and security findings; communicate risk clearly to leadership.

Technical Environment: Compliance: NIST SP 800-171, CMMC Level 2, RMF, ATO, CUI Cloud: Microsoft Azure Government, AWS GovCloud IAM: Azure AD / Entra ID, RBAC, ABAC, Managed Identity, PAM Infrastructure: Linux, Windows Server, Network Segmentation, VPN, Firewalls IaC: Bicep, Terraform Monitoring/SIEM: Microsoft Defender for Cloud, Microsoft Sentinel, Azure Monitor CI/CD Security: Azure DevOps, Git, secrets management, branch protections Scripting: Bash, PowerShell, Python, Azure CLI, AWS CLI Documentation: SSP, POA&M, policies, procedures, control implementation statements

Key Competencies

  • ATO lifecycle support and RMF process expertise
  • NIST SP 800-171 and CMMC Level 2 depth — both compliance and technical implementation
  • Hands-on security engineering across cloud, Linux, and application tiers
  • CUI handling and DoD data protection requirements
  • Clear, credible communication of risk and compliance status to leadership
  • Practical problem-solving orientation — builds solutions, not just findings reports
  • Effective cross-functional collaboration with engineering, DevOps, MSP partners, and program leadership

REQUIRED EXPERIENCE:

  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or a related technical discipline, or equivalent professional experience.
  • 5+ years of professional experience in cybersecurity, information assurance, or a closely related field.
  • Demonstrated hands-on experience implementing and assessing NIST SP 800-171 controls; familiarity with CMMC Level 2 requirements and assessment processes.
  • Strong working knowledge of fundamental security principles: least privilege, Zero Trust, defense in depth, IAM, encryption, network segmentation, vulnerability management, and system hardening.
  • Proficiency with Linux system administration including command-line tools, permissions, services, logging, patching, and OS-level security hardening.
  • Strong networking fundamentals: IP addressing, subnetting, routing, firewalls, VPN/private connectivity, and network access controls.
  • Working knowledge of cloud security within Microsoft Azure and/or AWS, including IAM, network security, storage encryption, logging, monitoring, and security posture management.
  • Ability to produce and maintain SSPs, control implementation statements, POA&Ms, policies, procedures, and compliance evidence packages.
  • Scripting proficiency in at least one of: Bash, PowerShell, Python, Azure CLI.
  • Strong written and verbal communication skills; ability to explain technical security risk to leadership and translate compliance requirements into engineering tasks.
  • Demonstrated ability to independently investigate technical security problems and develop practical solutions.

Required Certifications (One or More):

The following certifications are required, reflecting the ATO oversight responsibility and the DoD operating environment:

  • CompTIA Security+ (DoD 8570/8140 IAT Level II baseline — minimum acceptable; required if no higher certification held)
  • CISSP (Certified Information Systems Security Professional) — strongly preferred for candidates leading an ATO program
  • CISM (Certified Information Security Manager) — acceptable alternative to CISSP for candidates with a compliance/governance focus
  • CAP / CGRC (Certified Authorization Professional / Governance, Risk, and Compliance) — directly applicable to ATO and RMF activities; highly valued
  • Microsoft Certified: Cloud and AI Security Engineer Associate (SC-500) — required or expected to be obtained within 6 months of hire given the Azure Government operating environment

Note: Candidates holding CISSP + CAP/CGRC or CISSP + SC-500 represent the strongest certification profile for this role. Candidates who hold a legacy AZ-500 certification (earned prior to its August 31, 2026 retirement) remain qualified, as the certification stays valid on their transcript until its individual renewal date.

DESIRED EXPERIENCE:

  • Active experience working within DoD RMF (Risk Management Framework) processes, including ATO package preparation and assessment coordination.
  • Demonstrated experience obtaining or maintaining an ATO for a DoD system.
  • Experience with DoD IL4 or IL5 environments.
  • Familiarity with DISA STIGs, SCAP tooling, and automated compliance scanning.
  • Experience with Infrastructure as Code security review (Bicep, Terraform).
  • Experience configuring and reviewing Azure Policy, Microsoft Defender for Cloud, Microsoft Sentinel, or equivalent security posture tools.
  • Familiarity with PIEE, Navy ERP, or DoD financial system environments.
  • CASP+ (CompTIA Advanced Security Practitioner) — DoD 8570 IAT Level III; valued for technical depth.
  • CCSP (Certified Cloud Security Professional) — valued for cloud-native security expertise.

WHO WE ARE AND WHAT WE OFFER:

In addition to competitive salaries and opportunities for professional development and advancement, our employees enjoy a comprehensive range of benefits. To keep pace with the changing needs of our employees, we continually evaluate our benefit plans.

  • Paid time off
  • 10 paid holidays
  • Medical insurance
  • Dental insurance
  • Vision insurance
  • Legal assistance
  • Company-paid life insurance and AD&D
  • Company-paid long-term and short-term disability insurance
  • Tuition reimbursement
  • 401(k) plan with company contribution
  • Continuing Education Opportunities

Similar roles