Senior Cybersecurity Engineer
Remote
Full Time
Experienced
Core R&D Responsibilities
- Translate DLA mission needs, cyber threats, operational constraints, and capability gaps into research questions, technical hypotheses, measurable requirements, and experimentation roadmaps.
- Conduct technical literature reviews, standards analysis, market research, and technology assessments to identify promising capabilities and avoid duplicative development.
- Design and execute repeatable experiments, proofs of concept, prototypes, pilots, and demonstrations with defined test variables, controls, datasets, metrics, acceptance criteria, and exit decisions.
- Develop secure reference architectures and prototypes for relevant areas such as Zero Trust, identity, AI/ML-enabled defense, digital twins, cyber analytics, automation, cloud, edge computing, supply-chain security, and OT/ICS protection.
- Build or integrate laboratory and test-range environments that safely emulate representative DLA enterprise, logistics, facility-related control system, cloud, or hybrid operating conditions.
- Assess technical feasibility, security effectiveness, interoperability, scalability, reliability, usability, performance, data quality, cost, and operational utility using objective evidence.
- Plan and conduct threat modeling, attack-path analysis, adversarial testing, fault injection, security control testing, and cyber-resilience evaluation appropriate to the system and research objective.
- Track technology readiness, research risks, assumptions, dependencies, technical debt, and maturation actions; recommend continue, pivot, transition, or terminate decisions.
- Prepare white papers, research plans, test plans, experiment reports, technical data packages, architecture products, briefings, and transition recommendations for technical and executive audiences.
- Protect Government purpose rights, sensitive research data, Controlled Unclassified Information, source code, models, and other technical artifacts in accordance with contract and DLA requirements.
Cybersecurity Engineering Responsibilities
- Apply systems security engineering and cyber-resilience principles throughout concept, design, development, integration, test, authorization, deployment, and sustainment activities.
- Develop and review security architectures, data flows, trust boundaries, interface controls, security requirements, engineering trade studies, and risk-based design decisions.
- Support the Risk Management Framework and evolving cyber-risk life-cycle processes, including categorization, control selection and tailoring, implementation guidance, assessment evidence, continuous monitoring, and authorization readiness.
- Produce or update system security plans, security assessment plans and reports, control-to-evidence matrices, risk assessments, plans of action and milestones, cybersecurity strategies, and eMASS-ready records.
- Engineer security for cloud, hybrid, DevSecOps, application, data, network, endpoint, identity, and operational technology environments while accounting for mission availability and safety constraints.
- Evaluate vulnerabilities and weaknesses using approved evidence sources and tools; determine exploitability, mission impact, compensating controls, remediation priorities, and residual risk.
- Incorporate secure software development, software supply-chain risk management, software bills of materials, code and dependency analysis, configuration baselines, and automated security testing where applicable.
- Develop OT/ICS/FRCS test approaches that favor passive discovery, read-only validation, digital-twin or lab replication, and approved maintenance-window testing when operational systems could be affected.
- Collaborate with authorizing officials, ISSMs, ISSEs, security control assessors, system owners, engineers, data scientists, operators, vendors, laboratories, and research partners while preserving required assessment independence.
- Provide senior technical advice during design reviews, test readiness reviews, technical interchange meetings, risk boards, demonstrations, and transition decisions.
Required Qualifications
- Bachelor's degree in cybersecurity, computer science, computer engineering, electrical engineering, systems engineering, software engineering, applied mathematics, data science, or a closely related technical field.
- Eight or more years of progressive cybersecurity, systems security engineering, cyber-resilience engineering, or secure technology development experience.
- At least three years of hands-on applied R&D experience involving experiments, prototypes, pilots, laboratories, test ranges, demonstrations, or technology-transition activities.
- Demonstrated ability to design controlled tests, establish quantitative and qualitative measures, analyze results, document limitations, and make evidence-based engineering recommendations.
- Experience securing and assessing complex systems across two or more domains such as enterprise IT, cloud, applications, networks, data platforms, AI/ML, OT/ICS/FRCS, embedded systems, or edge computing.
- Working knowledge of NIST SP 800-160 systems security engineering and cyber resiliency concepts, NIST SP 800-53 security controls, DoD RMF processes, and security authorization evidence.
- Experience producing technical documentation suitable for Government engineering reviews, risk decisions, authorization activities, and transition to operations.
- Ability to communicate complex technical findings clearly to engineers, program leadership, mission owners, and senior Government decision-makers.
- Ability to satisfy the applicable DoD 8140 cyberspace workforce qualification requirements for the assigned work role.
- Eligibility to obtain and maintain required DLA facility, network, system, and security access. U.S. citizenship may be required for clearance eligibility and task-order performance.
Preferred Qualifications
- Master's degree or doctorate in a relevant engineering, cybersecurity, computer science, or applied research discipline.
- Active Secret clearance or higher and prior experience supporting DLA, another Defense Agency, a Military Department, a federal laboratory, or a DoD research organization.
- Experience with technology readiness levels, systems engineering technical reviews, model-based systems engineering, digital engineering, test and evaluation, or transition planning.
- Experience with digital twins, AI/ML assurance, adversarial machine learning, Zero Trust, cyber deception, autonomous defense, threat emulation, or OT/ICS cybersecurity research.
Apply for this position
Required*