Security Engineer - Continuous Diagnostics and Mitigation; CDM
Listed on 2026-01-09
-
IT/Tech
Cybersecurity, Systems Engineer, Information Security
Job Description
The Security Engineer - Continuous Diagnostics and Mitigation (CDM) is responsible for designing, implementing, integrating, and maintaining enterprise CDM capabilities to provide continuous visibility into cybersecurity risk, asset posture, and compliance. This role supports federal cybersecurity objectives by deploying and operating CDM tools and dashboards, integrating security data sources, and enabling real-time risk awareness across on‑premises and cloud environments. The Security Engineer works closely with cybersecurity operations, system owners, and compliance teams to improve situational awareness, support risk‑based decision‑making, and ensure alignment with federal cybersecurity standards and mandates.
Skillsand Requirements Requirements
Must be able to obtain a Public Trust
This position is primarily remote, but it requires the ability to attend occasional meetings in DC, MD, VA, WV, NJ, and OK as needed
Qualifications and ExperienceBachelor's degree in Computer Science, Cybersecurity, Engineering, Information Systems, Mathematics, Technology, or related IT field
6+ years of experience in cybersecurity engineering, security operations, or risk management roles.
Certifications- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Certified Information Systems Auditor (CISA)
- Certified Ethical Hacker (CEH)
- Certified Authorization Professional (CAP)
- CompTIA Security Or other equivalent IT or cybersecurity certifications
Demonstrated experience supporting or implementing CDM program capabilities within federal or regulated environments.
Technical Skills & CDM Expertise CDM Architecture & ToolsExperience implementing and operating CDM program tools, including capabilities across:
- Asset Management (HWAM, SWAM)
- Identity and Access Management (IdAM)
- Vulnerability Management
- Event Management
- Network and Data Protection
Experience integrating CDM components such as:
- Vulnerability scanners
- Endpoint security tools
- IAM solutions
- Network security tools
Experience supporting or integrating with CDM dashboards, data feeds, and agency or federal-level reporting.
Security Engineering & Operations Configuring and Tuning Security ControlsConfigure, manage, and tune security controls including:
Firewalls, IDS/IPS, endpoint protection, encryption, and network security controls.
Perform patch management and vulnerability remediation aligned with CIS Benchmarks, DISA STIGs, and SCAP.
Monitor security posture, vulnerabilities, and configuration compliance across enterprise environments.
Respond to security incidents, vulnerabilities, and emerging threats; support investigations and impact assessments.
Cloud & Zero Trust Security Cloud Environment SecurityExperience securing cloud environments (AWS, Azure, GCP) using:
- Zero Trust Architecture (ZTA) principles
- Cloud-native security controls, CSPM, CASB, and encryption
- Support implementation of IAM, PAM, and RBAC controls aligned with Zero Trust objectives
Assess, develop, and implement security policies and procedures aligned with:
- NIST RMF
- FISMA
- FedRAMP
- ISO 27001
- DoD STIGs
Conduct security risk assessments, control effectiveness reviews, and gap analyses.
Support preparation and maintenance of:
- System Security Plans (SSPs)
- Security Control Assessments (SCAs)
- Authorization to Operate (ATO) packages
- Plans of Action & Milestones (POA&Ms), including remediation tracking
Ensure compliance with federal regulations, industry standards, and organizational policies.
Support internal and external audits and certification activities.
Automation, Analysis & IntegrationDevelop scripts using Python, Power Shell, and/or Bash to automate security data collection, analysis, and reporting.
Integrate CDM tools and security platforms using APIs and automation frameworks (e.g., Ansible, Terraform, cloud‑native tools).
Analyze security data to assess risk impact and prioritize remediation efforts.
Analytical & Problem‑Solving SkillsApply standard and advanced analytical techniques to evaluate security control effectiveness in real‑world environments.
Analyze cyber threats,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).