Mission Critical Cyber Security/Isso Opportunity - Ts/Sci W/ Poly Required

Leading Path Consulting

  • Warrenton, VA
  • 3 days ago

    Highlights

    Leading Path is an award-winning Information Technology and Management Consulting firm focused on providing solutions in process, technology, and operations to our government and Fortune 500 clients. Networking (e.g., routing, switching, firewalls, load balancers, network security controls).

    Numbers & Facts

    LocationWarrenton, VA

    Description

    We are seeking a hands-on Cyber Security Engineer at the Subject Matter Expert (SME) level

    to lead and execute security engineering activities across complex, enterprise-scale

    environments. This role requires deep technical expertise across infrastructure, platforms, and

    applications, combined with expert-level, hands-on experience implementing the NIST Risk

    Management Framework (RMF) within federal government environments. The ideal candidate is

    a technical practitioner, not just an advisor-someone who can design, implement, assess, and

    secure systems end-to-ed while directly supporting system authorization, continuous monitoring,

    and risk-based decision-making. This role also serves as the technical focal point for all security

    incidents, leading triage, investigation, and resolution efforts in coordination with program and

    enterprise security teams. 

    QUALIFICATIONS

    Bachelor’s degree in Cybersecurity, IT, or other related technical discipline; or the equivalent

    combination of education, technical training, or work/military experience

    Minimum ten (10) years applied experience or relevant degree plus five (5) years of

    Cybersecurity expertise with demonstrated ability to successfully shepherd IT projects of

    varying types through the authorization lifecycle

    REQUIRED KNOWLEDGE/SKILLS

    Candidate must demonstrate hands-on experience in all the following areas:

        Security & Compliance

    Expert-level experience with NIST Risk Management Framework (RMF) in federal

    government environments.

    Strong knowledge of:

    o NIST SP 800-53

    o NIST SP 800-37

    o NIST SP 800-30

    Direct involvement in ATO packages, control implementation, and assessments.

    Hands-on experience with Security Information and Event Management (SIEM)

    platforms (e.g., Splunk, ELK Stack, ArcSight, Qradar).

    Demonstrated experience in security incident detection, analysis, and response.

    Proven ability to triage security alerts and determine criticality and impact.

    Infrastructure & Platforms (Hands-On)

    Networking (e.g., routing, switching, firewalls, load balancers, network security controls)

    Operating Systems:

    o Windows Server

    o Linux (RHEL, CentOS)

    Virtualization and storage platforms

    Databases (SQL and/or NoSQL)

    Data Platforms (e.g., HPCC, Hadoop/Cloudera)

    Web services, APIs, and application architectures

    Software development environments and CI/CD pipelines

    Security tooling (e.g., vulnerability scanners, endpoint protection, SIEM)

    Engineering Experience

    Security engineering and system hardening

    Vulnerability discovery and remediation

    Secure system design and architecture reviews

    Technical documentation supporting RMF compliance

    Experience in cloud environments (AWS, Azure, GCP, CI) within federal RMF contexts

    Experience with DevSecOps practices

    DESIRED SKILLS

    Hands-on experience with containerization and orchestration (Docker, Kubernetes)

    Hands-on experience with infrastructure-as-code

    Knowledge of federal overlays (e.g., DoD, FISMA High/Moderate)

    Relevant certifications (preferred, not required):

    o CISSP

    o CAP

    o CISM

    o Security+

    o Cloud Security

    o Certified Ethical Hacker

    Experience with guiding and directing junior engineers and information systems security

    officer (ISSO)

    Experience with security orchestration, automation, and response (SOAR) platforms

    Background in threat hunting and proactive security monitoring

    Relevant incident response certifications

    Ideal Candidate Profile 

    Proven hands-on Cyber Security Engineer SME, not policy-only or audit-only

    Comfortable working across network, system, platform, and application layers

    Deep understanding of how security controls are actually implemented and validated

    Experience in federal RMF-driven environments

    Able to bridge security, engineering, and compliance effectively

    Experienced in managing security incidents from detection through resolution

    Skilled at balancing immediate incident response needs with long-term security

    improvements

    Effective collaborator across organizational boundaries during high-pressure security

    events

    KEY RESPONSIBILITIES

    Serve as the Cyber Security Engineer SME, providing hands-on security engineering

    across all system layers (infrastructure, platform, and application).

    Engineer, implement, and validate security controls in accordance with NIST SP 800-53

    and RMF requirements.

    Lead and support RMF lifecycle activities (Categorize, Select, Implement, Assess,

    Authorize, Monitor).

    Perform security engineering for:

    o Network architectures and boundary protections

    o Windows and Linux operation systems

    o Storage and virtualization platforms

    o Databases and data platforms

    o Web services, APIs, and application stacks

    o Custom and COTS/GOTS software solutions

    Provide technical input to RMF artifacts, including:

    o System Security Plans (SSP)

    o Security Control Assessments (SCA) support

    o POA&Ms

    o Risk assessments and security impact analyses

    Collaborate with system owners, architects, developers, and operations teams to embed

    security into system design and implementation.

    Support ATO, re-authorization, and continuous monitoring activities.

    Identify security risks and provide practical, technically sound mitigation strategies.

    Participate in security reviews, technical design reviews, and vulnerability remediation

    efforts.

    Serve as technical point of contact for all security incidents affecting the program.

    Lead triage and analysis of new security alerts from SIEM, IDS/IPS, and other security

    monitoring tools.

    Drive remediation efforts for recurring security alerts, identifying root causes and

    implementing systemic fixes.

    Coordinate incident response activities between program stakeholders and enterprise

    security operations.

    Act as primary liaison between program teams and enterprise security for incident

    escalation, resolution, and reporting.

    Perform forensic analysis and technical investigations of security events.

    Document security incidents, response actions, and lessons learned.

    Develop and maintain runbooks and playbooks for common security incident types.

    Expectation (SME-Leve Role):

    Operate independently as the technical authority for system security engineering.

    Demonstrate the ability to provide technical hands-on configuration, validation, an

    assessment of security controls.

    Translate RMF and NIST requirements into real-world technical implementations.

    Communicate complex technical security issues clearly to both technical and non-

    technical stakeholders.

    Maintain a strong balance between security compliance and operational practicality.

    Lead rapid response to security incidents with minimal guidance.

    Demonstrate strong analytical and troubleshooting skills under pressure during active

    security events.

    Effectively communicate incident status, impact, and remediation progress to technical

    and leadership audiences.

    Requirements

    QUALIFICATIONS

    Bachelor’s degree in Cybersecurity, IT, or other related technical discipline; or the equivalent

    combination of education, technical training, or work/military experience

    Minimum ten (10) years applied experience or relevant degree plus five (5) years of

    Cybersecurity expertise with demonstrated ability to successfully shepherd IT projects of

    varying types through the authorization lifecycle

    REQUIRED KNOWLEDGE/SKILLS

    Candidate must demonstrate hands-on experience in all the following areas:

    Security & Compliance

    Expert-level experience with NIST Risk Management Framework (RMF) in federal

    government environments.

    Strong knowledge of:

    o NIST SP 800-53

    o NIST SP 800-37

    o NIST SP 800-30

    Direct involvement in ATO packages, control implementation, and assessments.

    Hands-on experience with Security Information and Event Management (SIEM)

    platforms (e.g., Splunk, ELK Stack, ArcSight, Qradar).

    Demonstrated experience in security incident detection, analysis, and response.

    Proven ability to triage security alerts and determine criticality and impact.

    Infrastructure & Platforms (Hands-On)

    Networking (e.g., routing, switching, firewalls, load balancers, network security controls)

    Operating Systems:

    o Windows Server

    o Linux (RHEL, CentOS)

    Virtualization and storage platforms

    Databases (SQL and/or NoSQL)

    Data Platforms (e.g., HPCC, Hadoop/Cloudera)

    Web services, APIs, and application architectures

    Software development environments and CI/CD pipelines

    Security tooling (e.g., vulnerability scanners, endpoint protection, SIEM)

    Engineering Experience

    Security engineering and system hardening

    Vulnerability discovery and remediation

    Secure system design and architecture reviews

    Technical documentation supporting RMF compliance

    Experience in cloud environments (AWS, Azure, GCP, CI) within federal RMF contexts

    Experience with DevSecOps practices

    Benefits

    Leading Path is an award-winning Information Technology and Management Consulting firm focused on providing solutions in process, technology, and operations to our government and Fortune 500 clients. We offer a professional and family friendly work environment with a strong work-life balance. Leading Path provides a comprehensive and competitive benefits package including fully paid medical/dental/vision premiums, generous PTO, 11 Paid Holidays, 6% 401K contribution, annual training and tuition reimbursement, SPOT Award bonuses, regular team events, opportunities for professional growth and advancement and much more!

    Similar Jobs

    See more jobs