Cybersecurity & Governance Engineer
5465
CALIBRE Systems, Inc., an employee-owned mission focused solutions and digital transformation company, is looking for a highly qualified Cybersecurity and Governance Engineer to support development of AI-enabled applications and reusable data products within customer’s existing environment. This position will be on-site, hybrid, or remote, at the discretion of the customer.
The role combines senior cybersecurity engineering, governance, risk, and compliance support with hands-on implementation of Federal security requirements. The individual will lead Risk Management Framework (RMF) and Authority to Operate (ATO) activities, strengthen security controls across cloud and enterprise environments, support continuous monitoring, and ensure systems, artifacts, and processes align with Federal customer expectations and approved governance frameworks.
This role requires expertise in Federal cybersecurity governance and all steps of NIST 800-53 RMF. Specifically, the candidate must have proven experience in FISMA, continuous monitoring, security assessment and authorization (ATO), control implementation and validation, vulnerability and configuration management, audit logging, cloud security, security documentation, POA&M management, and stakeholder coordination with Government cybersecurity personnel.
The selected candidate will work closely with Government system owners, ISSOs, ISSMs, authorizing officials, program offices, and delivery teams to ensure cybersecurity solutions, governance artifacts, and authorization packages meet Federal requirements, mission needs, security/privacy expectations, audit readiness standards, and production sustainment objectives.
Responsibilities include, but are not limited to:
• Federal Cybersecurity Governance and RMF Support
o Lead RMF lifecycle activities for Federal information systems, including categorization, control selection, implementation, assessment, authorization, and monitoring.
o Develop, review, and maintain authorization artifacts, including SSPs, SAR inputs, POA&Ms, control implementation statements, and supporting evidence.
o Map and validate NIST SP 800-53 controls against system architectures, security requirements, and Federal customer governance processes.
o Support FISMA reporting, audit readiness, control assessments, and preparation for security reviews with Government stakeholders.
o Advise program and technical teams on cybersecurity governance, compliance risk, and practical implementation of Federal security requirements.
• Security Engineering and Cloud Control Implementation
o Engineer and implement technical, operational, and management security controls across cloud, application, data, and enterprise environments.
o Support identity and access management, audit logging, vulnerability management, configuration baselines, encryption, and secure system design.
o Collaborate with cloud, DevSecOps, infrastructure, and application teams to embed security throughout the system lifecycle and deployment process.
o Evaluate security architectures, data flows, dependencies, and inherited controls to identify risks, gaps, and compensating-control options.
• Continuous Monitoring, Risk Management, and Delivery
o Implement and support continuous monitoring processes, security metrics, control-health reporting, and evidence collection.
o Track vulnerabilities, weaknesses, assessment findings, remediation activities, and POA&M status through closure.
o Support incident response readiness, security operations coordination, and review of audit logs and access control activity.
o Develop templates, standard operating procedures, user/admin guidance, knowledge-transfer materials, and transition artifacts.
o Support security authorization and ATO inputs, including SSP updates, assessment evidence, risk acceptance materials, and POA&M items.
· Creating cybersecurity documentation and authorization artifacts, including SSPs, SAR inputs, POA&Ms, control statements, assessment evidence, contingency plans, and RMF/ATO materials.
· Managing and complying with Federal cybersecurity requirements, including RMF, NIST SP 800-53/800-37, FISMA, ATO, control assessment, and audit readiness.
· Security control implementation, validation, and monitoring across all environments.
· Cloud security controls, including IAM, encryption, logging, vulnerability management, configuration baselines, and inherited controls.
· Full RMF lifecycle support, including categorization, implementation, and assessment
· Vulnerability management, remediation tracking, POA&M management, security metrics, evidence collection, and finding closure.
· Audit logging, access controls, security operations coordination, incident response readiness, and security activity review.
· Clear communication of cybersecurity risks, requirements, findings, and remediation plans to Government and technical stakeholders.
Desired Skills: (optional)
· Master’s Degree in Information Technology or related field
· DevSecOps practices, CI/CD security integration, infrastructure-as-code validation, container security, and SAST/DAST tools.
· Relevant certification such as CISSP, CISM, CISA, CRISC, CAP/CGRC, Security+, CCSP, AWS Security Specialty, or Azure Security Engineer.
· SOPs, security templates, control evidence guidance, user/admin documentation, knowledge-transfer materials, and transition artifacts.
Salary range will be from $125k-$145k
· Analytical, facilitation, and briefing skills to translate cybersecurity requirements into practical implementation guidance.
Washington, District of Columbia, United States
Full-Time/Regular
Equal employment opportunity, including veterans and individuals with disabilities.
PI286564269