Booz Allen Hamilton logo
Booz Allen Hamilton

Booz Allen Hamilton is an award-winning provider of strategic innovation, management consulting, technology, and engineering services. Founded in 1914, the comp

Defensive Cybersecurity Engineer

Location

California

Posted

4 days ago

Salary

$69.3K - $158K / year

Seniority

Senior

Job Description

Defensive Cybersecurity Engineer

Booz Allen Hamilton

FMS Defensive Cybersecurity Engineer Location: San Diego United States Job Description: FMS Defensive Cybersecurity Engineer, Mid The Opportunity: Are you looking for an opportunity to advance your experience in cybersecurity that will support international Security Cooperation? As a Cybersecurity Engineer, you will deliver the technical foundation and operational expertise required to modernize allied defense. Your role is to bridge the gap between U.S. standards and partner capabilities by deploying interoperable security stacks and building the workforce skills necessary for independent and joint defense operations. You don't just deliver tools, you deliver the capability for our allies to fight and win in cyberspace. In this role, you'll closely impact international Security Cooperation with U.S. Allies and Partner by delivering modern Cybersecurity capabilities to meet global security requirements. With mentoring, challenging hands-on problem-solving, and opportunities to learn new tools and skills, we focus on growing as a team to make the best solutions for our customers. What you'll do Do: - Deploy Interoperable SOC Stacks, and lead the hands-on installation and tuning of SIEM, SOAR, and XDR solutions within partner environments. - Ensure these platforms are optimized for real-time data sharing and seamless integration with U.S. defensive frameworks. - Design and execute technical "train-the-trainer" programs. - Work side-by-side with partner nation engineers to transition advanced skills in threat hunting, incident response, and SOC management, aligned with the NICE Framework. - Architect log ingestion and data integration frameworks that normalize multi-source intelligence. By delivering these pipelines, you enable allies to contribute to a shared, high-fidelity Common Operational Picture (COP). - Build and manage cloud-based virtual cyber ranges and integrated Learning Management Systems (LMS). - Provide the "digital playgrounds" where partner forces can safely simulate adversarial TTPs and validate their tactical proficiency. - Execute the tactical rollout of Zero Trust controls, such as identity and micro-segmentation to enable secure collaboration. You deliver technical architecture that allows partners to access shared mission data without compromising national security. - Spearhead the technical delivery of cyber range solutions for emulated environments, and provide the range infrastructure and real-time technical mentorship that matures partner nation response capabilities under combat-speed conditions. - Technical Advisory for Procurement: Conduct deep-dive evaluations of cyber solutions to ensure partners acquire battle-ready, DoD-compatible technology that fits their specific operational requirements and workforce maturity level. Join us. The world can't wait. You Have: - 3+ years of experience in cybersecurity engineering, including deploying technical solutions in support of DoD or international security cooperation - Experience in configuring SIEM/XDR platforms and managing virtualized lab environments, such as VMware, AWS, or Azure - Ability to translate complex technical concepts into structured training and performance-based evaluations for broad audiences - Secret clearance - Bachelor's degree - Information Assurance Management (IAM), Information Assurance Technical (IAT), or Information Assurance System Architect and Engineer (IASAE) Level I DoD 8570.1M certification Nice If You Have: - Experience working with foreign military cyber units in OCONUS environments - Experience in Python or PowerShell to automate range deployments and data normalization for partner networks - TS/SCI clearance - CISSP, GCIH, or GCIA certification - Completion of specialized training in cyber range orchestration Clearance: Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; Secret clearance is required. Compensation At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen's benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page. Salary at Booz Allen is determined by various factors, including but not limited to location, the individual's particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $69,300.00 to $158,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen's total compensation package for employees. This posting will close within 90 days from the Posting Date. Identity Statement As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud. Candidate AI Usage Policy AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided. Work Model Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings. - Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility. - Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility. - Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role. Commitment to Non-Discrimination All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 10,001+H1B Sponsor

• Proactively monitors the work queues • Performs operational tasks to resolve all incidents/requests in a timely manner and within the agreed SLA • Updates tickets with resolution tasks performed • Identifies, investigates, analyses issues and errors prior to or when they occur, and logs all such incidents in a timely manner • Captures all required and relevant information for immediate resolution • Provides second level support to all incidents, requests and identifies the root cause of incidents and problems • Communicates with other teams and clients for extending support • Executes changes with clear identification of risks and mitigation plans to be captured into the change record • Follows the shift handover process highlighting any key tickets to be focused on along with a handover of upcoming critical tasks to be carried out in the next shift • Escalates all tickets to seek the right focus from CoE and other teams, if needed continue the escalations to management • Works with automation teams for effort optimization and automating routine tasks • Ability to work across various other resolver group (internal and external) like Service Provider, TAC, etc • Identifies problems and errors before they impact a client’s service • Provides Assistance to L1 Security Engineers for better initial triage or troubleshooting • Leads and manages all initial client escalation for operational issues • Contributes to the change management process by logging all change requests with complete details for standard and non-standard including patching and any other changes to Configuration Items • Ensures all changes are carried out with proper change approvals • Plans and executes approved maintenance activities • Audits and analyses incident and request tickets for quality and recommends improvements with updates to knowledge articles • Produces trend analysis reports for identifying tasks for automation, leading to a reduction in tickets and optimization of effort • May also contribute to / support on project work as and when required • May work on implementing and delivering disaster recovery functions and tests • Performs any other related task as required

Spain

Senior Information Security Engineer

ASRC Federal

ASRC Federal, a wholly owned subsidiary of Alaska’s largest Alaskan-owned and operated company, the Arctic Slope Regional Corporation (ASRC), is a leading pro

Role Description ASRC Federal Technology Solutions is seeking an Information System Security Officer (ISSO) to support cybersecurity governance, risk management, and compliance activities for systems within the Department of Justice – Office of Justice Programs (OJP). The ISSO will support the full RMF lifecycle for both on-premise and cloud-based systems and work closely with system owners, engineers, and the ISSM to maintain authorization and continuous monitoring posture. - Support execution of the NIST Risk Management Framework (RMF) across multiple DOJ-OJP systems, including on-premise and cloud-hosted environments - Maintain and update System Security Plans (SSPs), POA&Ms, BIAs, contingency plans, and supporting security documentation - Track, assess, and remediate vulnerability findings, including coordination with technical teams and validation of corrective actions - Support continuous monitoring activities, including review of security controls, account management, audit logs, and security impact assessments - Coordinate with system owners, engineers, and ISSMs to support ATO sustainment, audit response, and compliance reporting - Utilize GRC and security tools to document risk posture, including log analysis and vulnerability scanning outputs Qualifications - Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or a related field - 6+ years of experience supporting cybersecurity/IT-related functions - Hands-on experience with NIST SP 800-53, FISMA, and RMF documentation - Experience supporting DOJ or other federal civilian agencies strongly preferred - Ability to obtain and maintain a federal clearance suitable for DOJ systems Requirements - Certifications - such as CC/Sec+ - Graduate degree Benefits - Competitive pay and benefits packages - Health care, dental, vision, life insurance - 401(k) - Education assistance - Paid time off including PTO, holidays, and any other paid leave required by law EEO Statement ASRC Federal and its Subsidiaries are Equal Opportunity employers. All qualified applicants will receive consideration for employment without regard to race, gender, color, age, sexual orientation, gender identification, national origin, religion, marital status, ancestry, citizenship, disability, protected veteran status, or any other factor prohibited by applicable law.

United States

Principal Software Engineer (Security Engineering)

Identity Digital

Our Mission: Create a world where everyone has an authentic digital identity. Identity Digital is an internet infrastructure company that makes sure web addresses work seamlessly. If we do our job right, we are invisible to the user. We have the world’s largest portfolio of nearly 300 TLDs like .info, .pro, .world, which lets people and businesses build, market, and own their digital identities using meaningful words on both sides of the dot. In addition to TLDs, Identity Digital is a best-in-class registry service provider (RSP) that supports more than 28 million domains. This means that we help organizations maintain business continuity, reduce risk and avoid reputational challenges with state-of-the-art AI and ML capabilities. Moreover, Identity Digital is a leader in the domain industry, helping expand the number and variety of digital identities to its customers and users around the world in a secure, stable, and reliable manner. Our technology and business practices are built on sustainable practices, inclusive governance initiatives and environmentally friendly practices. Our mission is to evolve the future of authentic digital identities for forward-thinking businesses and people everywhere. Beyond our registry services, we help customers discover, register, support, and use high-quality domain names with name.com, an Identity Digital-owned registrar.

Full TimeRemoteTeam 240Since 2010

Summary / Objective Identity Digital Innovation Labs (IDIL) is building DNSid, the foundational identity layer for the agentic internet, enabling AI agents to establish verifiable, DNS-anchored identities. This principal-level software engineering role will build the platform, SDKs, and tooling that make DNSid real, while bringing deep, hands-on security expertise to every layer of the product and engineering organization. Security is not a feature of DNSid; it is the product, and this engineer will write and review production code, shape the cryptographic core, define the standards the team builds against, and own the security posture of the IDIL engineering org. This role reports to the VP, Engineering & Technical Architect. What You'll Do - Own the security architecture and threat model for the DNSid platform, SDKs, and supporting infrastructure (STRIDE analysis, attack surface review, trust boundaries) - Design and review the cryptographic core: signing, verification, key management, rotation, and revocation - Build and maintain the DNSid SDKs (TypeScript, Go, and Python) with security-first design and safe defaults - Define and enforce supply-chain security practices for the codebase and dependencies - Conduct security reviews of new features, integrations, and partner-facing implementations - Partner with the standards effort (IETF draft) so the security properties are sound and keep the implementation honest - Establish secure-by-default patterns for how third parties integrate DNSid (auth schemes, scope validation, token handling) - Own the security posture of the entire IDIL engineering org: secure deployment patterns, secrets management, audit readiness (SOC 2), and incident response - Actively models and promotes Identity Digital's core values through day-to-day interactions, behaviors, and decision-making - Other duties as assigned Who You Are / What You Bring Required Qualifications - 10+ years of hands-on software engineering, building and shipping production systems - Bachelor's degree in a relevant field or equivalent experience - Fluency in TypeScript and at least one of Go or Python; depth across the stack from SDK to infrastructure - Proven experience building and shipping production SDKs or security-critical libraries - Track record as a principal or lead engineer, setting technical direction while staying hands-on - Deep, non-negotiable security expertise: cryptographic primitives and protocols (Ed25519, JWT/JWKS, OAuth2/OIDC, PKI, TLS, signature schemes), threat modeling (STRIDE or equivalent), and translating threat models into concrete engineering work - Strong understanding of DNS and DNS security (DNSSEC, TXT records, resolution) and how DNS records can anchor cryptographic identity - Working familiarity with the agentic AI ecosystem (agent identity, MCP, A2A patterns) - Minimal travel expected; occasional on-sites as needed - Ability to work across time zones as part of a global organization as needed Preferred Qualifications - Experience contributing to or reviewing IETF/security standards drafts - Background in identity protocols (WebAuthn, DID, Verifiable Credentials) - Knowledge of supply-chain security risks and mitigations Physical Requirements - Prolonged periods of sitting at a desk and working on a computer - Must be able to lift up to 15 pounds at times Location: Remote This position is open to candidates residing in the following states only: AZ, CA, CO, DE, MD, MA, MO, NJ, NV, NY, NC, OR, OK, PA, SC, TX, UT, VA, and WA. Salary Range The U.S. base salary range for this full-time position is $210,000 - $275,000 (flexibility based on experience) plus benefits as described below. In addition, the successful candidate will be eligible to receive other compensation from time to time in the form of discretionary and/or nondiscretionary bonuses and long-term incentive plan. Actual compensation will be influenced by a candidate's qualifications, internal employee equity considerations, and location. We will not ask for information about a candidate's current or past compensation for purposes of developing an offer of employment. US team members (and their spouses, domestic partners, and/or dependent children) are covered by generously subsidized medical, dental, and vision insurance which includes company contributions to a Health Savings Accounts. Team members are also covered by company-paid life and disability insurance and have the option of participating in employee-paid supplemental life, accidental death and dismemberment, critical illness, and accident insurance. In addition, team members can enroll in the company's 401(k) plan with up to a 5% match. You receive 15 days of paid vacation yearly, increasing to 20 days after one year. Additionally, you get 5 days of paid sick leave, 13 paid holidays, and 20 weeks of paid parental leave for birthing parents, 12 weeks for others. Also, there's an opportunity for tuition reimbursement for qualifying expenses. Note: Benefits programs are subject to eligibility requirements and may vary in certain locations. A few things to know about us Identity Digital is an Equal Opportunity Employer and does not discriminate based on race, color, religion, sex, age, national origin, veteran status, marital status, sexual orientation, gender identity, disability or any other category prohibited by local, state or federal law. This policy applies to all aspects of employment, including recruitment, placement, promotion, transfer, demotion, compensation, benefits, social and recreational activities, and termination. Background Check Statement At the time of an offer, you will be required to complete a background check. Any offer is contingent upon a satisfactory background check. Sponsorship Statement Please note that work sponsorship for this position may not be available now or in the future. While we strive to support our candidates, not all roles will qualify. Eligibility will be reviewed on a case-by-case basis. Accommodation Statement We are committed to the full inclusion of all qualified individuals. As part of this commitment, Identity Digital will ensure that persons with disabilities are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, please contact our Recruiting Team at careers@identity.digital.

United States
$210K - $275K / year
ContractRemoteTeam 5,001-10,000H1B No Sponsor

• Act as the primary technical point of contact for the client, driving discussions, defining strategies, and recommending M365 and Security solutions. • Design, implement, and manage complex hybrid Exchange environments (On-Premises + Exchange Online), handling coexistence techniques and appliance requirements during migrations. • Lead SharePoint 2019/SE and SharePoint Online initiatives, with a deep focus on information architecture, taxonomy, content types, and modern search configurations. • Manage hybrid identity environments using Entra ID and Active Directory, alongside endpoint management via Microsoft Intune and Microsoft Teams deployment. • Design and enforce security policies using the Microsoft Defender Suite (Defender for Endpoint, Identity, and Office 365), Microsoft Purview, and advanced Conditional Access policies.

Portugal