Praescient Analytics logo
Praescient Analytics

Praescient Analytics is a Veteran-led, Woman-Owned Small Business (WOSB) engaging in Government contracts.

Cyber Security Specialist, Senior

Location

Virginia

Posted

9 days ago

Salary

0

Seniority

Senior

Job Description

Cyber Security Specialist, Senior

Praescient Analytics

Title: Cyber Security Specialist, Senior (Top Secret) Location: Fairfax (REMOTE), Virginia, United States Job Description: Location: Remote Clearance: Top Secret Employment Type: Full-Time About Praescient Analytics: Praescient Analytics is a leader in delivering advanced analytic, data engineering, and technology integration solutions in support of the Department of Defense (DoD), Intelligence Community, and federal law enforcement. Our mission is to empower analysts and decision-makers through data-driven insights, enabling faster and more effective mission outcomes. Position Overview: Praescient Analytics is seeking a Cyber Security Specialist to lead all cybersecurity and Risk Management Framework (RMF) activities for a contract with the Defense Counterintelligence and Security Agency (DCSA). You will ensure the application suite—hosted within a Government-provided AWS IL5 cloud environment—maintains its Authorization to Operate (ATO) and strictly complies with DoD cybersecurity policies. *U.S. Citizenship is Required* Key Responsibilities: - RMF & ATO Management: Lead the Authorization and Accreditation (A&A) process, creating and updating all required documentation to obtain and maintain a full ATO. - System Security Planning: Develop and maintain the System Security Plan (SSP) and ensure all security-related software and hardware configuration management is documented. - Vulnerability Remediation: Identify points of vulnerability or non-compliance and manage the Plan of Actions and Milestones (POA&M) to address relevant security controls. - eMASS Oversight: Manage and contribute to eMASS packages by collaborating with ISSOs and ISSMs to ensure continuous compliance. - STIG Compliance: Implement changes required to maintain compliance with Security Technical Implementation Guides (STIGs) and DoD policy. - Security Assessments: Conduct periodic technical security assessments of computing environments and perform regular reviews to ensure SSP compliance. - Incident Response: Report security-related incidents to the ISSM and initiate protective or corrective measures when vulnerabilities are discovered. - DevSecOps Integration: Ensure 100% of the codebase is free of High or Critical Static and Dynamic vulnerabilities prior to production pushes. Required Qualifications: - Clearance: Active Top Secret clearance with SCI eligibility. - Certification: Must hold an active CISSP or CISM certification. - Experience: 10+ years of experience in cybersecurity or information assurance. - Cloud Proficiency: Proven experience securing systems in cloud environments (AWS preferred). - Framework Knowledge: Deep expertise in NIST SP 800-53 and implementing RMF processes within DoD environments. - Technical Compliance: Experience with STIG implementation and automated security scanning. Desired Qualifications - Direct experience utilizing eMASS for DoD accreditation. - Expertise in DevSecOps security integration, specifically managing SAST/DAST vulnerabilities within an Agile Software Factory. - Hands-on experience with AWS security services (IAM, KMS, CloudTrail, GuardDuty). - Experience implementing security controls specifically within AWS IL5 / FedRAMP environments. - Familiarity securing the OPIS technical stack, including Java-based web applications, Oracle databases, and FileNet document management. - Knowledge of CMMC Level 2 self-assessment and independent assessment requirements. What you can expect from us: - Real opportunity for career growth in an environment where your achievements will be celebrated - Constant collaboration with numerous teams to ensure client success - A team that respects and embraces your ideas and expertise - Coworkers that are motivated by pursuing excellence, rather than the prospect of personal gain - A workplace dedicated to supporting and bettering public safety and government agencies Benefits: - Competitive salary based on qualifications and experience - Comprehensive, Company paid healthcare for you (We pay your premiums and deductibles) - 401(k) with company match - Travel & performance incentives - 3 weeks paid time off (plus Federal Holidays) - $5K annual training allowance - $500 book allowance - Tuition reimbursement program Praescient Analytics is a Certified Woman-Owned Small Business (WOSB) with over a decade of expertise in advanced analytics, engineering, and DevOps, specializing in transforming complex data into actionable intelligence for informed decision-making. Since 2011, we have supported over 40 organizations across diverse domains, including military intelligence operations, financial and fraud investigations, and insider threat detection. Our team of experts—skilled in cloud computing, artificial intelligence, machine learning, data science, DevOps, and engineering—brings deep experience in solving complex challenges. With a proven track record in federal contracting, we deliver tailored, high-impact solutions designed to enhance operational efficiency, ensure mission success, and address the evolving needs of our clients. Praescient's innovative and adaptive approach makes us a trusted partner in delivering data-driven insights and technological excellence for critical missions. Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. US Citizenship Required.

Related Categories

Related Job Pages

More Security Engineer Jobs

Mable logo

Security Engineer

Mable

Mable is an online platform enabling people to connect with care and support in their local community.

Full TimeRemoteTeam 201-500Since 2014H1B No Sponsor

• Design and implement security controls across Mable's platform, applications, and infrastructure - including access controls, encryption, network segmentation, and endpoint protection • Embed security into the software development lifecycle: participate in design reviews, threat modelling sessions, and code reviews to identify and address risks early • Lead vulnerability assessments and coordinate remediation efforts across engineering teams, prioritising based on risk and business impact • Monitor systems and infrastructure for suspicious activity; support incident response including investigation, containment, and post-incident analysis • Define and maintain security standards, guidelines, and sensible defaults for engineering teams - making the secure path the easy path • Partner with Engineering Team Leads and engineers to build security literacy across squads, providing advice and guidance on secure coding practices and tooling • Contribute to the assessment and adoption of security tooling - including SIEM, vulnerability scanning, secrets management, and intrusion detection • Support compliance and risk management obligations relevant to Mable's operating environment (e.g. Australian Privacy Act, ISO 27001 alignment, Essential Eight) • Monitor the external threat landscape and emerging attack vectors; translate findings into practical recommendations for the business • Collaborate with Infrastructure Engineers on secure cloud architecture, CI/CD pipeline security, and secrets management practices

Australia
Simbian Inc logo

Red Teamer

Simbian Inc

Simbian® is building an Agentic AI platform for cybersecurity. Founded by repeat successful security founders, we have gathered an excellent cohort of employees, partners, and customers. Our mission is to solve security using AI and our core values are excellence, replication, and intellectual honesty. Our promise is to make Simbian the best workplace of your career, and we believe a small group of thoughtful, passionate people can make all the positive differences in the world. Our AI Agents automate security operations and provide our customers with 10x leverage. Our customers include some of the world’s largest companies. Our initial use cases include: AI-based SOC alert triage and investigation AI-based Threat Hunting AI-based Penetration Testing

Full TimeRemoteTeam 51-200

Role Description We're building AI that does offensive security work. Not assists with it - actually does it. We're looking for a Red Teamer who brings deep, hands-on attack expertise and wants to turn that knowledge into AI-powered products. This is not a role where you run red team engagements. You are the expert who makes our AI agents think and act like skilled attackers - across whatever domain we're building in. What You'll Do - Be the offensive security brain behind our AI agents - defining how they reason, plan, and execute across attack scenarios. - Translate attacker methodology into structured workflows the AI can learn from and act on. - Cover the breadth of offensive security: network and web pentesting, phishing and social engineering, cloud and infrastructure attacks, adversary emulation, threat intelligence. - Validate product output against what a skilled human attacker would actually do - close the gap when the AI falls short. - Research emerging techniques across the offensive security landscape and get them into the product. - Work closely with engineering to improve agent accuracy, realism, and coverage. - Document attack logic, edge cases, and findings in ways that feed back into the product. Qualifications - 3-6 years in offensive security, red teaming, or penetration testing. - Strong offensive security background across multiple domains: web, network, cloud, social engineering, or adversary simulation. - Real-world experience: pentesting, bug bounty, red team engagements, CTFs, or security research. - Ability to break complex attack chains into structured, repeatable steps. - Someone who thinks in attacker TTPs, not just tools. - Curiosity about AI and genuine interest in building with it, not just using it. Requirements - Experience with LLMs, agentic systems, MITRE ATT&CK, or security automation (bonus). - Working knowledge of prompt injection, jailbreaking techniques, and OWASP Top 10 for LLMs (bonus). - CEH, OSCP, or equivalent - preferred, not required. Benefits - Work on a problem most security teams haven't even defined yet. - Direct impact on product - your findings shape what we build. - Remote-first, async-friendly culture. - Competitive comp + equity at an early-stage AI security company. - Work alongside people who've shipped security products.

India
CrowdStrike logo

Information Systems Security Officer

CrowdStrike

CrowdStrike has redefined security with the world’s most advanced cloud-native platform that protects and enables the people, processes and technologies that drive modern enterprise. Tested and proven, the world's largest organizations trust CrowdStrike to stop breaches with unparalleled protection against the most sophisticated cyberattacks. The CrowdStrike culture has been built upon our Core Values since the day we began. We are Fanatical About the Customer, Relentlessly Focused on Innovation and believe that our Limitless Passion drives Unlimited Potential for every CrowdStriker. As a purpose-built remote-first company, we believe cultivating a connected culture for every employee, no matter where they are in the world, is a key ingredient in building a high-performing, diverse team. We don’t have a mission statement. We’re on a mission—to stop breaches. Ready to join a mission that matters?

Full TimeRemoteTeam 5,001-10,000Since 2011H1B Sponsor

Role Description CrowdStrike seeks an exceptionally qualified Information Systems Security Officer (ISSO) to establish, maintain, and enhance the security and compliance of our Federal cloud environments. This critical role ensures business continuity with government clients by implementing stringent federal security requirements. The ideal candidate will focus on managing security controls to achieve and sustain Authorization to Operate (ATO) status across multiple federal systems. This position requires a security professional expert in navigating the entire compliance lifecycle, from continuous monitoring to external audits, while maintaining the highest security standards in a highly regulated environment. What You'll Do - AI-Powered GRC Automation & Engineering - Utilize deep proficiency in Python, JavaScript, C, or C++ to architect and implement advanced AI automation pipelines, optimizing critical GRC functions such as control assessments, POA&M management, and compliance reporting across federal authorization frameworks. - Leverage professional-level cloud architecture expertise and experience in FedRAMP and IL-5 environments to engineer secure, GRC automation tools within GovCloud and high-security boundaries. - Translate complex agency security requirements into automated solutions, employing LLM assistance for the rigorous drafting and versioning of SSPs and security narratives to meet evolving FedRAMP 20x mandates. - Operationalize AI compliance frameworks and correlate vulnerability intelligence with NIST SP 800-53 controls, providing real-time audit readiness metrics and accelerating the ATO lifecycle. - Design and deploy autonomous AI agents capable of executing multi-step GRC workflows — including control validation, evidence gathering, risk analysis, and remediation tracking — reducing manual compliance overhead and enabling continuous, intelligent oversight of federal security environments. - Continuous Monitoring (ConMon) & Remediation - Establish, automate, and maintain the Continuous Monitoring (ConMon) strategy from the System Security Plan (SSP), including scanning, assessment, reporting, and automated remediation of compliance checks and Plan of Action and Milestones (POA&M) activities. - Participate in the vulnerability intelligence on-call rotation for 24/7 expert analysis and rapid response. - Security Authorization & Risk Management - Manage the full Authorization to Operate (ATO) lifecycle, including preparing documentation for initial and continuous security authorizations and acting as the primary point of contact for external compliance. - Coordinate annual Third-Party Assessment Organization (3PAO) audits for successful outcomes. - Manage the POA&M process, perform risk-based security impact analyses, and track vulnerability remediation to verified closure. - Execute security control analyses, recommending infrastructure enhancements based on threat landscape changes. - Cloud Security Architecture - Serve as the expert authority on cloud security architecture, providing guidance and implementing defense-in-depth strategies for federal workloads across various cloud configurations (FedRAMP, DISA, agency requirements). - Develop and maintain cloud security architecture documentation (diagrams, data flows, controls). - Evaluate architectural changes for security impact and guide secure DevSecOps practices in federal clouds. - Change Control & SCR Management - Manage the Change Control Board (CCB) and Significant Change Request (SCR) process, providing authoritative security guidance, coordinating stakeholder reviews, and implementing automated workflows. - Perform quality assurance and support quarterly audits of SCRs. - Generate detailed security impact analyses for FedRAMP and DISA change requests. - Documentation & Governance - Maintain the System Security Plan (SSP) and all security authorization packages, ensuring all security artifacts are accurate and align with FedRAMP and EMASS templates. - Support governance activities, including policy development and system sponsorship. - Coordinate compliance matters with authorizing officials, acting as the primary security advocate. - Incident Response & Business Continuity - Serve as the primary security point-of-contact for incident response, managing resolution from initial detection through root cause analysis and implementing preventative measures. - Strategically coordinate and lead incident response, business continuity, and disaster recovery exercises. - Audit & Access Management - Manage annual security audit evidence collection and coordination. - Rigorously audit account management, enforce least privilege through monthly access reviews, and oversee DISA whitelisting requests. - Process system deviation requests, including risk assessments and determination of compensating controls. Qualifications - Bachelor's degree (or equivalent experience) in a relevant technical field (Engineering, Computer Science, Cybersecurity, IT); advanced degree preferred. - Proven experience utilizing AI technologies to enhance decision-making, streamline workflows and processes, improve efficiency and drive business outcomes. - Must hold a DoD 8140/8570 IAM Level II Baseline Certification (CGRC, CASP+, CISM, CISSP/Associate, or CCISO). - U.S. Citizenship and residency required for work on sensitive government systems. - Expert knowledge of NIST SP 800-53, RMF, FedRAMP, and FISMA, with significant hands-on experience implementing and assessing controls in cloud environments (e.g., AWS GovCloud). - Proven success managing 3PAO audits and maintaining a sophisticated Continuous Monitoring (ConMon) program in federal settings. - Advanced technical familiarity with modern cloud infrastructure and security tools (e.g., SIEM, Endpoint Security, CI/CD, vulnerability management). - Exceptional analytical, communication, and documentation skills essential for a highly regulated environment. - Experience performing comprehensive cyber architecture reviews, identifying weaknesses, and recommending improvements. Bonus Points - Current professional-level AWS Certification (e.g., Solutions Architect, Security Specialist). - Proficiency in Python, JavaScript, C, or C++ for developing security automation. - Proven liaison experience with government customers regarding their security requirements. - Experience with FedRAMP or Agency authorization processes and package preparation. - Experience with CMMC, IRAP, TxRAMP, GovRAMP processes and package preparation. Benefits - Market leader in compensation and equity awards. - Comprehensive physical and mental wellness programs. - Competitive vacation and holidays for recharge. - Paid parental and adoption leaves. - Professional development opportunities for all employees regardless of level or role. - Employee Networks, geographic neighborhood groups, and volunteer opportunities to build connections. - Vibrant office culture with world class amenities. - Great Place to Work Certified™ across the globe.

United States
$125K - $180K / year
CACI International Inc logo

Cybersecurity Engineer

CACI International Inc

Expertise and Technology for National Security

Full TimeRemoteTeam 10,001+Since 1962H1B No Sponsor

Role Description CACI's Enterprise Network Services (ENS) Division supports the Department of Defense (DoD) in modernizing mission-critical communications and enterprise network infrastructures. We are seeking a motivated Cybersecurity Engineer with approximately two years of professional experience to support the deployment, integration, and sustainment of cybersecurity solutions across customer environments. This is a remote position that requires frequent travel (up to 50%) to customer sites within the U.S. (CONUS) and internationally (OCONUS). - Configure, deploy, integrate, and maintain cybersecurity solutions based on customer requirements, security policies, and performance specifications. - Perform Security Technical Implementation Guide (STIG) compliance validation and remediation activities across network and system components. - Execute vulnerability assessments using industry-standard scanning tools and assist in identifying, analyzing, and mitigating security vulnerabilities. - Support Risk Management Framework (RMF) activities and maintain compliance with DoD cybersecurity requirements. - Assist with system security hardening, configuration management, and secure baseline implementation. - Collaborate with government personnel, vendors, and subcontractors to integrate security solutions into existing enterprise infrastructures. - Troubleshoot and resolve cybersecurity and network security issues while documenting findings and recommended corrective actions. - Communicate technical security concepts, risks, and remediation plans effectively to both technical and non-technical stakeholders. - Develop and deliver technical presentations, demonstrations, and customer briefings. - Create and maintain technical documentation, implementation guides, security procedures, and system diagrams. - Support system integration, testing, and cybersecurity validation efforts during deployments. - Serve as a technical resource during customer meetings, engineering reviews, and operational support activities. - Travel up to 50% to CONUS and OCONUS customer locations to support installation, integration, troubleshooting, and sustainment activities. - Ensure compliance with CACI Environmental Health & Safety (EH&S), ethics, and corporate compliance policies. - Perform additional duties as assigned. Qualifications - Active DoD Secret security clearance with the ability to maintain clearance. - Approximately 2+ years of experience supporting cybersecurity, information assurance, or network security initiatives. - DoD 8570/8140 IAT Level II certification (Security+ CE or equivalent), or the ability to obtain certification within a specified timeframe. - Experience performing STIG implementation, validation, and remediation. - Experience conducting vulnerability scans using tools such as ACAS/Tenable Nessus or equivalent vulnerability management platforms. - Working knowledge of the DoD Risk Management Framework (RMF) and cybersecurity compliance requirements. - Understanding of secure network architecture, system hardening, and cybersecurity best practices. - Familiarity with Windows and Linux operating systems in enterprise environments. - Knowledge of TCP/IP networking fundamentals and common network security technologies. - Strong analytical and troubleshooting skills with the ability to identify and resolve technical issues. - Excellent written, verbal, interpersonal, and presentation skills. - Ability to work independently and collaboratively within cross-functional engineering teams. Requirements - Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or a related technical discipline. - Experience supporting DoD programs or other federal government environments. - Experience with the DoD Enterprise Mission Assurance Support Service (eMASS). - Familiarity with Commercial Solutions for Classified (CSfC) architectures and deployments. - Knowledge of Software Defined Networking (SDN) technologies. - Experience with endpoint security, firewalls, VPNs, identity and access management, or network security appliances. - Industry networking certifications such as CCNA, CCNP, JNCIA, or JNCIP. - Experience using Microsoft Visio, AutoCAD, or similar tools to develop network and security diagrams. - Familiarity with scripting languages such as PowerShell, Python, or Bash to automate administrative or security tasks. Benefits - Comprehensive benefits such as healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits. - Competitive compensation and learning and development opportunities. - Flexibility that allows employees to balance quality work and personal lives. Company Description CACI is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, age, national origin, disability, status as a protected veteran, or any other protected characteristic.

United States
$63.3K - $129.7K / year