SonicJobs Logo
Left arrow iconBack to search

Senior Cybersecurity Integration Engineer

BaseCamp Consulting & Solutions
Posted a day ago, valid for 12 days
Location

Chapel Acres, VA, US

Salary

$125,000 - $135,000 per year

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • The Senior Cybersecurity Integration Engineer position focuses on securing and integrating the Customer's enterprise API gateway while maintaining compliance with the Risk Management Framework.
  • Candidates must have a Bachelor's degree in Engineering, Computer Science, Cybersecurity, or a related field, along with eight years of relevant experience, including three years in a Federal environment subject to FISMA.
  • The role entails hands-on responsibilities such as API security policy design, certificate management, and system security plan authorship, along with maintaining continuous monitoring and troubleshooting across various layers.
  • An active Moderate Background Investigation (MBI) suitability determination is required at the start of employment, and candidates should possess strong technical writing skills for documentation and audit purposes.
  • The position offers a salary of $120,000 per year, reflecting the advanced expertise and experience required for this critical role.

POSITION OVERVIEW

The Senior Cybersecurity Integration Engineer secures and integrates the Customer's enterprise API gateway, drives it through the Risk Management Framework to a signed Authority to Operate, and keeps it authorized thereafter. The role combines hands-on security engineering at the API boundary — policy enforcement, cryptographic and certificate management, service onboarding across network and security boundaries — with ownership of the System Security Plan and the continuous monitoring program that sustains the authorization. This position requires an active Moderate Background Investigation (MBI) suitability determination at start.



RESPONSIBILITIES

  • Design and enforce API security policy — authentication, authorization, token validation, rate limiting, payload validation, threat protection
  • Manage TLS, mutual TLS, and certificate and key lifecycle across all environments and external trust relationships
  • Onboard applications, vendors, and SaaS services to the gateway; coordinate firewall, proxy, DNS, and load balancer changes with the owning teams
  • Integrate the gateway with enterprise identity and federation services
  • Harden gateway and hosts to STIG/SCAP; feed audit and security telemetry to the enterprise SIEM
  • Promote configuration through the Customer's environments under Government change control
  • Author and maintain the SSP and control narratives against NIST 800-53 Rev 5, including boundary, inventory, inheritance, and tailoring
  • Run the RMF package to ATO — evidence, assessor walkthroughs, finding resolution
  • Sustain ConMon: recurring scans, false positive validation, remediation and retest, POA&M closure, deviation requests, monthly deliverables
  • Perform security impact analysis on changes and keep documentation current
  • Troubleshoot end to end across gateway, network, identity, and application layers



REQUIRED QUALIFICATIONS

  • Bachelor's degree in Engineering, Computer Science, Cybersecurity, or Information Systems, or equivalent hands-on experience in lieu of the degree
  • Active MBI suitability determination, current and transferable as of your start date
  • Eight years of hands-on cybersecurity or integration engineering on enterprise API gateway, identity and access management, or boundary security platforms in production, including three years in a Federal environment subject to FISMA
  • Production ownership of an enterprise API gateway or comparable boundary platform, covering security policy authoring, version upgrades, certificate lifecycle, environment promotion, and day-to-day production support
  • Working depth in API and web security protocols, including OAuth 2.0, OpenID Connect, JWT validation, SAML 2.0 federation, mutual TLS, PKI, and the threats described in the OWASP API Security Top 10
  • Demonstrated experience integrating services across network and security boundaries, coordinating changes with separate firewall, proxy, and identity teams
  • Authorship of a System Security Plan for a Federal system, writing control narratives from the system's actual configuration and documenting inherited, hybrid, and tailored controls
  • Experience carrying a system or major component through the Risk Management Framework to a signed ATO, then sustaining it under continuous monitoring
  • Practical command of FISMA obligations and the NIST guidance that drives them — 800-37, 800-53 Rev 5, 800-53A, and 800-137
  • End-to-end vulnerability management: executing scans, validating false positives, remediating, retesting, and documenting closure
  • Experience with modern gateway operating models, including configuration-as-code, separated control and data planes, and API-driven administration
  • Linux administration on RHEL or CentOS, shell scripting, and log integration with an enterprise SIEM such as Splunk
  • Technical writing strong enough that your control narratives and diagrams hold up under assessor and auditor review
  • Experience delivering in an Agile or Scrum environment alongside Government product owners and multiple contractor teams


PREFERRED QUALIFICATIONS

  • An active professional security certification such as CISSP, CISA, CISM, CAP or CGRC, a relevant GIAC certification, or Security+
  • Time spent as an ISSO or ISSM, or directly supporting one, on a FISMA-reportable system
  • Hands-on authoring of security documentation inside a GRC or RMF package-of-record tool such as eMASS, Xacta, or CSAM
  • Familiarity with FedRAMP authorization artifacts — the SSP, Control Implementation Summary, and Customer Responsibility Matrix — and with inheriting controls from an authorized cloud service
  • An active vendor certification on the program's API gateway platform, or willingness to earn it within 90 days of start with training provided
  • Prior support to a Federal financial or tax administration program, particularly in identity, authentication, API gateway, or enterprise content management work
  • Container-native deployment experience with Docker, Kubernetes or OpenShift, ingress controllers, and Helm
  • Automation and infrastructure-as-code using Ansible, Terraform, or CI/CD pipelines
  • Depth in a commercial federation or identity platform such as Ping Federate, Ping Access, or CA SiteMinder
  • Experience with a secrets and key management platform such as HashiCorp Vault, CyberArk, or a cloud-native KMS
  • Development experience in Lua, Python, or Java sufficient to build custom gateway policy modules



Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.