Job Description
Senior Cyber Operations Engineer
TS/SCI CI Poly
Hybrid- Alexandria, VA
Full benefits package Must have strong hands-on AWS security cloud automaton and security ISEE background. Overview: The Senior Cyber Operations Engineer provides expert-level support to enterprise vulnerability management programs across cloud-based infrastructures. This role is critical in executing and maturing continuous monitoring capabilities through the use of industry-standard tools such as ACAS (Tenable.sc), AWS Inspector, and DISA STIG frameworks. The engineer is responsible for identifying, analyzing, and driving remediation of security vulnerabilities in alignment with DoD cybersecurity standards and Risk Management Framework (RMF) requirements. Core Responsibilities: Lead enterprise-wide vulnerability scanning, analysis, and reporting using ACAS for traditional infrastructure and AWS Inspector for cloud-hosted assets Interpret and apply DISA STIGs to support secure configuration baselines, remediation plans, and POA&M lifecycle management Coordinates with system owners, application teams, and ISSOs to drive resolution of findings Automates scanning and reporting pipelines to enhance operational efficiency Creates and maintains vulnerability dashboards, compliance reports, and audit-ready documentation Supports continuous monitoring tasks under RMF and ensures timely ingestion of findings into eMASS Provides mentorship to junior analysts and contributes to standard operating procedures and policy refinement Minimum Qualifications: 10+ years of hands-on experience in cybersecurity operations Demonstrated expertise with ACAS (Tenable.sc/Nessus), AWS Inspector, and DISA STIGs Solid understanding of NIST SP 800-53 controls and RMF processes Hands-on expertise with compliance systems such as eMASS, STIG Viewer, and SCAP tools Strong technical writing and communication skills to support findings, reports, and remediation plans Preferred Qualifications: AWS Security Certification or equivalent cloud security credential Scripting languages (e.g., Python, PowerShell, Bash) to support security automation Experience with STIG Manager, Splunk Enterprise Security, or similar orchestration tools Clearance Requirement: Active Top Secret CI Poly