What are the responsibilities and job description for the Cybersecurity Engineer position at Pioneering Evolution, LLC?
POSITION DESCRIPTION:
Pioneering Evolution is seeking a Cybersecurity Engineer to support the security engineering and compliance activities of SyncPoint, a DoD financial system operating in a Department of Defense Impact Level 4 (IL4) environment.
This is a hands-on engineering role focused on implementing security requirements, automating compliance activities, collecting and validating evidence, and supporting the program's Authority to Operate (ATO) and ongoing assessment readiness. The Cybersecurity Engineer will work closely with cybersecurity and technology leadership, DevSecOps engineers, software developers, infrastructure teams, and external service providers to help ensure security requirements are implemented effectively within the SyncPoint environment.
The role is intended for an engineer who can translate established security requirements into practical technical solutions. Particular emphasis will be placed on automation of security validation, configuration assessment, evidence collection, and continuous monitoring to support a more continuous and sustainable ATO posture.
Key Responsibilities:
ATO and Compliance Support
- Support development and maintenance of ATO and compliance artifacts, including the System Security Plan (SSP), control implementation statements, POA&Ms, procedures, and supporting evidence.
- Collect, organize, andvalidatetechnical evidence supporting security-control implementation and assessment activities.
- Assistcybersecurity and program leadership with security reviews, assessment preparation, remediation tracking, and response to assessor findings.
- Support implementation and validation of NIST SP 800-171, CMMC Level 2, RMF, and applicable DoD security requirements.
- Document technical implementations accurately so that security documentation reflects the actual operating environment.
- Assistwith gap assessments and translate identified deficiencies into actionable engineering work.
Security Automation and Continuous ATO
- Develop scripts, tooling, and automated workflows that reduce manual compliance and security-validation activities.
- Automate collection of security evidence from cloud platforms, operating systems, CI/CD pipelines, repositories, and security tools where practical.
- Develop automated configuration checks and compliance validations toidentifydriftfrom approved security baselines.
- Integrate security checks into CI/CD and infrastructure deployment workflows.
- Support automated vulnerability, configuration, and compliance scanning and help normalize findings into actionable remediation tasks.
- Help develop repeatable processes that improve continuous monitoring and support movement toward a Continuous ATO model.
Cloud and Infrastructure Security
- Implement andvalidatesecurity configurations within Microsoft Azure Government and related application infrastructure.
- Support identity and access controls including RBAC, managed identities,least privilege,privileged access, and service identities.
- Review cloud and Infrastructure as Code configurations for alignment with established security requirements.
- Support secure configuration of networking, logging, encryption,secretsmanagement, and workload access controls.
- AssistDevSecOpsengineers with securecontainer, Kubernetes, deployment, and infrastructure configurations.
Security Monitoring and Remediation
- Review security alerts, vulnerability findings, configuration findings, and audit information to helpidentifytechnical risks.
- Work with engineering and infrastructure teams to investigate findings and implementappropriate remediation.
- Support vulnerability-management activities including validation, prioritization, remediation tracking, and verification.
- Helpmaintainlogging, monitoring, and audit capabilities needed to support incident investigation and compliance evidence.
- Document findings and communicate technicalriskclearly to engineering and program leadership.
Secure Engineering Collaboration
- Work with developers andDevSecOpsengineers to incorporate security requirements into application, infrastructure, and deployment workflows.
- Translate security requirements into clear engineering tasks and practical implementation guidance.
- Support secure handling of Controlled Unclassified Information (CUI) within application and infrastructure workflows.
- Identify opportunities to replace manual security processes with automated and repeatable technical controls.
- Contribute to security documentation, engineering standards, implementation procedures, and lessons learned.
TECHNICAL ENVIRONMENT:
Area
Technologies / Practices
Compliance
NIST SP 800-171, CMMC Level 2, RMF, ATO, CUI
Cloud
Microsoft Azure / Azure Government
Infrastructure
Linux, Windows, containers, Kubernetes
Identity
Entra ID, RBAC, Managed Identity, least privilege
Infrastructure as Code
Bicep, Terraform or comparable technologies
Security Tooling
Vulnerability scanning, configuration assessment, cloud security monitoring, logging/SIEM
Automation
PowerShell, Python, Bash, Azure CLI or comparable scripting/tooling
DevSecOps
Git, CI/CD pipelines, automated security testing, secrets management
Documentation
SSP supporting artifacts, POA&Ms, control evidence, procedures, implementation documentation
KEY COMPETENCIES:
- Practical cybersecurity engineering and troubleshooting
- Security and compliance automation
- Cloud security fundamentals
- Ability to translate security requirements into technical implementation tasks
- Scripting and process automation
- Security-control validation and evidence collection
- Clear technical documentation
- Effective collaboration with engineering,DevSecOps, cybersecurity leadership, and external partners
REQUIRED EXPERIENCE:
- Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or a related technical discipline, or equivalent professional experience.
- 3 years of professional experience in cybersecurity, systems engineering, cloud engineering,DevSecOps, or a closely related technical field.
- Hands-on experience implementing,validating, or supporting technical security controls.
- Working knowledge of NIST SP 800-171 or comparable security-control frameworks.
- Experience with Microsoft Azure, AWS, oranother major cloud platform, including identity, networking, logging, encryption, and access-control concepts.
- Experience with scripting or automation using PowerShell, Python, Bash, Azure CLI, or comparable technologies.
- Experience working with Git-based development or infrastructure workflows.
- Familiarity with vulnerability management, security configuration assessment, or compliance-scanning tools.
- Strong analytical and troubleshooting skills.
- Strong written and verbal communication skills, including the ability to document technical implementations and findings clearly.
REQUIRED CERTIFICATION:
- CompTIA Security or another certification satisfying the applicable DoD 8140 workforce qualification requirement for the position.
DESIRED EXPERIENCE:
- Experience supporting a DoD RMF or ATO effort.
- Familiarity with CMMC Level 2 and NIST SP 800-171 assessment activities.
- Experience automating security-control validation, compliance evidence collection, or continuous-monitoring activities.
- Experience with DISA STIGs, SCAP, or automated security configuration assessment.
- Experience with Azure Government or other DoD-authorized cloud environments.
- Experience with Infrastructure as Code such as Bicep or Terraform.
- Experience integrating security tools or policy checks into CI/CD pipelines.
- Familiarity with container and Kubernetes security.
- Experience with Microsoft Defender for Cloud, Sentinel, Azure Monitor, or comparable security-monitoring platforms.
- Familiarity with Controlled Unclassified Information (CUI) handling requirements.
- CAP/CGRC, Microsoft cloud-security certifications, or similar technical/compliance certifications are beneficial but notrequired.
WHO WE ARE AND WHAT WE OFFER:
In addition to competitive salaries and opportunities for professional development and advancement, our employees enjoy a comprehensive range of benefits. To keep pace with the changing needs of our employees, we continually evaluate our benefit plans.
- Paid time off
- 10 paid holidays
- Medical insurance
- Dental insurance
- Vision insurance
- Legalassistance
- Company-paid life insurance and AD&D
- Company-paid long-term and short-term disability insurance
- Tuition reimbursement
- 401(k) plan with company contribution
- Continuing Education Opportunities
Salary : $100,000 - $153,000