What are the responsibilities and job description for the Cyber Security Engineer position at V Group Inc.?
For more details, please connect with Praveen H at praveenh@vgroupinc.com or call at 609-766-2733.
End Client: Congressional Budget Office (CBO)
Job Title: Cybersecurity Engineer
Duration: 5 Years
Location: Washington, DC 20515 (Remote preferred, onsite if needed)
Position Type: Contract W2
Hours Per Week: 40 Hours
Ceipal ID: FED_CYB012_PH
Job ID: CB26-RFQ0012
This is a W2 position and needs Public Trust Tier 2 clearance level
Background check conducted through Capitol Police to access the CBO network
Scope Of the Project:
The candidate will provide cybersecurity engineering, operational, and advisory support to strengthen and maintain the organization's enterprise security environment. Responsibilities include supporting the implementation of Zero Trust principles, improving identity and access management, securing cloud, network, and endpoint environments, remediating security findings identified through incident response activities, and enhancing continuous monitoring capabilities. The candidate will assist with the design, deployment, and maintenance of security controls, ensure adherence to federal cybersecurity standards such as NIST SP 800-53 and NIST SP 800-207, and collaborate with stakeholders to improve the organization's overall security posture and resilience against cyber threats.
Responsibilities:
- Implement and maintain enterprise security controls aligned with NIST SP 800-53, including access control (AC), configuration management (CM), system and communications protection (SC), audit and accountability (AU), incident response (IR), and system and information integrity (SI) control families.
- Enforce Zero Trust Architecture principles in accordance with NIST SP 800-207, including continuous verification of users and devices, identity-centric security, and least privilege access across cloud, network, and endpoint environments.
- Design, implement, and maintain least-privilege access controls, including role-based access control (RBAC), privileged access management (PAM), and multi-factor authentication (MFA) across enterprise systems and applications.
- Configure and manage identity and access management (IAM) solutions, ensuring secure authentication, authorization, and integration with enterprise identity providers.
- Configure and maintain centralized logging, monitoring, and audit capabilities across systems, applications, and cloud platforms, ensuring integration with enterprise SIEM tools and compliance with log retention policies.
- Conduct continuous security monitoring, vulnerability assessments, and risk analysis across enterprise environments; identify security gaps and coordinate remediation in alignment with NIST Risk Management Framework (RMF) practices.
- Harden systems, applications, and cloud environments using secure configuration baselines and industry best practices, including disabling unnecessary services, enforcing encryption standards, and securing administrative access.
- Secure cloud and hybrid environments (e.g., AWS, Azure), including configuration of security services, identity controls, network protections, and workload security.
- Identify, manage, and remediate vulnerabilities across systems, applications, and infrastructure, including coordination of patch management and mitigation strategies.
- Support incident response activities by monitoring alerts, performing analysis, executing containment actions, and assisting with forensic data collection and reporting.
- Implement and maintain segmentation and access control strategies to limit lateral movement and protect sensitive data and high-value assets.
- Ensure all security changes follow formal change management processes, including documentation and security impact analysis, in compliance with NIST configuration management requirements.
- Develop, implement, and maintain cybersecurity Standard Operating Procedures (SOPs); review and update periodically to reflect evolving threats, technologies, and policies.
- Document and maintain system configurations, security baselines, and asset inventories; ensure documentation is current and supports audit readiness.
- Perform root cause analysis (RCA) for security incidents and control failures; document findings and implement corrective and preventive actions.
- Support automated patch management and security update processes across systems and platforms in accordance with organizational policies.
- Support continuous, real-time security monitoring (24/7 operations) through integration with security tools such as SIEM, EDR/XDR, and cloud-native security platforms.
- Maintain accurate and up-to-date documentation of security configurations, processes, and procedures to ensure compliance, audit readiness, and operational continuity.
- Collaborate with network, cloud, and application teams to resolve security issues, support security integration, and enhance overall enterprise security posture
Required/Preferred Skills:
- Hands-on experience implementing and managing enterprise cybersecurity controls across cloud, network, endpoint, and identity environments in accordance with security best practices and federal standards
- Strong experience with Identity and Access Management (IAM) solutions, including Role-Based Access Control (RBAC), Privileged Access Management (PAM), Multi-Factor Authentication (MFA), Single Sign-On (SSO), and least-privilege access enforcement
- Demonstrated experience implementing and supporting Zero Trust Architecture principles, including continuous verification, identity-centric security, device trust, and micro-segmentation strategies
- Proficiency with Security Information and Event Management (SIEM) platforms and Endpoint Detection and Response (EDR/XDR) solutions for security monitoring, threat detection, alert analysis, and incident response
- Experience configuring, maintaining, and analyzing centralized logging, audit trails, and security monitoring solutions across enterprise and cloud environments
- Strong knowledge of vulnerability management processes, including vulnerability scanning, risk assessment, remediation planning, patch management, and security baseline enforcement
- Hands-on experience securing cloud platforms such as AWS and/or Azure, including identity controls, network security, workload protection, configuration management, and cloud-native security services
- Experience hardening operating systems, applications, and cloud environments using secure configuration standards, encryption technologies, and industry best practices
- Working knowledge of network security concepts including firewalls, access controls, network segmentation, secure communications, and strategies to prevent lateral movement
- Experience supporting incident response activities, including event investigation, threat analysis, containment, remediation, root cause analysis, and forensic data collection
- Strong understanding of NIST SP 800-53 security controls, NIST SP 800-207 Zero Trust Architecture, and NIST Risk Management Framework (RMF) requirements
- Experience developing and maintaining cybersecurity documentation, including security procedures, standard operating procedures (SOPs), configuration baselines, system inventories, and audit artifacts
- Familiarity with formal change management processes, security impact assessments, and configuration management practices in enterprise environments
- Ability to collaborate effectively with cloud, network, infrastructure, and application teams to resolve security issues and improve overall security posture
- Strong analytical, troubleshooting, and communication skills with the ability to support complex cybersecurity operations in a highly regulated environment.
Additional Requirement
- Security Clearance: Public Trust Tier 2 clearance level required
- Background check conducted through Capitol Police to access the CBO network
V Group Inc. is a NJ-based IT Services and Products Company with its business strategically categorized in various Business Units including Public Sector, Enterprise Solutions, Professional Services, Ecommerce, Projects, and Products. Within Public Sector business unit, we cater IT Professional Services to Federal, State and Local. We have multiple awards/ contracts with 30 states, including but not limited to NY, CA, FL, GA, MD, MI, NC, OH, OR, CO, CT, TN, PA, TX, VA, NM, VT, and WA.
If you are considering applying for a position with V Group, or in partnering with us on a position, please feel free to contact me for any questions you may have regarding our services and the advantages we can offer you as a consultant.
Please share my contact information with others working in Information Technology.
Website: https://www.vgroupinc.com/publicsector
LinkedIn: https://www.linkedin.com/company/v-group/
Facebook: https://www.facebook.com/VGroupIT
Twitter: https://www.twitter.com/vgroupinc