Summary
Trace3 is a transformative IT authority providing technology solutions and consulting services to its clients. The Information System Security Engineer/Cybersecurity Engineer I integrates cybersecurity across complex information systems, supports DoD programs in AWS classified environments, and leads RMF, vulnerability management, system hardening, and ATO documentation activities.
Responsibilities
- Support the design, development, and implementation of secure architectures across multi-level systems, cloud environments (AWS), and on-premise networks
- Integrate security controls into system design aligned with NIST 800-53 and DoD requirements
- Participate in RMF lifecycle activities, including system categorization, control selection, implementation, and continuous monitoring
- Tailor security controls based on system risk, mission needs, and operational constraints
- Develop and maintain Body of Evidence (BoE) documentation, including:
- System Security Plans (SSP)
- Security Assessment Reports (SAR)
- Plan of Action & Milestones (POA&M)
- Support assessment activities and coordinate with Authorizing Officials and assessors
- Conduct vulnerability scans using tools such as Nessus, ACAS, and SCAP
- Analyze findings, prioritize risks, and drive remediation efforts with engineering teams
- Implement and validate system hardening in accordance with DoD and industry standards
- Translate technical vulnerabilities into mission and business risk for senior stakeholders
- Provide security guidance on system changes, architecture decisions, and engineering trade-offs
Skills
- * 3-5 years of experience in cybersecurity, systems engineering, or information assurance
- * Experience implementing the **DoD Risk Management Framework (RMF)** in regulated or classified environments
- * Active certification meeting **DoD 8570 / 8140 requirements** (e.g., CISSP, CASP+, or equivalent)
- * Strong understanding of:
+ Network architecture and protocols
+ Encryption and key management
+ Secure system configuration (Windows and Linux)
- * Experience with vulnerability assessment tools (e.g., Nessus, ACAS, SCAP)
- * Ability to communicate complex technical risks to non-technical stakeholders
- * Remain in a **stationary position** for extended periods of time
- * Operate a **computer, keyboard, and other office equipment** using hands and fingers
- * Communicate effectively in person, over the phone, and through electronic means
- * Occasionally move about the office to access files, office equipment, and meeting spaces
- * Lift and/or move up to **15 pounds** as needed
- * Maintain specific vision abilities, including close vision and the ability to adjust focus
- * Cybersecurity certification
- * Experience working in **AWS classified or GovCloud environments**
- * Familiarity with **DevSecOps pipelines** and CI/CD security integration
- * Experience with container security (Docker, Kubernetes)
- * Knowledge of **Zero Trust Architecture (ZTA)**
- * Experience with compliance-as-code and automation tools
Qualifications
Must Haves
- * 3-5 years of experience in cybersecurity, systems engineering, or information assurance
- * Experience implementing the **DoD Risk Management Framework (RMF)** in regulated or classified environments
- * Active certification meeting **DoD 8570 / 8140 requirements** (e.g., CISSP, CASP+, or equivalent)
- * Strong understanding of:
+ Network architecture and protocols
+ Encryption and key management
+ Secure system configuration (Windows and Linux)
- * Experience with vulnerability assessment tools (e.g., Nessus, ACAS, SCAP)
- * Ability to communicate complex technical risks to non-technical stakeholders
- * Remain in a **stationary position** for extended periods of time
- * Operate a **computer, keyboard, and other office equipment** using hands and fingers
- * Communicate effectively in person, over the phone, and through electronic means
- * Occasionally move about the office to access files, office equipment, and meeting spaces
- * Lift and/or move up to **15 pounds** as needed
- * Maintain specific vision abilities, including close vision and the ability to adjust focus
Nice to Haves
- * Cybersecurity certification
- * Experience working in **AWS classified or GovCloud environments**
- * Familiarity with **DevSecOps pipelines** and CI/CD security integration
- * Experience with container security (Docker, Kubernetes)
- * Knowledge of **Zero Trust Architecture (ZTA)**
- * Experience with compliance-as-code and automation tools
Benefits
- Comprehensive medical, dental and vision plans for you and your dependents
- 401(k) Retirement Plan with Employer Match
- 529 College Savings Plan
- Health Savings Account
- Life Insurance
- Long-Term Disability
- Training and development programs
- Major offices stocked with snacks and beverages
- Collaborative and cool culture
- Work-life balance and generous paid time off
- This position is fully remote