Job Title: Cybersecurity Engineer Lead
Job Category: Engineering
Time Type: Full time
Minimum Clearance Required to Start: TS/SCI
Employee Type: Regular
Percentage of Travel Required: Up to 10%
Type of Travel: Local
The Opportunity:
Lead cybersecurity architecture development and implementation for complex Department of Defense intelligence, electronic warfare, and cyber systems. As a Cybersecurity Engineer Lead, you will:
Design and develop enterprise-level cybersecurity architectures for intelligence and mission systemsoperatingacross multiple security domains
Lead Zero Trust architecture implementation and Identity, Credential, and Access Management (ICAM) solutions for defense systems
Architect Cross Domain Solutions (CDS) and secure data transfer capabilities between unclassified, secret, and TS/SCI environments
Develop cybersecurity strategies, policies, and technical standards to protect mission-critical systems
Lead Risk Management Framework (RMF) activities and Authorization to Operate (ATO) efforts for complex systems
Provide technical leadership and mentorship to cybersecurity engineering teams
Interface with government program offices, Information System Security Managers (ISSMs), and Authorizing Officials
Responsibilities:
Architectand implement Zero Trust security frameworks incorporating micro-segmentation, continuous verification, andleast-privilegeaccess controls
Designsecure system architectures thatcomply withNIST 800-53, NIST 800-171, DoD RMF, and Intelligence Community Directive (ICD) 503 requirements
Developsecurity architecture artifacts including system security plans, security architecture diagrams, data flow diagrams, and threat models
Leadsecurity assessments, vulnerability analyses, penetration testing coordination, and security control validation activities
ArchitectandvalidateCross Domain Solutions (CDS) for Multi-Level Security (MLS) and secure information sharing across classification boundaries
ImplementSecurity Technical Implementation Guides (STIGs), secure configuration baselines, and automated compliance scanning solutions
DesignIdentity and Access Management (IAM) solutions incorporating Multi-Factor Authentication (MFA), Role-Based Access Control (RBAC), and Attribute-Based Access Control (ABAC)
ArchitectsecureDevSecOpspipelines integrating continuous security validation, automated vulnerability scanning, and Infrastructure as Code (IaC) security controls
Developencryption strategies, Public Key Infrastructure (PKI) implementations, and cryptographic key management solutions
Leadsecurity architecture reviews, threat modeling sessions, and design review boards
Developcybersecurity roadmapsidentifyingmodernization opportunities, emerging threats, and technology insertion strategies
Providetechnical guidance on security architecture decisions to program managers, system engineers, and development teams
Supportincident response planning, security event analysis, and continuous monitoring architectures
Maintaincurrent knowledge of emerging threats, attack vectors, and defensive technologies applicable to defense intelligence systems
Qualifications:
Required:
ActiveTop Secret security clearance with SCI eligibility (required)
Master'sdegree in Cybersecurity, Computer Engineering, Electrical Engineering, Electronics Engineering, or Mathematics with concentration in computer science
10+ years of professional experience with cybersecurity engineering and architecture
Demonstratedexperience architecting enterprise cybersecurity solutions for DoD or Intelligence Community systems
Strongunderstanding of Zero Trust architecture principles and implementation strategies
Provenexperience with Risk Management Framework (RMF) processes including IATT, ATC, and ATO activities
Experiencedesigning and implementing Cross Domain Solutions (CDS) for multi-level security environments
Deepknowledge of security frameworks including NIST 800-53, NIST 800-171, CNSSI 1253, and ICD 503
Experiencewith Identity and Credential Access Management (ICAM)architecturesand implementations
Strongunderstanding of defense-in-depth strategies, network security architecture, and secure system design principles
Experiencewith security assessment tools such as ACAS (Nessus),eMASS, and security automation platforms
Demonstratedability to lead technical teams and influence cybersecurity strategy
Excellenttechnical writing and communication skills with ability to brief senior leadership
IAM, IAT, or IASAE Level I certification per DoD 8570.01-M (or DoD 8140 equivalent)
Desired:
CISSP(Certified Information Systems Security Professional) or CISM (Certified Information Security Manager) certification
CCSP(Certified Cloud Security Professional) or cloud security architecture certifications (AWS Security, Azure Security)
Experiencewith DoD Cybersecurity Maturity Model Certification (CMMC) requirements and implementation
Knowledgeof C5ISR, SIGINT, EW, or intelligence systems security requirements
Experiencewith Secure Access Service Edge (SASE) and Software-Defined Perimeter (SDP) architectures
Familiaritywith container security, Kubernetes security, and cloud-native security architectures
Understandingof AI/ML security considerations and adversarial machine learning threats
Knowledgeof electromagnetic spectrum operations security and TEMPEST requirements
Experiencewith insider threat detection and User and Entity Behavior Analytics (UEBA)
Understandingof supply chain risk management and hardware security
Familiaritywith secure communications systems and COMSEC principles
Experiencesupporting government program offices in intelligence orspecial accessprograms
Backgroundin security engineering for tactical edge computing and disconnected/intermittent/limited (DIL) environments
-
What You Can Expect:
A culture of integrity.
At CACI, we place character and innovation at the center of everything we do. As a valued team member, you'll be part of a high-performing group dedicated to our customer's missions and driven by a higher purpose - to ensure the safety of our nation.
An environment of trust.
CACI values the unique contributions that every employee brings to our company and our customers - every day. You'll have the autonomy to take the time you need through a unique flexible time off benefit and have access to robust learning resources to make your ambitions a reality.
A focus on continuous growth.
Together, we will advance our nation's most critical missions, build on our lengthy track record of business success, and find opportunities to break new ground - in your career and in our legacy.
Pay Range :
There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families. At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits.
The proposed salary range for this position is:
$126,100 - 277,300 USD
CACI is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, age, national origin, disability, status as a protected veteran, or any other protected characteristic.