Senior Cybersecurity Integration Engineer

Basecamp Consulting & Solutions LLC

Senior Cybersecurity Integration Engineer

Reston, VA
Full Time
Paid
  • Responsibilities

    Benefits:

    401(k) matching

    Bonus based on performance

    Competitive salary

    Dental insurance

    Health insurance

    Paid time off

    Parental leave

    Tuition assistance

    Vision insurance

    POSITION OVERVIEW The Senior Cybersecurity Integration Engineer secures and integrates the Customer's enterprise API gateway, drives it through the Risk Management Framework to a signed Authority to Operate (ATO), and keeps it authorized. The role pairs hands-on security engineering at the API boundary with ownership of the System Security Plan and the continuous monitoring that sustains it. Requires an active Moderate Background Investigation (MBI) at start.

    RESPONSIBILITIES Design and enforce API security policy — authentication, authorization, token validation, rate limiting, payload validation, threat protection

    Manage TLS, mutual TLS, and certificate and key lifecycle across all environments and trust relationships

    Onboard applications, vendors, and SaaS services, coordinating firewall, proxy, DNS, and load balancer changes with owning teams

    Integrate the gateway with enterprise identity and federation services

    Harden gateway and hosts to STIG/SCAP and feed security telemetry to the enterprise SIEM

    Promote configuration through the Customer's environments under Government change control

    Author and maintain the SSP and control narratives against NIST 800-53 Rev 5, covering boundary, inventory, inheritance, and tailoring

    Run the RMF package to ATO: evidence, assessor walkthroughs, finding resolution

    Sustain ConMon: recurring scans, false positive validation, remediation and retest, POA&M closure, deviation requests, monthly reporting

    Perform security impact analysis on changes and troubleshoot across gateway, network, identity, and application layers

    REQUIRED QUALIFICATIONS

    Active MBI, current and transferable as of your start date

    U.S. citizenship, as required for Customer contractor staff

    Eight years of hands-on cybersecurity or integration engineering on enterprise API gateway, IAM, or boundary security platforms in production, including three years in a Federal FISMA environment

    Production ownership of an enterprise API gateway or comparable platform: policy authoring, upgrades, certificate lifecycle, environment promotion, and production support

    Depth in API and web security protocols: OAuth 2.0, OpenID Connect, JWT validation, SAML 2.0 federation, mutual TLS, PKI, and the OWASP API Security Top 10

    Experience integrating services across network and security boundaries, coordinating changes with separate firewall, proxy, and identity teams

    Authorship of a System Security Plan for a Federal system, writing control narratives from actual configuration and documenting inherited, hybrid, and tailored controls

    Experience carrying a system or major component through RMF to a signed ATO, then sustaining it under continuous monitoring

    Command of FISMA and NIST 800-37, 800-53 Rev 5, 800-53A, and 800-137

    End-to-end vulnerability management: scanning, validating false positives, remediating, retesting, and documenting closure

    Linux administration on RHEL or CentOS, shell scripting, and SIEM log integration such as Splunk

    Technical writing strong enough that control narratives hold up under assessor review

    Bachelor's degree in Engineering, Computer Science, Cybersecurity, or Information Systems, or equivalent hands-on experience

    PREFERRED QUALIFICATIONS

    An active professional security certification such as CISSP, CISA, CISM, CAP or CGRC, GIAC, or Security+

    Time as an ISSO or ISSM, or directly supporting one, on a FISMA-reportable system

    Hands-on authoring inside a GRC or RMF tool of record such as eMASS, Xacta, or CSAM

    An active vendor certification on the program's gateway platform, or willingness to earn it within 90 days; training provided

    Prior support to a Federal financial or tax administration program

    Experience with configuration-as-code, separated control and data planes, and API-driven gateway administration

    Depth in a federation platform such as Ping Federate, Ping Access, or CA SiteMinder

    Flexible work from home options available.