Remote Cyber Risk Mitigation Engineer (VA ESOM)

KentroUNAVAILABLE, UNAVAILABLE
Remote

About The Position

Kentro is hiring for Remote Cyber Risk Mitigation Engineer to support VA ESOM contract. The Cyber Risk Mitigation Engineer identifies and mitigates cybersecurity risks that could impact application recovery and resilience. This role assesses vulnerabilities, recovery processes, and security controls; supports cyber recovery exercises and testing; develops actionable mitigation recommendations; and communicates risks and progress to technical teams and program leadership. Location: Remote - This position can be performed remotely within the United States and will support Eastern Time working hours. Compensation Range: The pay range for this position is $140-$155K annually. Kentro determines compensation by evaluating current government contracting and commercial market conditions, as well as the role’s specific requirements. Final salary placement within this range will be based on the candidate’s relevant skills, experience, education, certifications, location, and security clearance level, where applicable. This Job Description reflects the primary duties of the role; however, it is not intended to be all‑inclusive. Team members may be asked to take on additional responsibilities in alignment with customer expectations, business needs, and Kentro’s culture of collaboration and adaptability.

Requirements

  • Master’s degree in cybersecurity, computer science, information systems, engineering, or a related technical discipline.
  • 10 years of relevant experience.
  • 10 years of additional relevant experience may be substituted for education.
  • Experience in cybersecurity engineering, incident response, cyber resilience, security architecture, or a related discipline.
  • Knowledge of identity and access management, network and endpoint security, logging, malware containment, backup protection, and secure restoration.
  • US Citizen or Lawful Permanent Resident (Green Card)
  • Willing and able to obtain and maintain Public Trust Clearance
  • Must meet updated ID requirements: https://www.gsa.gov/technology/it-contract-vehicles-and-purchasing-programs/federal-credentialing-services/get-appointment-help/bring-required-documents
  • If you do not currently meet the ID requirements outlined, you must be willing and able to update your current forms of ID in a timely manner to complete the suitability process successfully.

Nice To Haves

  • Experience applying NIST SP 800-34, NIST SP 800-84, or NIST SP 800-53 contingency planning controls.
  • Experience with ransomware recovery, clean-room restoration, privileged access recovery, or cyber recovery vaults.
  • Experience leading or supporting tabletop, functional, or technical recovery exercises.
  • Relevant cybersecurity, incident response, cloud, or business continuity certification.
  • Background supporting large federal, DoD, or public-sector IT environments.

Responsibilities

  • Identify cyber threats, vulnerabilities, and security dependencies that could affect application recovery.
  • Develop tabletop scenarios involving ransomware, destructive attacks, compromised credentials, data corruption, and loss of trusted services.
  • Define cyber-focused exercise objectives, assumptions, injects, expected decisions, and evaluation criteria.
  • Evaluate coordination between information system contingency plans and incident response plans.
  • Assess backup protection, privileged access, credential recovery, logging, network controls, clean recovery environments, and system reconstitution.
  • Evaluate whether recovery procedures reduce the risk of reinfection, unauthorized access, or continued compromise.
  • Document cyber findings and distinguish confirmed weaknesses from assumptions that require technical testing.
  • Develop specific mitigation recommendations with owners, priorities, and measurable completion criteria.
  • Support restoration, failover, and recovery tests used to validate security improvements.
  • Brief application owners, engineers, and program leaders on significant cyber recovery risks and mitigation status.

Benefits

  • paid time off
  • healthcare benefits
  • supplemental benefits
  • 401k including an employer match
  • discount perks
  • rewards
  • education reimbursement for certifications, degrees, or professional development
  • flexibility for you to take a course, complete a certification, or other professional growth and networking
  • funds for activities – virtual and in-person
  • happy hours
  • holiday events
  • fitness & wellness events
  • annual celebrations
  • charity galas/events
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service