Cyber Security Engineer – III DoS CSS

OneZero Solutions•Washington, DC
•Remote

About The Position

The Cyber Security Engineer III is the dedicated, full-time Tenable platform lead. The engineer owns engineering, operations, and maintenance of the CA Tenable vulnerability and compliance scanning platform used to assess on-premises consular systems (platform integrations, troubleshooting, backups, patching, user access, dashboard development, plugin updates, scan template design, and scan scheduling) and sustains 24x7x365 platform availability. The engineer also leads ad-hoc and BOD-driven scanning and agent deployment and integration efforts.

Requirements

  • Seven (7)+ years of cybersecurity or systems engineering experience, including four (4)+ years administering Tenable (Tenable Security Center / tenable.sc, Nessus, Nessus Agents, Tenable One / Vulnerability Management) at enterprise scale.
  • Strong Linux and Windows administration skills and scripting proficiency (Python, PowerShell, or Bash) including use of REST APIs for automation and reporting.
  • Experience with STIG/SCAP compliance scanning and audit files.
  • Active, final SECRET security clearance; U.S. citizenship.
  • DoD 8140/8570 IAT Level III baseline certification (e.g., CISSP, CASP+, GCIH, GCED) or IAT Level II with ability to obtain Level III within 6 months.
  • Experience supporting a 24x7 on-call rotation for a production security platform.

Nice To Haves

  • Tenable certifications (Tenable Security Center Specialist, Nessus Specialist, Tenable One).
  • Department of State experience, including iPost integration; DoD ACAS experience.
  • Experience with Wiz or another CNAPP for cloud scanning; SIEM (Splunk) integration.
  • Experience with CISA BOD 22-01 (KEV) and BOD 23-01 asset visibility reporting.

Responsibilities

  • Serve as the dedicated, full-time Tenable subject matter expert; maintain 24x7x365 platform availability and lead the on-call rotation.
  • Administer the Tenable platform end toend:integrations, troubleshooting, backups, patching and version upgrades, user access and role management, plugin and feed updates.
  • Design and maintain scan templates, policies, and schedules to ensure requiredcoverage: weeklyservers, monthly workstations, and any additional cadence required by Binding Operational Directives (RMF Step 6).
  • Perform ad-hoc and BOD-specific scans on request to confirm hardened server builds for developers, production applications, and appliances.
  • Ensure all in-scope assets are onboarded, grouped, and tagged in Tenable in accordance with CA configuration standards; support CA iPost application groupings and asset inventory accuracy.
  • Develop dashboards, reports, and metrics for the ISSM, AO, ISSOs, and other stakeholders, including KEV, CVE, and STIG compliance reporting.
  • Lead Nessus Agent deployment, data ingest and sharing, pipeline, and other integration efforts.
  • Deliver vulnerability and compliance scan results to ISSOs within timelines and to the assessment team during RMF Step 4.
  • Coordinate logistics for Red Cell penetration testing and Blue Team cyber hygiene scans; support hardened-build verification.
  • Document platform architecture, SOPs, and configuration baselines; provide Tenable evidence for the Evidence Index and SSPs.
  • Mentor the Cyber Security Engineer on platform operations and serve as escalation point for scanning issues.

Benefits

  • health, dental, vision, and life insurance
  • a 401(k) with company matching
  • paid time off and holidays
  • an employee referral program
  • educational assistance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service