Cybersecurity Engineer- CBP

Sherpa 6Ashburn, VA
$120,000 - $160,000Onsite

About The Position

The Cybersecurity Engineer supports the U.S. Customs and Border Protection (CBP) Operational Technology Operations Center (OTOC) and the build-out, integration, and operation of the Office of Information and Technology (OIT) ISS OTOC. This position will provide cybersecurity engineering, vulnerability management, incident response (IR), risk assessment, and Risk Management Framework (RMF) support for complex operational technology (OT) and mission systems. This role is intended for a cybersecurity professional who can operate at the intersection of mission requirements, OT, systems engineering, software, infrastructure, and cybersecurity. The engineer will be responsible for translating operational and technical requirements into practical security requirements, identifying and assessing vulnerabilities, determining security and mission risk, and helping engineering and program teams make informed decisions throughout the system lifecycle. The successful candidate will bring strong experience in vulnerability management, IR, and cybersecurity engineering, combined with a working knowledge of RMF, Authorization to Operate (ATO) processes, cybersecurity requirements, and mission/operational technology environments.

Requirements

  • Current DHS Suitability or the ability to obtain and maintain suitability.
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Systems Engineering, or a related technical discipline. Equivalent directly relevant professional experience may be substituted for the degree requirement.
  • 5+ years of experience in cybersecurity engineering, information security, systems engineering, vulnerability management, or a closely related technical field.
  • Demonstrated experience supporting mission-critical systems or environments with high availability, real-time communications, operational constraints, or other demanding performance requirements.
  • Demonstrated experience with cybersecurity engineering, vulnerability management, risk assessment, and security architecture across complex systems, applications, infrastructure, networks, or operational technology environments.
  • Experience supporting cybersecurity incident response, including incident analysis, investigation, containment, remediation, recovery, and post-incident activities.
  • Experience applying FISMA, NIST cybersecurity standards and guidance, and the Risk Management Framework (RMF) to government information systems.
  • Experience supporting systems through the security assessment and authorization/ATO lifecycle, including security control implementation, assessment, remediation, authorization, and continuous monitoring.
  • Experience developing and maintaining System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), Security Assessment Reports (SARs), control implementation statements, security assessments, authorization evidence, system inventories, network diagrams, and data-flow diagrams.
  • Demonstrated ability to analyze technical vulnerabilities and security findings, assess their operational and mission impact, and develop risk-based remediation or mitigation strategies.
  • Experience translating mission and operational requirements into cybersecurity requirements, security controls, and practical technical solutions.
  • Experience working with system owners, engineers, authorizing officials, security leadership, program managers, and senior government stakeholders to resolve cybersecurity risks and support authorization decisions.
  • Ability to communicate complex cybersecurity risks and technical findings clearly to both technical and non-technical audiences.

Nice To Haves

  • Cybersecurity certification such as CISSP, CISM, Security+, GSEC, or equivalent. Equivalent demonstrated cybersecurity experience may be considered in lieu of certification, where permitted.
  • Experience with government security authorization, RMF, vulnerability management, and continuous monitoring platforms and tools.
  • Familiarity with security operations and monitoring technologies, including SIEM, EDR/XDR, IDS/IPS, threat intelligence, security analytics, and incident response platforms.
  • Familiarity with Zero Trust architecture and identity-centric security, including identity and access management (IAM), privileged access management (PAM), endpoint security, threat detection, and access control.
  • Experience supporting incident response exercises, tabletop exercises, after-action reviews, and remediation activities.
  • Experience with cloud security and hybrid infrastructure, including AWS, Azure, or other government-authorized cloud environments.
  • Experience integrating cybersecurity into DevSecOps, software development, CI/CD, or automated security testing environments.
  • Experience assessing software, hardware, third-party, and supply-chain cybersecurity risks.
  • Experience supporting FISMA reporting, federal cybersecurity assessments, agency cybersecurity policies, governance processes, and compliance activities.
  • Experience developing or reviewing security architectures, system boundaries, system interconnections, attack surfaces, threat models, and cybersecurity requirements.

Responsibilities

  • Provide cybersecurity engineering support for the integration, deployment, authorization, and sustainment of complex OTOC operational technology and mission systems.
  • Translate mission, operational, and system requirements into actionable cybersecurity requirements and secure system architectures.
  • Evaluate system designs, architectures, configurations, interfaces, and dependencies to identify cybersecurity risks, vulnerabilities, and attack surfaces.
  • Integrate cybersecurity requirements into system design, development, testing, integration, deployment, and sustainment activities.
  • Provide cybersecurity engineering guidance for applications, data platforms, tactical communications systems, mission networks, and authorized effectors.
  • Collaborate with cross-functional engineering teams to resolve cybersecurity issues while maintaining mission performance, system availability, interoperability, and operational requirements.
  • Perform vulnerability identification, analysis, prioritization, remediation, and tracking across applications, infrastructure, networks, and operational technology environments.
  • Assess vulnerabilities in the context of system architecture, mission impact, threat exposure, and operational risk.
  • Analyze security findings and translate technical vulnerabilities into clear, actionable risk information for system owners, engineers, and program leadership.
  • Develop and recommend risk mitigation strategies and work with engineering teams to implement appropriate security controls and corrective actions.
  • Track security deficiencies and remediation activities through resolution, ensuring risks are appropriately mitigated, accepted, or otherwise managed.
  • Support the identification, analysis, investigation, containment, remediation, and recovery of cybersecurity incidents affecting mission systems and operational technology environments.
  • Collaborate with cybersecurity operations, engineering, and program teams to assess the technical and operational impact of security incidents and implement appropriate corrective actions.
  • Support post-incident analysis and lessons learned, incorporating findings into vulnerability management, security controls, system architecture, and risk mitigation activities.
  • Support incident response exercises, technical investigations, and recovery activities as required.
  • Support Risk Management Framework (RMF) activities throughout the system lifecycle, including security categorization, control implementation, assessment, remediation, and continuous monitoring.
  • Support the development, maintenance, and execution of Authorization to Operate (ATO) activities and associated authorization artifacts.
  • Develop and maintain cybersecurity documentation, including risk assessments, security plans, POA&Ms, control assessments, vulnerability assessments, and ATO documentation.
  • Support cybersecurity assessments, audits, inspections, and technical reviews associated with system authorization and operational deployment.
  • Support continuous monitoring and ongoing authorization activities to ensure systems remain secure, compliant, operationally viable, and supportable.
  • Serve as a technical cybersecurity advisor to systems engineering, software, infrastructure, operations, cybersecurity, and program leadership teams.
  • Provide cybersecurity expertise throughout the system lifecycle, from requirements definition and architecture through integration, authorization, deployment, and sustainment.
  • Work closely with engineering and program teams to incorporate cybersecurity considerations into technical and operational decision-making.
  • Communicate cybersecurity risks, technical findings, and recommended courses of action to both technical and non-technical stakeholders.
  • Stay current with applicable cybersecurity standards, RMF requirements, vulnerability management practices, emerging threats, and cybersecurity technologies relevant to mission and operational technology environments.
  • Apply evolving cybersecurity practices and threat information to support risk-informed security decisions and system protection.

Benefits

  • Competitive benefits package
  • Medical insurance for you and your family
  • Dental insurance
  • Vision insurance
  • Health and wellness benefits
  • Generous retirement savings plan
  • Generous PTO policy
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service