Cybersecurity & Governance Engineer

CALIBRE Systems, Inc.Washington, DC
$125,000 - $145,000Hybrid

About The Position

CALIBRE Systems, Inc., an employee-owned mission focused solutions and digital transformation company, is looking for a highly qualified Cybersecurity and Governance Engineer to support development of AI-enabled applications and reusable data products within customer’s existing environment. This position will be on-site, hybrid, or remote, at the discretion of the customer. The role combines senior cybersecurity engineering, governance, risk, and compliance support with hands-on implementation of Federal security requirements. The individual will lead Risk Management Framework (RMF) and Authority to Operate (ATO) activities, strengthen security controls across cloud and enterprise environments, support continuous monitoring, and ensure systems, artifacts, and processes align with Federal customer expectations and approved governance frameworks. This role requires expertise in Federal cybersecurity governance and all steps of NIST 800-53 RMF. Specifically, the candidate must have proven experience in FISMA, continuous monitoring, security assessment and authorization (ATO), control implementation and validation, vulnerability and configuration management, audit logging, cloud security, security documentation, POA&M management, and stakeholder coordination with Government cybersecurity personnel. The selected candidate will work closely with Government system owners, ISSOs, ISSMs, authorizing officials, program offices, and delivery teams to ensure cybersecurity solutions, governance artifacts, and authorization packages meet Federal requirements, mission needs, security/privacy expectations, audit readiness standards, and production sustainment objectives.

Requirements

  • Expertise in Federal cybersecurity governance and all steps of NIST 800-53 RMF.
  • Proven experience in FISMA, continuous monitoring, security assessment and authorization (ATO), control implementation and validation, vulnerability and configuration management, audit logging, cloud security, security documentation, POA&M management, and stakeholder coordination with Government cybersecurity personnel.

Responsibilities

  • Lead RMF lifecycle activities for Federal information systems, including categorization, control selection, implementation, assessment, authorization, and monitoring.
  • Develop, review, and maintain authorization artifacts, including SSPs, SAR inputs, POA&Ms, control implementation statements, and supporting evidence.
  • Map and validate NIST SP 800-53 controls against system architectures, security requirements, and Federal customer governance processes.
  • Support FISMA reporting, audit readiness, control assessments, and preparation for security reviews with Government stakeholders.
  • Advise program and technical teams on cybersecurity governance, compliance risk, and practical implementation of Federal security requirements.
  • Engineer and implement technical, operational, and management security controls across cloud, application, data, and enterprise environments.
  • Support identity and access management, audit logging, vulnerability management, configuration baselines, encryption, and secure system design.
  • Collaborate with cloud, DevSecOps, infrastructure, and application teams to embed security throughout the system lifecycle and deployment process.
  • Evaluate security architectures, data flows, dependencies, and inherited controls to identify risks, gaps, and compensating-control options.
  • Implement and support continuous monitoring processes, security metrics, control-health reporting, and evidence collection.
  • Track vulnerabilities, weaknesses, assessment findings, remediation activities, and POA&M status through closure.
  • Support incident response readiness, security operations coordination, and review of audit logs and access control activity.
  • Develop templates, standard operating procedures, user/admin guidance, knowledge-transfer materials, and transition artifacts.
  • Support security authorization and ATO inputs, including SSP updates, assessment evidence, risk acceptance materials, and POA&M items.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service