{"id":1639213,"url":"https://alion.io/job/innovim-cybersecurity-engineer-cbo","title":"Cybersecurity Engineer - CBO","company":{"id":3854336,"name":"Innovim","domain":"innovim.com","url":"https://alion.io/company/innovim","size_band":"501-1000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"UltiPro","truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":[],"countries":[],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":90000,"max":107000,"currency":"USD","period":"year","gross":null,"usd_annual":107000},"salary_estimate":null,"experience_years_min":8,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"IAM","optional":false},{"name":"Least Privilege","optional":false},{"name":"Microsoft Defender","optional":false},{"name":"Microsoft Sentinel","optional":false},{"name":"SIEM","optional":false},{"name":"Splunk","optional":false},{"name":"Zero Trust","optional":false},{"name":"Active Directory","optional":true},{"name":"Microsoft Entra ID","optional":true}],"status":"live","first_seen_at":"2026-09-09T15:25:40Z","employer_posted_date":"2026-09-09","last_verified_at":"2026-10-11T02:48:45Z","board_verified":true,"closed_at":null,"days_open":31,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":31},"description":"Location Washington, DC - hybrid; on-site as required by task assignment\nEmployment Type Full-time - contingent upon contract award\nSalary Range $90,000 - $107,000\nClearance / Suitability Public Trust (Tier 2); U.S. citizenship or permanent residence required\nPosition Summary\nThe Cybersecurity Engineer designs, implements, and maintains enterprise security controls that enforce Zero Trust principles - identity-centric access, least-privilege enforcement, continuous monitoring, and threat detection - across cloud, network, and endpoint environments for a U.S. legislative branch agency. The role strengthens the organization's overall security posture and improves detection and response capabilities in alignment with NIST SP 800-53 and NIST SP 800-207.\nKey Responsibilities\nImplement and maintain enterprise security controls aligned with NIST SP 800-53 (AC, CM, SC, AU, IR, SI control families).\nEnforce Zero Trust Architecture per NIST SP 800-207, including continuous verification, identity-centric security, and least-privilege access across cloud, network, and endpoint environments.\nConfigure and manage Identity and Access Management (IAM): authentication, authorization, role-based access control (RBAC), privileged access management (PAM), and multi-factor authentication (MFA).\nMonitor, analyze, and respond to security events using enterprise tools (SIEM, EDR/XDR); support incident triage, containment, investigation, and remediation.\nMaintain continuous monitoring capabilities - centralized log collection, correlation, and analysis with compliant log retention.\nConduct vulnerability scanning, assessment, and remediation across systems and applications; coordinate patching and mitigation.\nSupport cloud and application security (e.g., AWS, Azure): secure configuration, identity controls, and workload security.\nHarden systems, applications, and cloud environments to secure configuration baselines; implement segmentation to limit lateral movement.\nPerform risk analysis aligned with the NIST Risk Management Framework (RMF); conduct RCA for security incidents and control failures.\nDevelop and maintain cybersecurity SOPs, security baselines, and audit-ready documentation; support 24/7 security monitoring operations.\nRequired Qualifications\nBachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field (equivalent experience considered).\nMinimum 8 years of hands-on cybersecurity engineering experience.\nDemonstrated experience with SIEM (e.g., Microsoft Sentinel or Splunk), EDR/XDR (e.g., Microsoft Defender), IAM/MFA, and vulnerability management (e.g., Tenable).\nWorking knowledge of NIST SP 800-53, NIST SP 800-207 Zero Trust, and the NIST Risk Management Framework.\nCompTIA Security+ (DoD 8140/8570 IAT/IAM) required; higher-level certification preferred.\nS. citizenship or permanent residence status; ability to obtain a Public Trust (Tier 2) determination.\nPreferred Qualifications\nCISSP, CySA+, GIAC (e.g., GCIH, GCIA), or CEH.\nMicrosoft (SC-200/AZ-500) or AWS security certifications.\nHands-on experience with Microsoft Sentinel, Microsoft Defender, and Tenable.sc.\nExperience securing hybrid Active Directory / Entra ID and M365 GCC environments.\nPrior experience supporting federal or Congressional / legislative branch environments.\nClearance, Suitability & Security\nU.S. citizenship or permanent residence status is required. The selected candidate must be able to obtain and maintain a Public Trust (Tier 2) suitability determination and will undergo an FBI criminal background check and U.S. Capitol Police fingerprinting prior to starting work, in accordance with the contract's security requirements. Remote work is authorized; however, on-site presence at the customer's facilities in Washington, DC (and, as needed, data-center/computing facilities in Ashburn, VA and Manassas, VA) may be required based on task assignment. Local travel to these sites is non-reimbursable. Core hours are 9:00 AM-6:00 PM ET, Monday-Friday; occasional after-hours or weekend maintenance activity may be required.\nCompensation\nSalary Range: $90,000 - $107,000, commensurate with experience, education, and certifications. INNOVIM offers a comprehensive benefits package including health, dental, and vision coverage, retirement savings, paid time off, and professional development support.","description_format":"text","description_chars":4354,"description_truncated":false,"requirements":{"experience_years_min":8,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":true,"languages":[]},"benefits":["Professional development"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","Information Security"],"lifecycle":[{"event":"open","at":"2026-10-01T21:44:25Z"}],"visa":[],"liveness":{"score":61,"band":"ok","label":"Likely open","p_open":1,"p_active":0.811,"p_room":0.75,"age_days":30,"expected_fill_days":40,"reasons":["conf:0","velocity","win:late"],"computed_at":"2026-10-10T05:45:15Z"},"pay":{"stated_usd_annual":107000,"is_top_pay":false},"html_url":"https://alion.io/job/innovim-cybersecurity-engineer-cbo","json_url":"https://alion.io/job/innovim-cybersecurity-engineer-cbo.json","meta":{"generated_at":"2026-10-11T02:51:59Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":139,"day_limit":5000,"remaining_today":4861,"minute_limit":60,"resets_at":"2026-10-12T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":3854336},"rest":"https://alion.io/mcp/rest/get_company?id=3854336"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Finnovim-cybersecurity-engineer-cbo"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Finnovim-cybersecurity-engineer-cbo"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Finnovim-cybersecurity-engineer-cbo"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/innovim-cybersecurity-engineer-cbo\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Finnovim-cybersecurity-engineer-cbo"}]}