Please Accept our Privacy Policy
Security has to work in the system, not just on paper.
An SSP can describe a control perfectly and still be wrong about what the system actually does. A scanner can report a passing result without telling the whole story. An assessment can be successful while leaving behind a process nobody can sustain.
We are looking for a Cybersecurity Engineer who wants to work in the space between the requirement and the implementation and make sure the two actually match.
Pioneering Evolution has spent more than 15 years building software for federal acquisition and financial management. We are now building and operating SyncCore and SyncPoint in a controlled government cloud environment, supporting real mission decisions and real money. The program is pursuing and sustaining an Authority to Operate, and security has to be part of how the system is engineered, not something assembled for an assessor after the work is finished.
We need someone who is comfortable working where compliance requirements meet actual systems: cloud infrastructure, identity, containers, pipelines, logs, configurations, vulnerabilities, evidence, and the engineers who build and operate them.
Your job is to help turn security requirements into things that actually work.
What you would actually work on:
SyncCore is our Mission Operating System the secure, event-driven digital backbone for identity, integration, canonical data, governance, auditability, and interoperability. Built on it, SyncPoint is a modular application ecosystem covering requirements management, budgeting, task planning, resource allocation, execution, and decision support.
Identity, governance, and auditability are not features bolted onto that platform. They are what it is made of, which is why this role sits close to the engineering.
Your immediate focus will be SyncPoint and its authorization environment in Microsoft Azure Government.
You will work directly with the Deputy Director of DevOps, Cybersecurity, and Compliance, who leads PE's technical execution of the SyncPoint ATO and the broader DevSecOps, cybersecurity-engineering, cloud-security, and technical-compliance functions. You will also work closely with DevSecOps engineers, software engineers, the Chief Engineer, program leadership, our Managed Service Provider, and external cybersecurity stakeholders.
Some days you may be validating that an Azure or Kubernetes configuration actually satisfies the control described in our authorization documentation. Other days you may be investigating a vulnerability finding, helping an engineer develop a remediation, collecting the evidence that proves the correction, or writing a script so nobody has to collect that evidence manually again next month.
You will contribute to the System Security Plan, control implementation statements, POA&Ms, procedures, assessment artifacts, technical diagrams, and the evidence behind them.
The important part is not producing documents for their own sake.
The documentation has to accurately describe what the system actually does.
You will help perform technical gap assessments, investigate findings, validate control implementations, and turn identified deficiencies into engineering work that the appropriate team can execute.
You will also help apply and validate applicable DISA STIGs and SRGs, document implementation and deviations, and automate configuration validation wherever practical.
And we want to automate as much of this work as we reasonably can.
A major objective of the role is helping us move away from periodic manual compliance exercises toward repeatable security validation and continuous assessment. That means automating evidence collection, checking configurations, identifying drift, integrating security validation into engineering workflows, and helping us answer a much more useful question than "Were we compliant at the last assessment?"
Are the controls still operating correctly right now?
How the security function actually works
We want the ownership boundaries to be clear before day one.
The Deputy Director of DevOps, Cybersecurity, and Compliance leads PE's technical ATO execution, establishes cybersecurity and technical-compliance standards, coordinates assessments, oversees vulnerability management and security monitoring, leads the DevSecOps function, and owns the technical oversight relationship with our MSP.
The Cybersecurity Engineer turns that direction into implementation support, validation, investigation, automation, evidence, and remediation.
You do not independently set cybersecurity policy, own the authorization program, accept cybersecurity risk, or make authorization decisions.
You are expected to understand the requirements deeply enough to determine whether the implementation actually satisfies them and help fix it when it does not.
DevSecOps owns the implementation and operation of PE-managed cloud platforms, infrastructure, deployment pipelines, and platform controls. You will work alongside that team to translate security requirements into testable technical requirements, validate that controls are operating effectively, investigate findings, automate security checks and evidence collection, and help design practical remediation.
You may contribute directly to security-specific configuration or automation when that is the right answer. But you are not the platform operator simply because the platform contains security controls.
For security functions delivered by our MSP, you may review technical evidence, validate control coverage, investigate findings, and help identify gaps. The Deputy Director owns the broader MSP oversight relationship and resolution of control-ownership boundaries.
The Chief Engineer owns application and system architecture. Cybersecurity identifies security requirements, constraints, and risks and works with the Chief Engineer and engineering teams to develop solutions that satisfy them.
Security should influence the architecture.
It should not silently become a second architecture authority.
The current environment:
SyncPoint operates in Microsoft Azure Government and uses containerized workloads, Kubernetes / AKS, Linux and Windows systems, Entra ID, RBAC and managed identities, cloud networking, Infrastructure as Code, Git-based CI/CD, logging and monitoring, vulnerability-management tooling, and automated deployment workflows.
The security and authorization environment includes federal RMF and ATO activities, applicable NIST security controls, NIST SP 800-171, CMMC Level 2 where applicable, CUI protection requirements, DISA STIGs and SRGs, vulnerability and configuration assessment, evidence collection, and continuous monitoring.
You may work with PowerShell, Python, Bash, Azure CLI, Bicep, Terraform, cloud-security tooling, CI/CD platforms, and comparable technologies.
You do not need to have used every product on that list.
We care much more about whether you understand secure configuration, least privilege, useful logging, vulnerability remediation, evidence, automation, configuration drift, and how to prove that a control is actually working.
What we actually require:
A bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related discipline is useful.
Equivalent professional experience is absolutely acceptable.
Particularly useful, not an entrance exam:
Specific workforce-certification requirements will be applied where required by the program or labor category. We are not using a certification as a substitute for demonstrated engineering ability.
You do not need:
You do not need to have personally owned an ATO.
You do not need to arrive as an expert in every RMF artifact, Azure service, STIG, security tool, or compliance framework we use.
You do not need a CISSP or CISM to convince us that you are senior enough for the job. This is a hands-on engineering position, not the program's senior cybersecurity authority.
And you do not need to have spent your career in federal cybersecurity.
If you understand systems, security controls, automation, evidence, and how to investigate technical problems, we can teach you the specifics of our authorization environment.
Who thrives here:
The strongest people in this role are curious about what is actually happening underneath the compliance language.
They do not stop at "the scanner failed the control."
They want to know why.
Was the configuration wrong? Did the baseline change? Is the scanner interpreting the system incorrectly? Is the control inherited from somewhere else? Is the documentation wrong? Can we automate the test so we never have to wonder again?
You should like working with engineers rather than policing them.
Sometimes the best security solution starts with explaining a requirement clearly enough that a developer or DevSecOps engineer can solve it correctly. Sometimes you will build part of the solution with them. Sometimes you will create the validation that proves it stays solved.
You should also be comfortable supporting incidents and difficult technical investigations without needing to be the person formally in charge of every response.
We move fast, and we are trying to create something special rather than a compliance package that satisfies an assessor and nobody else. That takes a dynamic team of genuinely talented people, and ours is small enough that the automation you build this quarter changes how the whole program operates the next one.
If you want cybersecurity engineering where the technical answer matters as much as the compliance answer, we should talk.
Clearance, citizenship, and location
What we offer:
$100,000 – $153,000 based on demonstrated technical depth, scope of prior responsibility, and interview performance.
Plus paid time off, 10 paid holidays, medical, dental, and vision insurance, company-paid life and AD&D, company-paid short- and long-term disability, 401(k) with company contribution, legal assistance, tuition reimbursement, and continuing education opportunities.
And the part specific to this role: our security and authorization environment is actively evolving.
You are not joining simply to maintain a finished compliance package. You will have the opportunity to replace manual validation with automation, make technical evidence more trustworthy, improve how security integrates with engineering, and help build a security posture that is easier to sustain because it is part of how the system actually operates.
Innovate. Accelerate. Evolve.
Pioneering Evolution is an equal opportunity employer.