The engineer will design and enforce API security policies while managing the enterprise API gateway through the Risk Management Framework to achieve and maintain an Authority to Operate. They are responsible for system security planning, continuous monitoring, and coordinating security integrations across network and identity boundaries.
Benefits:
401(k) matching
Bonus based on performance
Competitive salary
Dental insurance
Health insurance
Paid time off
Parental leave
Tuition assistance
Vision insurance
POSITION OVERVIEW The Senior Cybersecurity Integration Engineer secures and integrates the Customer's enterprise API gateway, drives it through the Risk Management Framework to a signed Authority to Operate (ATO), and keeps it authorized. The role pairs hands-on security engineering at the API boundary with ownership of the System Security Plan and the continuous monitoring that sustains it. Requires an active Moderate Background Investigation (MBI) at start.
RESPONSIBILITIES Design and enforce API security policy — authentication, authorization, token validation, rate limiting, payload validation, threat protection
Manage TLS, mutual TLS, and certificate and key lifecycle across all environments and trust relationships
Onboard applications, vendors, and SaaS services, coordinating firewall, proxy, DNS, and load balancer changes with owning teams
Integrate the gateway with enterprise identity and federation services
Harden gateway and hosts to STIG/SCAP and feed security telemetry to the enterprise SIEM
Promote configuration through the Customer's environments under Government change control
Author and maintain the SSP and control narratives against NIST 800-53 Rev 5, covering boundary, inventory, inheritance, and tailoring
Run the RMF package to ATO: evidence, assessor walkthroughs, finding resolution
Perform security impact analysis on changes and troubleshoot across gateway, network, identity, and application layers
REQUIRED QUALIFICATIONS
Active MBI, current and transferable as of your start date
U.S. citizenship, as required for Customer contractor staff
Eight years of hands-on cybersecurity or integration engineering on enterprise API gateway, IAM, or boundary security platforms in production, including three years in a Federal FISMA environment
Production ownership of an enterprise API gateway or comparable platform: policy authoring, upgrades, certificate lifecycle, environment promotion, and production support
Depth in API and web security protocols: OAuth 2.0, OpenID Connect, JWT validation, SAML 2.0 federation, mutual TLS, PKI, and the OWASP API Security Top 10
Experience integrating services across network and security boundaries, coordinating changes with separate firewall, proxy, and identity teams
Authorship of a System Security Plan for a Federal system, writing control narratives from actual configuration and documenting inherited, hybrid, and tailored controls
Experience carrying a system or major component through RMF to a signed ATO, then sustaining it under continuous monitoring
Command of FISMA and NIST 800-37, 800-53 Rev 5, 800-53A, and 800-137
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”