Cyber Risk Mitigation Engineer (VA ESOM)
cybersecurityIncident ResponseSecurity ArchitectureIdentity and Access Management (IAM)Network SecurityEndpoint SecurityMalware ContainmentBackup ProtectionResilience ValidationNIST SP 800-34
About the Role
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Cyber Risk Mitigation Engineer (VA ESOM) based in United States. This role focuses on strengthening cyber resilience and protecting application recovery capabilities across a federal technology environment. You will identify vulnerabilities, security dependencies, and cyber risks that could affect recovery and operational continuity. The position combines cybersecurity engineering, incident response, resilience planning, and security architecture to evaluate how systems respond to disruptive threats. You will design and support recovery exercises covering scenarios such as ransomware, destructive attacks, compromised credentials, and data corruption. Working closely with application owners, engineers, and program leadership, you will translate technical findings into practical and measurable mitigation actions. This is a high-impact opportunity to help strengthen secure recovery processes and reduce the risk of reinfection, unauthorized access, and continued compromise. This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Cyber Risk Mitigation Engineer (VA ESOM) based in United States. This role focuses on strengthening cyber resilience and protecting application recovery capabilities across a federal technology environment. You will identify vulnerabilities, security dependencies, and cyber risks that could affect recovery and operational continuity. The position combines cybersecurity engineering, incident response, resilience planning, and security architecture to evaluate how systems respond to disruptive threats. You will design and support recovery exercises covering scenarios such as ransomware, destructive attacks, compromised credentials, and data corruption. Working closely with application owners, engineers, and program leadership, you will translate technical findings into practical and measurable mitigation actions. This is a high-impact opportunity to help strengthen secure recovery processes and reduce the risk of reinfection, unauthorized access, and continued compromise. Accountabilities: Identify cyber threats, vulnerabilities, and security dependencies that could affect application recovery and resilience. Develop tabletop exercise scenarios addressing ransomware, destructive attacks, compromised credentials, data corruption, and loss of trusted services. Define cyber-focused exercise objectives, assumptions, injects, expected decisions, and evaluation criteria. Evaluate coordination and alignment between information system contingency plans and incident response plans. Assess backup protection, privileged access, credential recovery, logging, network controls, clean recovery environments, and system reconstitution capabilities. Evaluate whether recovery procedures adequately reduce the risk of reinfection, unauthorized access, or continued compromise. Document cybersecurity findings and clearly distinguish confirmed weaknesses from assumptions requiring additional technical validation. Develop actionable mitigation recommendations with defined owners, priorities, and measurable completion criteria. Support restoration, failover, and recovery testing used to validate security improvements and resilience capabilities. Brief application owners, engineering teams, and program leadership on significant cyber recovery risks, findings, and mitigation progress. Collaborate with technical and program stakeholders to improve cyber recovery processes and strengthen operational resilience. Contribute to additional responsibilities aligned with customer requirements, business needs, and program priorities. Requirements: Master’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical discipline. 10 years of relevant professional experience; additional relevant experience may be substituted for the required education on a year-for-year basis. Demonstrated experience in cybersecurity engineering, incident response, cyber resilience, security architecture, or a related discipline. Strong knowledge of identity and access management, network and endpoint security, logging, malware containment, backup protection, and secure system restoration. Ability to assess complex recovery environments, identify security weaknesses, and translate technical findings into practical mitigation strategies. Experience developing or supporting cybersecurity exercises, recovery testing, and resilience validation. Preferred: experience applying NIST SP 800-34, NIST SP 800-84, or NIST SP 800-53 contingency planning controls. Preferred: experience with ransomware recovery, clean-room restoration, privileged access recovery, or cyber recovery vaults. Preferred: experience leading or supporting tabletop, functional, or technical recovery exercises. Preferred: relevant cybersecurity, incident response, cloud, or business continuity certification. Preferred: experience supporting large federal, Department of Defense, or public-sector IT environments. Must be a U.S. Citizen or lawful permanent resident (Green Card holder). Must be willing and able to obtain and maintain a Public Trust clearance. Must meet applicable updated identification requirements for the suitability process and be willing to update existing identification documents if necessary. Strong analytical, communication, documentation, and stakeholder management skills, with the ability to brief both technical teams and program leadership. Benefits: Remote position available within the United States. Eastern Time working hours. Annual compensation range of $140,000–$155,000, with final placement based on relevant skills, experience, education, certifications, location, and applicable security clearance level. Paid time off. Healthcare benefits. Supplemental benefits. 401(k) plan with employer matching. Discount and rewards programs. Education reimbursement for certifications, degrees, and professional development, subject to applicable IRS limitations. Flexibility to pursue courses, certifications, professional development, and networking opportunities. Opportunities to work across diverse technology and business career paths supporting federal missions. Collaborative environment focused on teamwork, innovation, dedication, and professional growth. Virtual and in-person employee activities, including wellness and fitness events, social gatherings, holiday events, and annual celebrations. Opportunities to participate in community and charitable events. Commitment to equal employment opportunity and an inclusive workplace. Reasonable accommodations available to qualified individuals with disabilities. How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1
You'll be redirected to Jobgether's application page
Job Details
Salary
$140K–$155K
Location
United States
Job type
Contract
Category
Cybersecurity
Experience
10 years
Posted
Today
Job Highlights
- $140K–$155K salary
- 10 years level role
- 100% Remote — open to candidates in United States
About Jobgether
This job is hosted by Jobgether. Clicking Apply opens their site.
Remote Work Style
Mixed
Mix of flexible and scheduled meetings
Your Match
See how well your skills line up with this role, and what you're missing.
AI Cover Letter
Generate a cover letter tailored to this job from your profile.