JobRaahGet matched free

Jobs

Cyber Security Project Engineer

Bespoke Technologies · McLean, VA · United States · On-site

Posted Oct 5, 2026

Apply with JobRaah

Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.

BT-474 – Cyber Security Project Engineer Location: McLean **Please do NOT apply if you do not have an active Poly clearance. Those without a Poly will not be considered.** Introduction The Sponsor’s proactive cyber defense team is responsible for timely identification, triage, analyze, quantify, and track remediation of newly discovered or withstanding vulnerabilities and weaknesses across all of the organization’s networks and systems. The Sponsor requires support specializing in the application of theoretical and practical knowledge of cybersecurity, specifically vulnerability management, to maintain an optimal security and risk posture of networks, systems, and information. This is a tactical role and the work may be performed independently or within a team environment. The Sponsor needs polished skills in data analysis, fundamental understanding of types of vulnerabilities, network attacks, and current industry threats, executing within a moderate to heavy workload. To include analysis across data sources and tools from numerous sources, with detailed remediation/mitigation plans to be tracked via KPI metrics. Skills/Experience Experience in cyber security or related IT field. Experience with adversarial tactics, techniques, & procedures (TTPs). Experience with computer attack methods and system exploitation techniques. Experience with cyber security principles for Linux, Windows, virtual platforms, networking, and Cloud. Experience with network architectures and fundamentals. Experience developing risk management methodologies. Experience analyzing test results to develop risk and threat mitigation plans. Experience with market-leading vulnerability management tools including the ability to deploy, configure, and run these tools. Experience with vulnerability concepts and prevalent vulnerability types such as SQL injection, cross-site scripting (XSS), cross-site request forgery (CSRF), path traversals, denial of service (DoS), buffer overflows, command injection, race conditions, open redirects, privilege escalation, authentication bypasses, XML External Entity (XXE) attacks and similar. Experience with privilege and high/low trust boundaries and what defines a vulnerability vs. weakness. Experience with vulnerability and risk scoring frameworks and methodologies such as CVSSv2 and CVSSv3. Experience with vulnerability repositories (NVD, CVE MITRE, and VULdb) and exploitation techniques (MITRE ATT&CK and DEFEND). Experience with web application (OWASP) and OS-level vulnerability categories and documentation. Experience communicating how an attacker would exploit vulnerabilities and the types of attacks they could be used for. Experience with the general threat landscape of an IT network and how vulnerabilities and exploitation of them impact it. Experience with patch management and software development lifecycle (SDLC). Experience in security operations, vulnerabilities and exploitation, network…