Cybersecurity Validation and Test Engineer
Job Locations
US
| ID |
2026-4469
|
Category |
Defense
|
Type |
Full Time
|
Overview
Amyx is seeking Cybersecurity Validation and Test Engineer to support the Defense Logistics Agency (DLA) by performing cybersecurity control validation, security assessment, testing, and compliance activities across enterprise applications, systems, and environments.
This position is responsible for evaluating the effectiveness of implemented security controls, supporting Risk Management Framework (RMF) activities, conducting security assessments, and assisting with authorization and compliance efforts. The specialist works closely with cybersecurity personnel, engineers, developers, system administrators, and government stakeholders to identify security risks, validate corrective actions, and ensure compliance with Department of Defense (DoD) cybersecurity requirements.
The successful candidate will possess strong analytical, troubleshooting, and cybersecurity assessment skills with the ability to balance security requirements against operational and business needs.
Responsibilities
Conduct cybersecurity control validation and security assessment activities for enterprise applications, systems, and environments.
- Evaluate implemented security controls to determine effectiveness and compliance with DoD and federal cybersecurity requirements.
- Support RMF activities, security authorization efforts, and cybersecurity compliance initiatives.
- Perform vulnerability assessments, security reviews, and risk analysis activities.
- Validate remediation efforts and evaluate proposed mitigations for identified security findings.
- Support eMASS documentation, artifact collection, control assessments, and package maintenance activities.
- Collaborate with engineers, developers, system administrators, and stakeholders to identify and resolve security concerns.
- Analyze security risks and provide recommendations for improving security posture while balancing business and operational requirements.
- Develop assessment reports, testing documentation, findings summaries, and compliance-related deliverables.
- Support AMPS modernization efforts and cybersecurity initiatives through security testing, requirements analysis, and risk evaluation activities.
- Must have the ability to communicate accurate information
Qualifications
Required:
- Sensitivity Level: Non-Critical Sensitive
- Must possess or be able to obtain an IT-II Non-Critical Sensitive (Tier 3/T3) determination prior to onboarding.
- 3+ years of experience supporting cybersecurity assessment, control validation, compliance, or related security functions.
- 3+ years of experience working with DoD 8500-series guidance, NIST SP 800-53, and Risk Management Framework (RMF) principles.
- 2+ years of experience supporting eMASS activities.
- Experience conducting security assessments, control validation, vulnerability assessments, or risk analysis activities.
- Experience evaluating security controls and validating remediation or mitigation efforts.
- Experience analyzing security risks and balancing business requirements with cybersecurity requirements.
- Experience supporting system authorization, compliance, or cybersecurity governance activities.
- Knowledge of network security concepts and security control implementation.
- Proficiency with Microsoft Office Suite, including Word, Excel, Access, and PowerPoint.
- Strong analytical, troubleshooting, and problem-solving skills.
- Strong written and verbal communication skills.
Desired:
- Experience supporting RMF-authorized environments within the Department of Defense.
- Experience supporting Security Control Assessor (SCA), ISSO, ISSM, or cybersecurity compliance activities
- Experience conducting vulnerability assessments using automated scanning and security assessment tools.
- Experience supporting security testing for enterprise applications, infrastructure, or identity management solutions.
- Experience reviewing Security Plans (SSPs), POA&Ms, Security Assessment Reports (SARs), and other RMF documentation.
- Experience supporting cybersecurity efforts within the Defense Logistics Agency (DLA), Department of Defense (DoD), or other federal government customers.
- Familiarity with Zero Trust Architecture principles and cybersecurity modernization initiatives.
- Experience supporting cloud-based or hybrid environments.
- Experience evaluating security requirements throughout the system development lifecycle.
- Experience working with engineers, developers, and system administrators to implement corrective actions and improve system security.
- Relevant cybersecurity certifications such as Security+, CySA+, CASP+, CISSP, CISM, or CAP.
- Bachelor's degree in Cybersecurity, Information Technology, Information Security, Computer Science, or a related discipline.
Benefits include:
- Medical, Dental, and Vision Plans (PPO & HSA options available)
- Flexible Spending Accounts (Health Care & Dependent Care FSA)
- Health Savings Account (HSA)
- 401(k) with matching contributions
- Roth
- Qualified Transportation Expense with matching contributions
- Short Term Disability
- Long Term Disability
- Life and Accidental Death & Dismemberment
- Basic & Voluntary Life Insurance
- Wellness Program
- PTO
- 11 Holidays
- Professional Development Reimbursement
Salary- 100-140k Please contact talent@amyx.com with any questions! Amyx is proud to be an Equal Opportunity Employer. All qualified candidates will be considered without regard to race, color, religion, national origin, age, disability, sexual orientation, gender identity, status as a protected veteran, or any other characteristic protected by law. Amyx is a VEVRAA federal contractor and we request priority referral of veterans.
Physical Demands
Employee needs to be able to sit at a workstation for extended periods; use hand(s) to handle or feel objects, tools, or controls; reach with hands and arms; talk and hear. Most positions require ability to work on desktop or laptop computer for extended periods of time reading, reviewing/analyzing information, and providing recommendations, summaries and/or reports in written format. Must be able to effectively communicate with others verbally and in writing. Employee may be required to occasionally lift and/or move moderate amounts of weight, typically less than 20 pounds. Regular and predictable attendance is essential.
|