Haystack
← Back to Jobs
Temporary/Casual
Technology

Cybersecurity Risk & Authorization Engineer - DAOR 3 with Security Clearance

NineFX, Inc.Fort Meade, MD🇺🇸United StatesPosted 27 Jul 2026

Why This Role Stands Out

Leverage your expertise in cybersecurity risk management and authorization to drive secure system development and compliance within a reputable organization, offering a hybrid work model for enhanced flexibility. You'll thrive in this role if you excel at identifying security requirements, conducting risk assessments, and collaborating with diverse teams to safeguard critical data and systems. This is an excellent opportunity to grow your skills and make a significant impact.

Quick Overview

Work Type
Hybrid
Schedule
Temporary/Casual
Level
Mid Senior

Job Description

The DAOR supports enterprise Cybersecurity and risk management activities by identifying security requirements, evaluating and validating security controls, and ensuring systems meet federal information assurance standards. This role works closely with technical teams, stakeholders, and senior leaders to guide secure system development, integrate legacy capabilities, and support authorization activities across complex IT environments. Responsibilities:
• Identify Cybersecurity requirements and ensure appropriate security controls are implemented to protect organizational data.
• Conduct and analyze security risk assessments, risk analyses, and risk management activities for systems and network operations.
• Support security control assessments, configuration management processes, and Cybersecurity awareness activities.
• Ensure Cybersecurity considerations are incorporated throughout development, deployment, and risk management lifecycles, with emphasis on infrastructure protection and defensive IT strategies.
• Collaborate with customers, IT staff, and executive leadership to define and achieve enterprise Cybersecurity and risk management objectives.
• Contribute to the development and enhancement of security architectures.
• Support secure integration of legacy systems into modern environments.
• Assist with acquisition, RDT&E, and system deployment by embedding Cybersecurity controls into operational system designs.
• Prepare comprehensive security authorization documentation, including risk assessments, POA&Ms, authorization recommendations, and related materials in accordance with organizational and federal guidelines. Core Capabilities:
• Analyze Cybersecurity controls within systems intended for operational deployment.
• Prepare risk assessments, POA&Ms, and authorization documentation aligned with RMF and ICD 503.
• Identify and support enterprise-wide security requirements, ensuring compliance with policies, controls, and processes.
• Facilitate collaboration among stakeholders to achieve organizational security and risk management goals.
• Support secure legacy system integration within current IT environments. Qualifications:
• Active TS/SCI with Full Scope Polygraph (must already be held)
• Eight (8) years of experience as an IT Risk Assessor, System Security Engineer, Information Systems Security Manager, or Delegated Authorizing Official (DAO) for programs of similar scope and complexity.
• Bachelor’s degree in Computer Science, IT Engineering, or a related field; may substitute four (4) additional years of experience for a total of twelve (12) years.
• IAM Level III CISM, CISSP (or Associate), GSLC, CCISO. Required Knowledge:
• System security design principles
• Defense-in-depth and defense-in-breadth strategies
• Engineering lifecycle processes
• Information domains and cross-domain solutions
• Controlled interfaces
• Identification, authentication, authorization
• Systems integration
• ICD 503 and RMF
• Intrusion detection, incident handling, and contingency planning
• Configuration management and change control
• Auditing processes
• Security authorization workflows
• Core Cybersecurity principles: confidentiality, integrity, availability, non-repudiation, and access control
• Security testing methodologies

Similar jobs