Skip to main content

Cyber Engineer

**Company Overview**

Check out this video and find out why our team loves to work here! (https://www.cdmsmith.com/resources/videos/meet-cdm-smith)

**Join Us! CDM Smith – where amazing career journeys unfold.**

Imagine a place committed to offering an unmatched employee experience. Where you work on projects that are meaningful to you. Where you play an active part in shaping your career journey. Where your co-workers are invested in you and your success. Where you are encouraged and supported to do your very best and given the tools and resources to do so. Where it’s a priority that the company takes good care of you and your family.

Our employees are the heart of our company. As an employer of choice, our goal is to provide a challenging, progressive and inclusive work environment which fosters personal leadership, career growth and development for every employee. We value passionate individuals who challenge the norm, deliver world-class solutions and bring diverse perspectives. Join our team, and together we will make a difference and change the world.

**Job Description**

The Cyber Engineer will assist CDM Smith in their Continuous Threat Exposure Management (CTEM) journey. Items such as identifying, tracking, and verifying remediation of vulnerabilities across internal and external applications and systems. This role requires broad knowledge of enterprise applications, operating systems, networking, cloud infrastructure, and emerging threats. Working with IT infrastructure, application development and security operations teams, the engineer helps reduce vulnerabilities and attack surface risk while staying current on threats affecting both advanced and legacy technologies.

You will help architect, deploy and operate secure cloud application infrastructure aligned to business needs. This advanced technical role supports operational innovation, provides cloud security direction, and helps deliver resilient applications at scale. The engineer is expected to apply strong administrative, troubleshooting, architecture, engineering, and design skills while maintaining policies and controls that support business direction.

Working with security leadership, cloud security engineers assess the threat landscape and adapt quickly to reduce business risk. They should be highly technical, with 5–7+ years of security and systems administration experience across SaaS, IaaS, and PaaS environments. Strong analytical thinking, adaptability, work ethic, listening, and communication skills are essential.

This role will also lead vulnerability management and collaboration with technology leadership and business units to secure company digital assets. They report on vulnerability criticality, exploit probability, business impact and remediation progress to security and IT leadership. The role requires pragmatic collaboration, urgency when needed and support for strategic and tactical initiatives that reduce attack surface through automation, innovation and operational efficiency.

+ Develop and maintain secure, resilient enterprise-grade cloud & on-prem processes in tandem with architects and system engineers.

+ Secure AI & NHI at scale

+ Secure business applications and computing environments across public, private, or hybrid cloud infrastructures.

+ Protect business applications in compliance with privacy, security, business resiliency, and compliance frameworks as defined in corporate policies.

+ Maintain a consistent, secure environment using configuration management solutions (e.g., Puppet, Chef, Ansible, etc.). Conduct rigorous oversight of security systems and security configuration administration to reduce risk to enterprise systems and accounts.

+ Deploy strong identity and access management (IDAM) controls across applications and computing environments.

+ Assist with development, maintenance and utilization of scripts (e.g., Python, Ruby, etc.) to support custom extract, transform load (ETL) tools with a security focus for data flow.

+ Attend regular technical project and implementation meetings and serve as the security consultant to help guide secure application and infrastructure configurations.

+ Actively monitor, assess and recommend tactical and strategic initiatives based on new and emerging threats posing risk to cloud computing environments.

+ Manage remediation efforts after security assessment findings outline weaknesses requiring attention.

+ Document, formulate and enforce areas of security improvement that balance risk with business operations and do not diminish efficiencies or innovation.

+ Stay apprised of current and proposed security changes impacting regulatory, privacy and security industry best practice guidance. Apply learned knowledge across key lines of business, including products, practices and procedures.

\#LI-LP1

\#LI-REMOTE

**Skills & Abilities**

+ Demonstrated ability to use cloud tools and automation technologies to support secure, efficient infrastructure and security operations.

+ Proficient in one or more: Bicep, AKS, Terraform, Kafka, Kubernetes, Helm, OpenShift, scripting (Python, JavaScript).

+ Proven use with zero trust network access, encryption, web application firewalls, data protection, vulnerability management, API security, IaC.

+ Proven ability to influence technical teams and business units and collaborate to reduce attack surface.

+ Knowledge in one or more: NIST 800-144, 800-171, CIS, CSA-CCM, ISO (27040, 27017, 27001).

+ Ability to document technical policies and controls

+ Strong knowledge of vulnerability management principles, methodologies, and best practices.

+ Ability to define, track, and report on key performance indicators (KPIs) and metrics to measure vulnerability management program effectiveness.

+ Experience automating asset inventory, vulnerability discovery, assessment, and reporting processes.

+ Ability to identify, assess, document, prioritize, and validate remediation of system and application vulnerabilities.

+ Knowledge of vulnerability assessment across applications, endpoints, databases, network infrastructure, mobile devices, and cloud environments.

+ Strong understanding of attack surface management, secure configuration practices, host hardening, and application hardening techniques.

+ Ability to prioritize remediation efforts based on vulnerability severity, exploitability, threat intelligence, and business risk exposure.

+ Experience maintaining vulnerability management documentation, policies, procedures, and remediation tracking records.

+ Ability to collaborate effectively with security engineering, security operations, infrastructure, IT operations, and development teams.

+ Strong understanding of change management processes and their impact on organizational security posture.

+ Ability to provide vulnerability-related guidance, training, and technical recommendations to stakeholders, developers, IT teams, and business leaders.

+ Experience conducting continuous asset discovery and monitoring remediation status across enterprise environments.

+ Ability to analyze emerging threats and recommend tactical measures to reduce attack surface and mitigate risk.

+ Experience supporting remediation efforts and validating security controls to address newly identified vulnerabilities and threats.

+ Ability to work in a collaborative purple-team environment with offensive security, defensive security, threat intelligence, risk management, and operations teams.

+ Strong analytical, problem-solving, and risk assessment skills with the ability to make sound remediation recommendations.

+ Ability to maintain and analyze inventories of internal and third-party assets, including vulnerability status, remediation recommendations, and overall security posture.

+ Excellent written and verbal communication skills with the ability to communicate technical security concepts to both technical and non-technical audiences.

+ Commitment to staying current on emerging threats, vulnerabilities, attack techniques, and cybersecurity industry trends.

**Qualifications**

+ Bachelor's degree.

+ 8 years of related experience.

+ Equivalent additional directly related experience will be considered in lieu of a college degree.

Domestic and/or international travel may be required. The frequency of travel is contingent on specific duties, responsibilities, and the essential functions of the position, which may vary depending on workload and project demands.

**Amount of Travel Required**

No Travel is required

**EEO Statement**

We attract the best people in the industry, supporting their efforts to learn and grow. We strive to create a challenging and progressive work environment. We provide career opportunities that span a variety of disciplines and geographic locations, with projects that our employees plan, design, build and operate as diverse as the needs of our clients. CDM Smith Inc. and its divisions and subsidiaries are an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, pregnancy related conditions, childbirth and related medical conditions, sexual orientation, gender identity or gender expression), national origin, age, marital status, physical or mental disability, veteran status, citizenship status, genetic information or any other characteristic protected by applicable law.

**Background Check and Drug Testing Information**

CDM Smith Inc. and its divisions and subsidiaries (hereafter collectively referred to as “CDM Smith”) reserves the right to require background checks including criminal, employment, education, licensure, etc. as well as credit and motor vehicle when applicable for certain positions. In addition, CDM Smith may conduct drug testing for designated positions. Background checks are conducted after an offer of employment has been made in the United States. The timing of when background checks will be conducted on candidates for positions outside the United States will vary based on country statutory law but in no case, will the background check precede an interview. CDM Smith will conduct interviews of qualified individuals prior to requesting a criminal background check, and no job application submitted prior to such interview shall inquire into an applicant's criminal history. If this position is subject to a background check for any convictions related to its responsibilities and requirements, employment will be contingent upon successful completion of a background investigation including criminal history. Criminal history will not automatically disqualify a candidate. In addition, during employment individuals may be required by CDM Smith or a CDM Smith client to successfully complete additional background checks, including motor vehicle record as well as drug testing.

**Massachusetts Applicants**

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

**Additional Pay Range Information**

CDM Smith is committed to fair and equitable compensation practices. This pay range is a good faith estimate representative of all experience levels for the geographic location assigned to the position. In addition to geographic location, a candidate’s salary is determined by several other factors including, but not limited to, the role, function and associated responsibilities, relevant work experience, skills, required certifications, and education/training.

**Additional Compensation**

All bonuses at CDM Smith are discretionary and may or may not apply to this position.

**Visa Sponsorship Available**

No-We will not support sponsorship in the United States, i.e. H-1B or TN Visas for this position

**Agency Disclaimer**

All vendors must have a signed CDM Smith Placement Agreement from the CDM Smith Talent Acquisition Manager to receive payment for your placement. Verbal or written commitments from any other member of the CDM Smith Inc. and its divisions and subsidiaries staff will not be considered binding terms. All unsolicited resumes sent to CDM Smith Inc. and its divisions and subsidiaries and any resume submitted to any employee outside of CDM Smith Talent Acquisition Team will be considered property of CDM Smith. CDM Smith Inc. and its divisions and subsidiaries will not be held liable to pay a placement fee.

**Pay Range Max**

USD $214,510.00

**Pay Range Min**

USD $122,595.00


Similar jobs

Cyber Engineer

Full time
Fayetteville, AR

Published on 09/22/2026

Share this job now

Similar jobs