2

Full Time Federal Cybersecurity Jobs (NOW HIRING)

Cyber Architect III

Springfield, VA ยท On-site

$150K - $155K/yr

Provide thought leadership on federal cybersecurity policy, NIST Cybersecurity Framework (CSF) 2.0 ... Paid Time Off (PTO) is offered to regular full-time and part-time employees. Company Description ...

Senior ISSO

Mclean, VA ยท On-site

The ideal candidate possesses advanced knowledge of federal cybersecurity standards, hands-on ... to full time employees, including a Health Savings Account (HSA) option as well as two tiers of ...

... Full time benefits include Medical, Dental, Vision, 401K and other possible benefits as provided ... Support federal staff by providing expertise/training to Reclamation ISSOs and advising on RMF ...

Showing results 41-60

Full Time Federal Cybersecurity information

See salary details

$57K

$133K

$186K

How much do full time federal cybersecurity jobs pay per year?

As of Sep 2, 2026, the average yearly pay for full time federal cybersecurity in the United States is $132,962.00, according to ZipRecruiter salary data. Most workers in this role earn between $111,000.00 and $150,000.00 per year, depending on experience, location, and employer.

What is the difference between Full Time Federal Cybersecurity vs Full Time Federal Network Administrator?

AspectFull Time Federal CybersecurityFull Time Federal Network Administrator
CertificationsCompTIA Security+, CISSP, CEHCompTIA Network+, Cisco CCNA, Security+
Work EnvironmentGovernment agencies, federal IT security teamsGovernment agencies, federal IT infrastructure teams
Job FocusProtecting systems from cyber threats, incident responseManaging and maintaining network infrastructure, troubleshooting
Common TasksSecurity audits, vulnerability assessmentsNetwork configuration, hardware setup

Full Time Federal Cybersecurity roles focus on safeguarding federal systems from cyber threats, requiring security certifications and incident response skills. In contrast, Full Time Federal Network Administrators manage and maintain network infrastructure, emphasizing network configuration and hardware management. Both roles are essential in federal IT but differ in their primary responsibilities and skill sets.

How much does full time federal cybersecurity pay?

Full-time federal cybersecurity positions typically offer salaries ranging from approximately $70,000 to over $130,000 annually, depending on experience, education, and security clearance level. Entry-level roles may start lower, while senior positions or specialized roles with certifications like CISSP or CISA tend to pay higher. Benefits often include health insurance, retirement plans, and paid leave.

Which government job is best for full time federal cybersecurity?

The best full-time federal cybersecurity jobs include positions such as Cybersecurity Analyst, Information Security Specialist, and Cybersecurity Engineer within agencies like the Department of Homeland Security, NSA, or FBI. These roles typically require security clearances, relevant certifications like CISSP or Security+, and knowledge of tools such as firewalls, intrusion detection systems, and encryption protocols.

What cities are hiring for Full Time Federal Cybersecurity jobs?

Cities with the most Full Time Federal Cybersecurity job openings:

What are the most commonly searched types of Federal Cybersecurity jobs?

The most popular types of Federal Cybersecurity jobs are:

Senior Cybersecurity Engineer

Pueo Business Solutions LLC

Mclean, VA โ€ข On-site

$115K - $158K/yr

Full-time

Re-posted 18 days ago


Job description

Job Type
Full-time
Description
Pueo is known for bringing the best talent and unique tools to every opportunity. Pueo's Parliament (aka workforce) is composed of professionals who are seeking the opportunity to work in a business organization that thrives on career development and independence. In support of mission and professional growth, our Parliament has supported the development of multiple patents, proprietary tools, and applications as well as trademarked processes.
Our organization emphasizes career development across multiple career environments (at the members own pace) and ensures those who contribute broadly are properly rewarded. Pueo has four career environments where every member of the parliament can participate. Each environment has opportunities available for all levels. Opportunities are framed by an employee's desires and capabilities, and we ensure challenges, growth, and unique experiences are available for employees at all levels.
Our Career Environments (Program, Functional, Service, and Leadership) provide numerous opportunities for employees to invest in their personal growth and those things that offer fulfillment. We invest in helping our members create and execute their career development plans. Our Pods (small teams of 5 or less) are comprised of personnel with similar skillsets to ensure mentorship, understanding, and peer support.
OVERVIEW:
We are seeking a highly skilled Cybersecurity Engineer (CSE) with extensive experience in air-gapped and classified container platforms, CI/CD pipelines, security automation, and federal cybersecurity requirements. The ideal candidate will possess hands-on expertise in Kubernetes, OpenShift, registry management, security test automation, and the implementation of cybersecurity controls in compliance with federal standards like NIST 800-53, DISA STIGs, and RMF/ATO workflows.
A) Air-Gapped / Classified Container Platforms (Kubernetes/OpenShift/RKE2)
  1. Designing a Disconnected Cluster
    • Design and manage a multi-container OpenShift hosted platform in an air-gapped enclave.
    • Expertise in cross-domain CI/CD, blue-green testing, and platform deployment within disconnected environments.
    • Familiar with image/helm/chart mirroring, FIPS 140 validated crypto, OS hardening (e.g., Alpine), and SELinux enforcing.
  2. Registry and Artifact Governance
    • Maintain and govern a disconnected container registry, ensuring content sources, image signing, SBOMs, and vulnerability gating.
    • Familiarity with tools such as Cosign, Syft, Grype, Trivy, OCI level attestations, and curated repository promotions.
  3. Admission Control & Policy Enforcement
    • Enforce security baselines and policies without internet dependencies using tools like OPA Gatekeeper, Kyverno, and image provenance verification.
  4. Cluster Multi-Tenancy in SCIFs
    • Implement RBAC, namespace isolation, and mTLS for mixed-sensitivity workloads within a SCIF (Sensitive Compartmented Information Facility).
  5. Patching and CVE Response Offline
    • Manage critical Kubernetes CVEs in air-gapped enclaves through risk triage, change windows, and mirrored updates.

B) CI/CD & Security Test Automation (Disconnected)
  1. Pipeline Architecture for Classified Enclaves
    • Design CI/CD pipelines to build, test, sign, scan, and promote containers across Dev ? Test ? Prod in closed networks.
    • Familiarity with GitLab/Jenkins runners, artifact promotion, and "compliance as code" practices.
  2. Automated Security Testing Coverage
    • Implement automated tests for SAST, DAST, IAST, SCA, and IaC scanning within CI/CD pipelines.
    • Ensure pipeline failures persist if discrepancies are detected.
  3. Evidence Generation for RMF
    • Generate RMF/ATO evidence via automated pipeline outputs, mapping artifacts to NIST controls.
    • Knowledge of OSCAL output, control mappings, and integration with evidence stores like eMASS.
  4. Promotion Gates & Provenance
    • Ensure artifacts meet quality and security criteria (e.g., reproducible builds, signed/provenanced artifacts, passing STIG checks) before promotion to higher environments.
  5. Testing for Platform + App Security Regressions
  • Implement tests for platform upgrade regressions using tools like kube-bench, kube-hunter, and e2e integration suites.

C) Federal Cybersecurity Requirements (RMF/ATO, STIGs, CNSS, FedRAMP)
  1. RMF Tailoring in Containerized Systems
  • Tailor NIST 800-53 controls for microservices platforms, identifying platform vs. app team responsibilities.
  • Work with shared responsibility matrices and control inheritance catalogs.
  1. DISA STIG Application to Kubernetes Workloads
  • Apply and track Kubernetes/Docker/OpenShift STIG findings and exceptions.
  • Implement a "STIG as code" approach in CI/CD pipelines and perform continuous drift checks.
  1. Continuous Monitoring (CONMON)
  • Implement telemetry collection for CONMON using on-prem tools (e.g., Prometheus, Grafana, auditd, Falco).
  • Design and manage control dashboards and evidence snapshots.
  1. ATO Acceleration through Automation
  • Reduce ATO lead times using automated assessments, OSCAL generation, and integration with tools like eMASS.
  1. Policy Conflicts & Adjudication
  • Reconcile conflicts between NIST, CNSS, and program-specific directives, leveraging risk-based decision memos and compensating controls.

D) Networking, Identity & Zero Trust in On-Prem/Classified Enclaves
  1. Zero Trust in Kubernetes
  • Implement Zero Trust principles within Kubernetes beyond mTLS and RBAC, using tools like SPIFFE, SPIRE, and service mesh authZ.
  1. Offline PKI Operations
  • Manage certificate lifecycles in air-gapped environments, utilizing offline roots, short-lived certs, and mesh cert synchronization strategies.
  1. East-West Segmentation Strategy
  • Design and implement micro-segmentation and egress controls for multi-tenancy within classified environments.
  1. Identity Propagation Across Layers
  • Ensure identity propagation from build systems through runtime enforcement, using tools like Sigstore attestations and audit chain linking.
  1. Cross-Domain and Data Movement Patterns
  • Securely move artifacts across domains with tamper-evident transfer logs, hash-based validation, and offline review stations.

E) Operations, SRE & Incident Response in SCIFs
  1. Observability without SaaS
  • Build observability solutions for logs, metrics, traces, and capacity planning using on-prem tools like EFK, Prometheus, and Tempo.
  1. Break Glass & Change Control
  • Design a break-glass process with time-bound privilege elevation, session recording, and immutable logs.
  1. Forensics & Container Runtime
  • Collect forensic evidence from compromised container nodes while preserving data integrity through disk snapshots and isolated triage nodes.
  1. Resiliency & DR in Disconnected Sites
  • Develop strategies for service continuity across multiple isolated sites, including staged upgrades and backup/restore drills.
  1. Application Team & SOC Integration
  • Integrate containerized environments with enterprise SOC teams during incident detection, containment, and recovery.
  • Define roles, telemetry requirements, and communication channels for effective response.

REQUIRED QUALIFICATIONS:
  • 12 years of experience and a Masters degree. Degree can be substituted for 6 additional years of applicable experience
  • IAT/IAM Level 3 Certification in compliance with DoD 8570/8140 guidelines
  • Extensive experience working with Kubernetes, OpenShift, RKE2, and container registry management in air-gapped and classified environments.
  • Deep understanding of CI/CD pipeline architectures, especially in disconnected networks.
  • Expertise in federal cybersecurity frameworks, such as NIST 800-53, DISA STIGs, RMF, and ATO processes.
  • Familiarity with security testing tools (SAST, DAST, IAST, IaC) and automated compliance validation.
  • Proven track record of enforcing Zero Trust principles, PKI management, and network segmentation in a classified environment.
  • Strong ability to map pipeline artifacts to RMF/ATO controls and support security operations during incidents.
  • Extensive experience in cybersecurity design and architecture.

CLEARANCE:
  • Top Secret minimum

Pueo is an equal employment opportunity employer and affirmative action employer. All interested individuals will receive consideration and will not be discriminated against on the basis of race, color, religion, sex, national origin, disability, age, sexual orientation, gender identity, genetic information, or protected veteran status. Pueo takes affirmative action in support of its policy to advance diversity and inclusion of individuals who are minorities, women, protected veterans, and individuals with disabilities.