Zermount, Inc.

Emerging Technology/ Cybersecurity Engineer

Zermount, Inc.
2 - 5 years
Arlington, VA
Full-time
Hybrid
1 month ago

About the role

Company Description
Zermount, Inc., a Certified Service-Disabled Veteran-Owned Small Business (SDVOSB), specializes in Cybersecurity, Information Assurance, and IT consulting for both federal and commercial markets. Founded by Terry Butler, a seasoned leader with over 15 years of experience, Zermount is committed to providing innovative and sustainable solutions that empower clients to excel while protecting them from security vulnerabilities. The company emphasizes tailored strategies, forward-thinking professionals, and strong client partnerships to enhance operational efficiency, reduce costs, and drive innovation. Leveraging proven methodologies and leadership, Zermount delivers reliable solutions to address complex challenges in an ever-evolving technological landscape.
POSITION OVERVIEW
The Emerging Technology / Cybersecurity Engineer will support Zermount and our federal client in modernizing cybersecurity authorization, cloud security, security architecture review, and emerging technology assessment processes. This is a senior, client-facing cybersecurity engineering and assessment role focused on helping the client securely adopt SaaS, AI-enabled technologies, cloud services, and other emerging capabilities. The position blends federal RMF and continuous ATO expertise, security architecture review, AI security testing, cloud compliance, control validation, and process modernization. The successful candidate will help reduce authorization timelines by developing reusable security patterns, repeatable assessment baselines, structured test plans, and continuous ATO ready evidence. The ideal candidate has strong experience in federal cybersecurity, RMF, ATO, cloud security, security architecture, SaaS/product assessments, vulnerability management, emerging technology risk, and AI security This position requires a hands-on professional who can work across cybersecurity, engineering, procurement, legal, privacy, records management, vendor, product, and mission teams to evaluate technologies, validate controls, document risk, and accelerate secure adoption.
DUTIES & RESPONSIBILITIES
Security Architecture Review
• Conduct Security Architecture Reviews for SaaS, cloud, AI-enabled tools, non-COTS technologies, embedded AI capabilities, operating system baselines, and supporting infrastructure.
• Integrate architecture review activities with existing cybersecurity workflows, including ATO intake, security assessment, vulnerability scanning, cloud compliance, change management, and authorization decision support.
• Review system designs, data flows, identity models, access controls, logging approaches, network architecture, tenant isolation, administrative control structures, and security boundary assumptions.
• Develop security architecture patterns and reusable designs that enable faster assessments and ATO decisions by aligning solutions with federal security controls early in the lifecycle.
• Translate technical architecture findings into actionable risk statements, control recommendations, remediation plans, POA&Ms, and acceptance decision inputs. Emerging Technology Assessment and AI Security Testing
• Perform cybersecurity assessments of commercial SaaS products, non-COTS AI products, embedded AI components, cloud-hosted services, operating system baselines, and related technologies during intake and change events.
• Evaluate AI-specific threats and vulnerabilities, to include direct, indirect, and instruction smuggling prompt injection, jailbreak susceptibility, data leakage/sensitive data exposure, model poisoning, RAG/vector database exposure, unintended model behavior, tool or agent misuse, insecure plugin use, and unsafe browsing capabilities.
• Execute structured AI and emerging technology testing, including functional and accuracy testing, adversarial testing, data exfiltration probes, red-team scenarios, control regression testing, and validation of previously accepted security controls.
• Develop structured AI test cases, adversarial prompts, expected results, pass/fail criteria, scoring rubrics, and repeatable evaluation scripts aligned to NIST AI RMF, OWASP Top 10 for LLM/GenAI, MITRE ATLAS, client security baselines, and federal ATO acceptance criteria.
• Validate logging coverage, DLP efficacy, safety controls, accuracy thresholds, telemetry availability, and technical acceptance criteria prior to production use.
• Document findings, support remediation planning, and perform retesting to verify closure of identified security gaps.
PREFERRED QUALIFICATIONS:
• Experience assessing AI-enabled technologies, machine learning platforms, generative AI tools, RAG architectures, vector databases, AI agents, or commercial AI SaaS products.
• Knowledge of AI security risks, including prompt injection, jailbreaks, model misuse, data leakage, training data exposure, adversarial testing, tool/agent misuse, and AI governance.
• Experience with continuous ATO, ongoing authorization, automated evidence collection, cybersecurity authorization modernization, or continuous monitoring.
• Experience with cloud environments such as AWS, Azure, or Google Cloud Platform.
• Experience with DevSecOps, CI/CD security, Infrastructure as Code, container security, or cloud-native security controls.
• Experience integrating security telemetry into SIEM, SOAR, GRC, vulnerability management, or continuous monitoring platforms.
• Familiarity with security tools such as Splunk, Microsoft Sentinel, QRadar, Tenable, Security Hub, Defender, Prisma Cloud, ServiceNow, or similar platforms.
• Experience with AI/LLM evaluation, red-teaming, guardrail, or model-security testing tools such as Microsoft PyRIT, NVIDIA Garak, Promptfoo, DeepEval, OpenAI Evals, Azure AI Foundry Evaluation, Amazon Bedrock Guardrails, Google Vertex AI Evaluation, Lakera Guard, HiddenLayer, Protect AI ModelScan/Guardian, or equivalent tools.
• Experience developing reusable security baselines, control templates, architecture patterns, runbooks, assessment playbooks, and technical acceptance criteria.
EDUCATION
• Bachelor of Science (or higher) in one of the following: Computer Science, Information Technology, Cybersecurity, Engineering, or equivalent.
CERTIFICATIONS
At least one of the following certifications is required: • GIAC Certified Incident Handler (GCIH); Security+; Certified Information Security Manager (CISM), Certified in Governance of Enterprise IT (CGEIT); Certified Information Systems Security Professional (CISSP); Certified Information Security Auditor (CISA); Certified Cloud Security Professional (CCSP); AWS Certified Security Specialist; Microsoft Certified: Cybersecurity Architect Expert; Microsoft Azure Azure Security Engineer Associate; or another equal GIAC certification related to cloud, incident response, security engineering, or penetration testing.
CLEARANCE LEVEL
• Public Trust, but an active Secret Clearance is preferred.
WORK LOCATION
• Primary location(s) are Arlington and Alexandria VA. Remote work is authorized, but the employee may have to report to one of the primary sites occasionally or as requested by management or the client.

Skills

Information TechnologyComputer and Network Security
See more jobs in Arlington, VA