About this role
Wireless and Edge Infrastructure Cybersecurity Engineer
The Opportunity:
Are you driven by relentless curiosity and a passion for securing systems that have never been built before? Does the convergence of wireless networking and AI infrastructure excite you? We are seeking a cybersecurity engineer who can harden, assess, and defend a lab-built system from the server BIOS up through the radio, and who is ready to turn that work into the security baseline for a platform that will be deployed, loaned, and demonstrated across government sites.
You will work in a hands-on lab environment where new hardware arrives, gets stood up, gets broken, and gets rebuilt on tight timelines ahead of demos, pilots, and stakeholder reviews. If you enjoy owning security end-to-end on a small, fast-moving team, and want to shape how next-generation wireless and edge AI systems are secured for the mission, we want to hear from you.
What You’ll Work On:
- Own security hardening of the lab platform end-to-end, including GPU-accelerated servers, network switches, radio units, management interfaces, and the Kubernetes and virtualization layers that run on them.
- Apply and verify defense STIGs and CIS benchmarks on Ubuntu hosts, Kubernetes, hypervisors, and network devices.
- Track findings to closure and maintain hardening evidence.
- Design and implement network segmentation and access control across management, control, user, and timing planes, including VLAN isolation, ACLs, and TLS on all management interfaces.
- Build and operate vulnerability management for the lab, including Nessus or ACAS scanning, patch cadence, and remediation tracking for hosts, containers, and firm ware.
- Perform security assessments of wireless and core network components, including protocol analysis of signaling and user-plane traffic via Wireshark and system logs, and brief findings to engineering and leadership.
- Prepare and maintain RMF artifacts and supporting documentation for an Authority to Operate ( ATO ) , including system security plans, control implementation statements, and POA & Ms.
- Secure identity, credential, and secrets management for the platform, including the PKI and certificate lifecycle, SSH key management, service accounts, and privileged access to BMC or IPMI and switch consoles.
- Implement logging and monitoring, including centralized syslog, host and container tele met ry, and alerting for security- relevant events across the stack.
- Define the shipping and field security posture for a system that is loaned to government sites, including device encryption, baseline integrity verification, and secure teardown and re-image procedures.
- Write Met hod of Procedure ( MOP ) , SOP, and security configuration guides concurrently with lab work so the hardened build is reproducible by other teams.
- Collaborate with network, RF, and sof tware engineers to translate mission and sponsor security requirements into working configurations without blocking delivery timelines.
Join us. The world can't wait.
You Have:
- Experience hardening Linux systems to STIG or CIS benchmarks, including evidence collection and remediation
- Experience securing virtualized and containerized environments, including Kubernetes, Docker, and hypervisors such as Proxmox, VMware, or KVM
- Experience with network security on Layer 2 or Layer 3 infrastructure, including VLAN segmentation, ACLs, 802.1X, firewalls, and TLS or PKI for management traffic
- Experience with the DoD Risk Management Framework ( RMF ) , NIST SP 800-53 controls, and preparing artifacts for an ATO
- Experience with vulnerability scanning and management tools such as Nessus or ACAS, and interpreting scan results in a mixed hardware and sof tware environment
- Ability to read packet captures such as Wireshark or tcpdump, and system logs to investigate protocol-level and host-level security issues
- Ability to work hands-on in a fast-paced lab environment with hard delivery deadlines, triage issues independently, and produce clear, accurate technical documentation under time pressures
- Ability to obtain a Secret clearance
- Bachelor's degree in CS, Cybersecurity, Electrical Engineering, or Computer Engineering and 5+ years of experience with cybersecurity engineering, or 9+ years of experience with cybersecurity engineering in lieu of a degree
- Ability to obtain a Security+ CE or DoD Baseline Certification within 6 months of start date
Nice If You Have:
- Experience securing wireless or cellular infrastructure, including radio access networks, packet cores, or private LTE or 5G systems, and with their signaling and user-plane protocols
- Experience with open RAN architectures and the security guidance published for them, including interface-level threats across management, control, user, and timing planes
- Experience with Zero T rus t architectures, NAC platforms such as Aruba ClearPass or Cisco ISE, and SIEM or log analytics platforms such as Splunk or Elastic
- Experience securing GPU-accelerated or edge AI platforms, including NVIDIA Container Toolkit, GPU operator, driver and firm ware integrity, and model or inference service exposure
- Experience with precision timing security, including PTP or GNSS spoofing or jamming risks and mitigation, security automation and Infrastructure-as-Code, including Ansible or scripted STIG compliance in Python or Bash, and SIM or eSIM provisioning security, including Ki or OPc handling and SM-DP+ platforms
- Experience supporting DoD research, test, or evaluation programs, including sponsor reporting and demonstrations at government venues
- Experience with CBRS or SAS, or federal spectrum coordination
- Possession of excellent written and verbal communication skills, to brief both engineers and senior stakeholders
- Secret clearance
- CISSP, CCSP, GICSP, or Certified Kubernetes Security ( CKS ) Certification
Clearance:
Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information.
Compensation
At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.
Salary at Booz Allen is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $86,900.00 to $198,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen’s total compensation package for employees. This posting will close within 90 days from the Posting Date.
Identity Statement
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.
Candidate AI Usage Policy
AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided .
Work Model
Our people-first culture prioritizes the benefits of collaboration. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings.
- Remote : If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility.
- Hybrid : If this position is listed as hybrid, you will be expected to work from a Booz Allen or customer facility, in alignment with your leadership's expectations and the needs of the role.
- Onsite : If this position is listed as onsite, work will primarily be performed full-time at a customer facility, where employees will collaborate directly with colleagues and customers as required by the role.
Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.