This is a remote position.
Position Overview:
We are offering an exciting opportunity for a Security Engineer with expertise in NIST 800-53 security controls and a strong technical background in risk and vulnerability management. The ideal candidate will play a crucial role in implementing security controls, assessing vulnerabilities, and ensuring compliance with federal cybersecurity frameworks such as FISMA, FedRAMP, and RMF.
Key Responsibilities:
- Develop, assess, and document System Security Plans (SSPs), Plan of Action and Milestones (POA&Ms), and Risk-Based Decisions (RBDs).
- Collaborate with developers and technical staff to guide the proper implementation of each security control family.
- Collect, organize, and submit evidence for Security Control Assessments (SCAs).
- Possess technical expertise in security technologies such as encryption methods, IAM concepts, and technologies like SAML, OIDC, SSO, and MFA.
- Experience with SIEM technologies (e.g., Splunk) and other monitoring tools.
- Identify and remediate vulnerabilities through risk and vulnerability management.
- Work across teams and with external customers to develop security strategies, design solutions, and provide guidance during deployment.
Required Qualifications:
- At least 8 years of experience in the Information Technology field with increasing responsibility.
- A minimum of 5 years of experience in Information Security solutions.
- Relevant security certifications (e.g., CISSP, CCSP, CEH).
- Deep understanding of NIST 800-53, RMF, FedRAMP, FISMA, and other federal security standards.
- Knowledge of system security vulnerabilities and effective remediation techniques.
- Familiarity with networking concepts, including subnetting, routing, VPC / VNet, security groups, load balancing, etc.
- Experience with microservices-based architectures and designing security solutions for multi-tenant applications, using containerization and orchestration tools like Docker and Kubernetes (highly desirable).
- Hands-on experience supporting security for AWS cloud platforms (highly desirable).
- Candidates must be U.S. Citizens or Legal Permanent Residents (Green Card holders) for at least 3 years and be Federal Tax compliant.
