Role OverviewWe are seeking an experienced Lead Security Engineer to design, implement, and lead cybersecurity engineering for a secure, on-premises Federal data, analytics, and AI platform. The Lead Security Engineer will translate Federal security requirements into practical technical controls and engineering patterns while ensuring those controls are implemented, tested, monitored, and supported.
What You Will Do
Translate FISMA Moderate and NIST SP 800-53 Rev. 5 requirements into actionable technical controls and evidence. Support Risk Management Framework activities, security planning, control implementation, assessment readiness, and remediation tracking.
Why It Might Be a Fit
The Lead Security Engineer will work with a diverse team of professionals to solve matters, architect nuisances, and come up with alternatives. We offer competitive compensation with opportunities for bonuses, employer-paid healthcare, training and development funds, and 401k match.
Requirements
- 8+ years of experience in cybersecurity engineering, security architecture, information assurance, or a related field.
- Demonstrated experience designing and implementing security controls for Federal information systems, preferably in FISMA/RMF environments.
- Strong knowledge of FISMA, NIST SP 800-53 Rev. 5, RMF, and secure software development/DevSecOps.
- Experience securing enterprise infrastructure, applications, databases, APIs, networks, and on-premises or hybrid platforms.
- Hands-on experience with Linux, Docker/containerization, and Kubernetes and/or Rancher.
- Experience implementing IAM, RBAC, privileged access, authentication, authorization, encryption, certificates, secrets, and key-management controls.
- Experience with vulnerability management, security scanning, patching, configuration management, and remediation.
- Experience integrating security into CI/CD pipelines, preferably with Jenkins and/or self-hosted Azure DevOps.
- Understanding of application security, including SAST/SCA/DAST, dependency management, container security, secrets detection, and secure API design.
- Experience with security logging, monitoring, alerting, audit trails, and incident response.
- Experience supporting security assessments, audits, POA&Ms, vulnerability assessments, and continuous monitoring.
- Ability to conduct threat modeling and evaluate security risks associated with new technologies and architectures.
- Strong technical documentation, communication, and problem-solving skills.
- Ability to collaborate across platform, infrastructure, application, data, AI/ML, DevOps, and Government teams.
- U.S. citizenship and ability to obtain and maintain Top Secret eligibility, as required for contractor personnel supporting the effort. Active Top Secret clearance highly preferred.
Benefits
- Competitive compensation
- Opportunities for bonuses
- Employer-paid healthcare
- Training and development funds
- 401k match
]]>