Security Engineer III
Role details
Job location
Tech stack
Job description
We are seeking a Senior Security Analyst to join a team of skilled professionals. The ideal candidate will play a pivotal role in safeguarding and strengthening the security posture of the ClaimsCore platform by performing comprehensive security analysis, vulnerability assessments, and compliance monitoring. This position will support ongoing system maintenance, platform enhancements, and major modernization activities by providing expert security guidance, reviewing configurations, and ensuring alignment with enterprise and federal security standards. The Senior Security Analyst will contribute directly to the reliability, resilience, and integrity of systems supporting federal health mission partners., * Performing security analysis, vulnerability assessments, and compliance monitoring for the ClaimsCore platform.
- Reviewing, interpreting, and validating security scan results from tools such as Tenable, Qualys, or similar enterprise vulnerability platforms.
- Prioritizing remediation efforts and tracking vulnerability resolution against established SLA timelines.
- Coordinating with development, operations, and infrastructure teams to ensure timely remediation and secure configuration management.
- Supporting internal and external audit activities, including evidence collection, control validation, and implementation of corrective actions.
- Reviewing system and application security configurations to ensure alignment with enterprise standards, NIST guidelines, and Zero Trust principles.
- Providing actionable security recommendations to technical teams and participating in design reviews for secure implementation of new features or system updates.
- Monitoring compliance with security policies, procedures, and regulatory requirements, and escalating deviations as appropriate.
- Assisting in the development and continuous improvement of security processes, documentation, and reporting dashboards.
- Supporting incident response activities by analyzing potential vulnerabilities, misconfigurations, and threat vectors relevant to the ClaimsCore environment.
Requirements
Education: A Bachelor of Science or Bachelor of Arts degree with 5 years of experience, a Master of Science or Master of Arts degree with 3 years of experience, or a PhD with 0 years of experience is required.
Experience: 5-8+ years of experience in security analysis, vulnerability management, or cybersecurity operations in a large enterprise or federal environment. Experience supporting compliance, audit activities, or regulatory requirements for federal or large enterprise systems is also required.
Technical Skills:
- Hands-on experience with vulnerability scanning platforms (e.g., Tenable.sc, Tenable Nessus, Qualys) and an understanding of CVE, CVSS, and vulnerability lifecycle processes.
- Demonstrated ability to analyze scan data, identify false positives, and translate technical findings into clear, actionable remediation tasks.
- Familiarity with security frameworks and standards including NIST 800-53, NIST CSF, RMF, and CIS benchmarks.
- A strong understanding of secure configuration principles for operating systems, cloud platforms, and application environments.
- Effective communication skills (verbal and written) with both technical and non-technical stakeholders.
- U.S. Citizenship may be required based on project needs., * Security-related certifications such as Security+, CySA+, GSEC, CEH, CISSP, CISM, or equivalent.
- Experience with cloud environments (AWS, Azure, or Google Cloud Platform) and associated security services or baseline configurations.
- Experience supporting large modernization efforts or legacy-to-cloud migrations.
- Knowledge of SIEM platforms, security automation workflows, and log analysis.
- Experience working in Agile or DevSecOps environments and providing security input throughout SDLC processes.
- Familiarity with federal healthcare systems or related compliance requirements.
- Experience generating security reports and presenting findings to leadership or program stakeholders.