> Markdown version of [/jobs/ext/1283494-information-security-engineer](https://www.wearedevelopers.com/jobs/ext/1283494-information-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Engineer - **Company:** Nightwing Intelligence Solutions, LLC - **Location:** Sterling, VA, United States - **Experience:** Expert - **Salary:** $122,000.0 - $253,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Amazon Web Services, Amazon Elastic Compute Cloud, Amazon S3, Software System Penetration Testing, Audit Trail, Ubuntu (Operating System), CentOS, CompTIA Security+, Cyber Security, Identity and Access Management, Intrusion Detection and Prevention, Network Security, Nmap, Public Key Infrastructure, Red Hat Enterprise Linux, Cloud Services, Security Information and Event Management, Software Vulnerability Management, Scripting, Cloud Platform System, Software Security, Malware, Amazon Virtual Private Cloud (VPC), Information Technology, Cybercrime, Nessus, Cloudwatch, Splunk, Devsecops, Security Orchestration, Automation & Response, Vulnerability Analysis - **Published:** July 15, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=2e1d84b3d33ceabc ## About the Role * U.S. Citizenship * Must have an active TS/SCI clearance * Must be able to obtain DHS Suitability * 5+ years of experience in information security, preferably in cloud environments * Strong knowledge of AWS security services and best practices * Experience with security monitoring and SIEM tools * Understanding of encryption, PKI, and data protection technologies * Knowledge of federal security compliance requirements (FISMA, FedRAMP, NIST 800-53) * Experience with AWS EC2/S3/VPC deployment and configuration, Cloudtrail, Cloudwatch, AWS Security Hub * Experience with Nmap, Nessus, Splunk Administration/Configuration * Linux/Unix System Administration (Alma9, RHEL, CentOS, Ubuntu from most to least) * Experience/knowledge with NIST, STIG, ATO, SOC, or system hardening experience * Experience with vulnerability management and penetration testing * Strong understanding of network security principles * Experience with security automation and scripting * Relevant security certifications (CISSP, Security+, CCSP, or similar) Desired Skills: * Experience supporting incident response or threat hunting operations * Knowledge of container and Kubernetes security * Experience with infrastructure-as-code security scanning * Familiarity with STIG implementation and compliance automation * Background in forensics or malware analysis * Experience with cloud security posture management tools * Knowledge of DevSecOps practices and tools Required Education: * Bachelor's degree in Cybersecurity, Computer Science, or related field, or High School diploma and 7+ years of directly relevant experience Desired Certifications: * AWS Certified Security - Specialty * DoD 8140 IAT Level 3 ## Description Nightwing is supporting a U.S. Government customer to provide rapid deployment and management of secure cloud-based engagement kits for cyber incident response and threat hunting operations. As part of the Engagement Support Services (ESS) contract, this program enables analysts to quickly access the tools and environments they need to investigate cyber threats affecting federal agencies, state and local governments, and critical infrastructure. Working on this team means directly supporting the nation's cybersecurity defenders by ensuring they have reliable, scalable, and secure cloud infrastructure available within hours of a cyber incident-helping protect America's digital infrastructure when it matters most. The Information Security Engineer will ensure the security, compliance, and resilience of Bespin cloud engagement kits throughout their lifecycle. This position is responsible for implementing security controls, conducting continuous monitoring, managing vulnerabilities, and ensuring adherence to federal security requirements and best practices. Responsibilities: * Implement and maintain security controls for cloud engagement infrastructure * Enforce encryption standards (TLS 1.2/1.3) and hardened cloud configurations * Conduct continuous security monitoring and threat detection * Manage vulnerability assessment and remediation processes * Implement namespace obfuscation and data protection measures * Ensure compliance with federal security frameworks (NIST, FedRAMP, etc.) * Conduct security reviews of engagement kit configurations and deployments * Coordinate incident response activities related to security events * Develop and maintain security documentation and standard operating procedures * Perform security assessments of third-party cloud services and dependencies * Implement and manage identity and access management controls * Monitor for and respond to potential security incidents or anomalies * Support security aspects of engagement kit decommissioning and data sanitization * Provide security guidance and training to operations teams ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)