Senior Security Engineer

Gormat, LLC
United States
9 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Amazon Web Services Microsoft Azure Cloud Computing Security Configuration Management Encodings Cyber Security Information Systems System Configuration Continuous Integration DevOps Multi-Factor Authentication
+40 more
Elasticsearch Github Information Technology Operations Intrusion Detection Systems Information Systems Security Architecture Professional Information Systems Security Engineering Professional Python (Programming Language) Network Security OAuth Public Key Infrastructure Windows PowerShell Systems Development Life Cycle Comptia Pentest+ CE Ansible Kusto Query Language Security Assertion Markup Language (SAML) Security Information and Event Management Systems Integration Software Vulnerability Management Circleci Data Logging Scripting Cloud Platform System Data Ingestion Multi-Cloud Azure Powershell Cyber Threat Analysis SC Clearance Gitlab-ci Kubernetes Information Technology Patch Management Bitbucket Cyber Warfare Splunk Webhooks Security Orchestration, Automation & Response Jenkins Servicenow Vulnerability Analysis

Job description

The Senior Security Engineer plays a critical role in designing, implementing, and maintaining the security infrastructure of the organization. This position is responsible for ensuring the confidentiality, integrity, and availability of enterprise systems and data across on-premises and cloud environments., This role collaborates closely with IT Operations, SOC Analysts, Vulnerability Management teams, Engineering, DevOps, and leadership to align security initiatives with business and mission requirements. By leveraging automation, secure design, and defensive strategies, the Senior Security Engineer ensures robust protection against evolving threats while maintaining compliance with federal and industry standards., * Provide architectural and design oversight to ensure enterprise security requirements are met across all systems.

  • Serve as a Subject Matter Expert on enterprise security architecture and ensure designs align with mission, business, and compliance requirements.
  • Translate organizational security goals into technical requirements for infrastructure and applications.
  • Evaluate enterprise cybersecurity architecture effectiveness and recommend improvements.
  • Oversee the deployment, configuration, and management of enterprise security platforms, including SIEM, IDS/IPS, logging, UAM, EDR, SOAR, Elastic Search, and encryption technologies.
  • Assess, test, select, and integrate security tools with an emphasis on scalability and automation.
  • Conduct security testing and evaluation for new platforms and integrations.
  • Perform vulnerability scanning, analysis, and reporting to identify enterprise security weaknesses.
  • Recommend mitigations and track remediation efforts across teams.
  • Ensure effective system hardening, patch management, and configuration management practices.
  • Collaborate with SOC and Incident Response teams to triage, investigate, and mitigate threats.
  • Identify anomalous activity and potential threats using logs, network data, and defensive tools.
  • Develop and refine content for SIEM and cyber defense platforms.
  • Create dashboards and reports that improve visibility into the organization’s security posture.
  • Build and maintain automated scripts and processes for monitoring, alerting, and remediation.
  • Perform health checks on systems, applications, and security services to ensure availability.
  • Recommend emerging technologies to improve detection and response capabilities.
  • Oversee enterprise ICAM implementations, including multi-factor authentication and least privilege models.
  • Provide expertise on authentication and authorization protocols such as SAML, OAuth2, and PKI.
  • Ensure compliance with NIST, ISO 27001, FedRAMP, HIPAA, and other applicable frameworks.
  • Develop and enforce security policies, STIGs, and hardening guidelines.
  • Provide documentation, audit support, and compliance reporting to leadership.
  • Collaborate with developers and system architects to integrate security into the systems development lifecycle.
  • Conduct security reviews, testing, and evaluations during system development and release cycles.
  • Maintain protected repositories of technical documentation, artifacts, and system configurations.
  • Provide training and security awareness sessions for technical teams and stakeholders.
  • Collaborate with IT, DevOps, and Engineering teams to integrate security into daily operations.

Requirements

The ideal candidate possesses deep expertise in cybersecurity threats, tools, and frameworks and has the ability to develop and oversee enterprise-level defenses that mitigate risk and improve the organization’s security posture. The Senior Security Engineer works across multiple domains, providing architectural oversight, embedding security into the systems development lifecycle, reviewing code and scripts, testing security implementations, and managing the deployment and optimization of security platforms., * Bachelor’s degree in Information Technology, Cybersecurity, Data Science, Information Systems, Computer Science, or a related field from an ABET-accredited or CAE-designated institution.

  • Minimum of six (6) years of experience in Information Technology (IT) and/or Information Security (IS).
  • Must possess at least one DoD 8140 certification applicable to the role or obtain certification within six (6) months of onboarding.
  • Must maintain required DoD 8140 certification(s) throughout employment.
  • Must be able to successfully complete a DEA background investigation.
  • Must possess an active Secret clearance (or higher) and be eligible to obtain a Top Secret clearance if required.
  • Preferred Qualifications
  • Advanced certifications aligned with DCWF Roles 521, 461, 651, or 622, including:
  • ISC2: CISSP-ISSAP, CISSP-ISSEP, CCSP, CSSLP, SSCP
  • EC-Council: CEH
  • GIAC: GCIA, GCLD, GICSP, GCSA, GSNA, GDSA, GFACT, GISF, GSEC
  • CompTIA: CySA+, PenTest+, Security+, SecurityX/CASP+
  • In-depth knowledge of SIEM platforms, scripting languages (Python, SPL, KQL), network security, and threat intelligence.
  • Hands-on experience with Splunk, Elastic Search, and ServiceNow.
  • Experience with APIs, webhooks, and custom queries for data ingestion.
  • Strong cloud security experience in multi-cloud enterprise environments (AWS and/or Azure).
  • Experience migrating applications to cloud environments and implementing cloud security controls.
  • Experience across the DevOps lifecycle, including orchestration, configuration management, CI/CD, monitoring, and security.
  • Experience using automation and orchestration technologies such as GitHub Actions, Jenkins, CircleCI, Ansible, Azure DevOps, GitLab CI, and Bitbucket Pipelines.
  • Scripting and automation experience using PowerShell, Azure CLI, or similar technologies.

Must have an ACTIVE Secret Clearance and be eligible for a Top-Secret Clearance. ***This position is primarily remote (approximately 95%), with occasional onsite requirements as needed.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · WWC 2023

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

Videos

See all

Related articles

See all