Security Engineer

IBSS Corp.
Washington, DC, United States
6 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Azure Cloud Computing Security Cloud Engineering Cyber Security Software Design Documents Network Segmentation Role-Based Access Control Azure Active Directory Zero Trust Network Access Software Requirements Analysis SARS Software Products SC Clearance
+2 more
Azure AKS Vulnerability Analysis

Job description

IBSS is seeking a Senior Security Engineer to support a Federal customer. This position develops, enhances, and maintains Security Operations Center (SOC) processes and standard operating procedures, performs vulnerability analysis and hands-on security testing, and leads the engineering and implementation of secure cloud solutions, primarily in Microsoft Azure, in alignment with the customer’s cybersecurity strategy and federal compliance mandates (NIST, FISMA, FedRAMP). The Senior Security Architect works alongside the Cyber Security SME, ISSOs/Security Assessors, and customer leadership to sustain a strong security posture., * Develop, enhance, and maintain Security Operations Center (SOC) standard operating procedures (SOPs) and assessment operations processes.

  • Ensure accountability, integrity, confidentiality, and protection of operational security processes and data.
  • Perform vulnerability analysis, review program-level documentation (system requirements, architectures, design documents, test plans, security plans), and provide technical recommendations.
  • Develop and document security evaluation plans, test procedures, and assessment methodologies.
  • Conduct hands-on security testing, analyze results, identify risk, and recommend countermeasures.
  • Assess and calculate risk based on identified threats, vulnerabilities, and security control weaknesses.
  • Identify and document mitigation strategies for threats, vulnerabilities, and deficiencies.
  • Support the design, development, and implementation of security-related systems, tools, and assessment capabilities.
  • Participate in and/or lead technical exchange meetings, document action items and outcomes, and brief leadership on security engineering status and results.
  • Support SOC alert analysis, triage, escalation, containment actions, and continuous improvement of detection and response use cases.
  • Lead the engineering and implementation of secure cloud solutions - primarily in Microsoft Azure - in alignment with the customer’s cybersecurity strategy and federal compliance mandates (NIST, FISMA, FedRAMP).
  • Integrate Zero Trust security principles across Azure cloud environments, including identity hardening, micro-segmentation, conditional access, and continuous monitoring.
  • Configure and operationalize Azure cloud platform services, including:
  • Azure Kubernetes Service (AKS) secure cluster configuration, governance, and node-pool hardening
  • Azure Policy creation and enforcement
  • Secure Landing Zones following Azure enterprise-scale frameworks
  • Role-Based Access Control (RBAC) and least-privilege access models
  • Resource tagging, naming standards, and governance implementation

Requirements

  • Bachelor’s degree
  • Minimum of eight (8) years of cybersecurity experience.
  • CISSP or similar (CISM, CASP+, GSLC, etc.) recognized cybersecurity certification.
  • Cloud Architecture/Engineer or similar certification, preferably one (or more) of the following, * Demonstrated experience implementing and securing Azure cloud services, including AKS, Azure Policy, Azure AD/Entra, Conditional Access, RBAC, and Zero Trust controls.
  • Ability to evaluate security documentation and develop security test plans, evaluation methodologies, and technical recommendations.
  • Ability to coordinate across cybersecurity teams and communicate technical information to leadership.
  • Secret Clearance or higher required.

Desired Skills:

  • Experience supporting the Department of Commerce or another Federal Civilian Executive Branch (FCEB) agency’s cybersecurity or cloud security program.
  • Experience supporting Security Operations Center (SOC) alert triage, escalation, and incident containment activities.
  • Experience developing ATO/A&A documentation (SSPs, SARs, POA&Ms) within a NIST Risk Management Framework or FedRAMP environment.

Benefits & conditions

IBSS offers a competitive benefits package that includes medical, dental, vision, and prescription drug coverage with a company-paid deductible, paid time off, federal holidays, a matching 401K plan, tuition/professional development reimbursement, and Flex-Spending (FSA)/Dependent Care Account (DCA) options.

About the company

Since 1992, IBSS, a woman-owned small business, has provided transformational consulting services to the Federal defense, civilian, and commercial sectors. Our services include cybersecurity and enterprise information technology, environmental science and engineering (including oceans, coasts, climate, and weather), and professional management services.

Our approach is to serve our employees by investing in their growth and development. As a result, our employees bring greater capabilities and provide exceptional service to our clients. In addition to creating career development opportunities for our employees, IBSS is passionate about giving back to the community and serving the environment. We strive to leave something better behind for the next generation.

We measure our success by the positive impact we have on our employees, clients, partners, and the communities we serve. Our tagline, Powered by Excellence, is a recognition of the employees that make up IBSS and ensures we deliver results with quality, applying industry best practices and certifications.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

5:01 min

Container hosting options available on Microsoft Azure

Federico Fregosi · World Congress 2022

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:46 min

Evaluating managed container services and migration strategies

Adam Bien · World Congress 2021

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all