> Markdown version of [/jobs/ext/2633569-information-security-sr-principal-azure-security-senior-engineer](https://www.wearedevelopers.com/jobs/ext/2633569-information-security-sr-principal-azure-security-senior-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Sr. Principal (Azure Security Senior Engineer) - **Company:** General Dynamics Information Technology - **Location:** Washington, DC, United States - **Experience:** Expert - **Salary:** $148,750.0 - $201,250.0 - **Contract:** Permanent contract - **Skills:** Agile Methodology, Microsoft Antivirus, Microsoft Azure, Cloud Computing, Cloud Computing Security, CompTIA Security+, Cyber Security, Information Systems, Network Security, Package Development Process, Smartsuite, Security Content Automation Protocol, Security Information and Event Management, Software Vulnerability Management, Data Logging, SC Clearance, Microsoft Sentinel, Data Management, CIS Benchmarks, Devsecops, Key Vault, Plan of Action and Milestones - **Published:** August 21, 2026 - **Apply:** https://dejobs.org/x/x/BCD6AD8F742E4E10800AB8F6F154311A/job/ ## About the Role Microsoft Azure,Plan of Action and Milestones (POA&M),Security Vulnerability Assessments Experience: 10 + years of related experience, * Microsoft Azure Security Stack (Sentinel, Defender, Auditing) * RMF for classified systems/applications * Plan of Action & Milestones (POA&M) management * Experience with GRC tools (CSAM, eMASS) Requirements & Qualifications: * Bachelor's degree in Information Systems Security, IT, or Networking * Active Secret clearance * 5+ years of cloud security experience, including 2+ years in Azure Government or DoD environments * Strong knowledge of Azure-native security tools, IL6 data-handling, cloud networking, and architectural validation * Experience with DoD SRG/STIG/CIS Benchmarks * Hands-on experience with classified enclaves, hardened images, and enclave-to-enclave connectivity * Deep experience with auditing, logging, vulnerability management, and secure configuration management * Strong communication skills; customer-facing experience * Knowledge of Agile software development * Secret clearance required for start Required Technical Skills: * SCAP, STIGs, patching, eMASS, and related RMF tools * Cybersecurity and A&A package development * Experience obtaining ATOs and navigating the assessment/authorization process * Experience across cybersecurity, information security, and IT security protocols and procedures Experience: * 5 years of relevant experience ( may vary based on training, certifications, or degree ) * Cloud security experience (Azure Government) and SIPRNet exposure * Experience with internet, web, application, and network security techniques * Experience working in federal environments * Ability to work independently and remotely Certification Requirements: * Active DoW 8570 IAT Level II/III (Security+, CISSP, CISM) ## Description * Configure and manage security controls, auditing, logging, vulnerability management, and CONMON activities across Microsoft Defender, Key Vault, Azure Policy, and other Azure security services * Provide guidance for SIEM/SOAR integrations (e.g., Microsoft Sentinel IL6) for monitoring, logging, and incident response * Support engineering teams in implementing remediations aligned with NIST 800-53, DoD STIGs/SRGs, and CIS Benchmarks * Collaborate with mission owners, compliance teams, and developers to ensure secure DevSecOps pipelines * Support ATO processes by developing security documentation, gathering control evidence, and assisting with audits * Navigate federal systems through the authorization process to achieve and maintain ATO * Work closely with Program and DOC ITD IA teams to maintain required security authorizations * Develop System Security Plans (SSPs) documenting implementation of NIST 800-53 Rev 5 and overlay controls * Coordinate with third-party assessors for security assessments * Manage POA&Ms to address identified vulnerabilities * Ensure continuous monitoring plans meet agency requirements * Prepare authorization packages for government review * Maintain compliance through established change-management processes * Serve as liaison between technical teams and authorizing officials * Translate security requirements into actionable technical tasks * Ensure all documentation meets federal information system requirements ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Best Practices for Using GitHub Secrets](https://www.wearedevelopers.com/videos/1214-best-practices-for-using-github-secrets) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)