System Engineer Sr Principal
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+32 more
Job description
security baselines across operating systems, applications, networks, and container platforms.Own the lifecycle of patch management (assessment, planning, testing, deployment, and verification) to ensure timely and compliant remediation of vulnerabilities.Maintain and harden virtual machine environments (e.g., cloud-native VMs), ensuring availability, performance, and security.Configure and maintain network devices (e.g., routers, switches, firewalls) in accordance with security policies, STIGs, and best practices.Deploy and maintain container platforms (e.g., Docker, Kubernetes/OpenShift) with a focus on secure configuration, image scanning, and vulnerability remediation.Integrate and leverage vulnerability scanning tools (e.g., Tenable, Qualys, Rapid7, ACAS) and configuration/compliance tools to identify, track, and remediate findings.Collaborate with cross-functional teams (cybersecurity, network engineering, systems administration, DevSecOps) to ensure cohesive and secure designs and
Requirements
operations.Participate in incident response and root cause analysis related to vulnerabilities, misconfigurations, and system security issues, driving corrective and preventive actions.Ensure solutions meet applicable contractual, regulatory, and compliance requirements (e.g., DoD directives, RMF/ATO, NIST SP 800-53).Required QualificationsActive DoD Security Clearance of SECRET, or higher8+ years of relevant systems engineering experience, including work in secure or mission-critical environments.Compliance with DoD 8570/8140 requirements (e.g., CCSP, Security+ CE, CISSP, Security X/CASP+, or equivalent baseline certification).Demonstrated experience leading vulnerability management and patching activities across complex, multi-platform environments.Experience with Microsoft Azure Cloud services such as virtual machines, storage, resource manager, etc.Experience with implementing PKI and PIV standards, Active Directory or LDAPExperience with Group Policy Objects and managementHands-on experience implementing STIGs and security baselines for:Operating systems (e.g., Windows Server, RHEL Linux, Ubuntu)Network devices (e.g., Cisco, Juniper, firewalls)Virtualization platforms and/or container platformsExperience maintaining and securing virtual machine infrastructures (e.g. cloud-based VMs).Experience supporting network infrastructure including configuration, hardening, and troubleshooting of routers, switches, and firewalls.Experience deploying and maintaining container-based environments (e.g., Docker, Kubernetes) with an emphasis on secure configuration and image management.Expertise with vulnerability scanning and compliance tools (e.g., Tenable.sc/Nessus ACAS or similar), including interpreting results and driving remediation.Proficiency with automation and scripting (e.g., Ansible, PowerShell, Python, Bash) for patching, configuration management, and reporting.Strong understanding of networking fundamentals (TCP/IP, routing, witching, DNS, DHCP, VLANs, VPNs) and how they intersect with security best practices.Solid understanding of cybersecurity principles, controls, and frameworks, such as NIST, RMF, and defense-in-depth strategiesStrong written and verbal communication skills, including the ability to translate technical risk and remediation plans into language stakeholders understand.Demonstrated ability to work collaboratively across engineering, cybersecurity, operations, and customer teams.Desired QualificationsBachelors degree in Computer Science, Information Systems, Engineering, Cybersecurity, or related field;Experience in Microsoft Azure Cloud securityimplementationsFamiliaritywithNIST 800-207 Zero Trust ArchitectureFamiliaritywithNIST 800-144 Guidelines on Security and Privacy in Public Cloud Computing
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
9 Ways to Make Money Hacking
Dev Digest 134 - Where pixels sing?
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.