> Markdown version of [/jobs/ext/264825-compliance-security-engineer-ts-sci](https://www.wearedevelopers.com/jobs/ext/264825-compliance-security-engineer-ts-sci). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Compliance / Security Engineer TS SCI - **Company:** Aperio Global, Llc - **Location:** Fort Meade, MD, United States - **Experience:** Expert - **Salary:** $200,000.0 - $220,000.0 - **Contract:** Contract - **Skills:** Microsoft Windows, Amazon Web Services, Microsoft Azure, Cloud Computing, Data Transmissions, Linux, Identity and Access Management, Network Architecture, Zero Trust Network Access, Software Vulnerability Management - **Published:** May 15, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=62067d2178d8fc02 ## About the Role Do you have experience in Windows?, * Active TS/SCI clearance (no exceptions). * 5+ years of hands-on experience leading ATO/IATT workstreams in DoD or IC environments. * Expert-level knowledge of NIST Risk Management Framework (RMF) - SP 800-37, SP 800-53, and related publications. * Demonstrated experience operationalizing DISA STIGs across Linux, Windows, and network infrastructure. * Working knowledge of Cross-Domain Solutions (CDS) architecture, accreditation, and operational requirements. * Proficiency with eMASS or equivalent DoD authorization tools. NICE TO HAVE: * CISSP, CAP (Certified Authorization Professional), or equivalent DoD 8570/8140 IAM Level III certification. * Experience supporting DISA programs or working within the DISA RMF process directly. * Familiarity with cloud-based deployment environments (AWS GovCloud, Azure Government) and associated security frameworks. * Experience with zero-trust architecture concepts and implementation in classified environments. ## Description We are seeking a highly experienced Compliance / Security Engineer to lead Authorization to Operate (ATO) and Interim Authority to Test (IATT) workstreams within a high-security DoD program environment. This dedicated role is embedded directly with the program team and requires an expert-level practitioner capable of operating across classification boundaries. The ideal candidate brings deep practical experience operationalizing security frameworks in deployed, classified environments. * Lead end-to-end ATO and IATT workstreams, coordinating with government stakeholders, ISSOs, and program leadership to ensure timely authorization milestones. * Operationalize DISA STIGs across system components; develop and maintain STIG checklists, deviation requests, and risk acceptance documentation. * Map security controls to deployment architectures, ensuring continuous compliance alignment with NIST RMF steps (Categorize Authorize Monitor). * Design and support Cross-Domain Solutions (CDS) implementations; liaise with accreditation authorities for cross-domain data transfer approvals. * Develop, review, and maintain System Security Plans (SSP), Security Assessment Reports (SAR), Plans of Action & Milestones (POA&M), and related RMF artifacts. * Conduct continuous monitoring activities and coordinate vulnerability remediation with engineering teams. * Interface directly with DISA and other DoD oversight bodies throughout the authorization lifecycle. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)