Senior Security Engineer
Role details
Job location
Tech stack
Job description
- Vulnerability Management:
-
Implement patching procedures for multiple Operating Systems (Linux, Windows, VMware, Cisco)
-
Run and review vulnerability scans and STIGs
-
Prioritize vulnerability remediation efforts across endpoints, networks, and applications
-
Automate patching process for multiple Operating Systems (Linux/Windows)
-
Responsible for securing and hardening hardware and software systems.
- Governance, Risk & Compliance:
-
Support tracking, resolution, and milestones for the program's Plan of Action and Milestones (POA&M) items
-
Develop and maintain security policies, procedures, and standards
-
Ensure compliance with relevant standards, directives, and regulations
-
Conduct risk assessments and support audit activities
-
Remain abreast of emerging technologies, cyber threats, and security tools
- Security Architecture & Engineering
-
Design, implement, and manage security solutions (e.g., SIEM, EDR, firewalls, IDS/IPS, IAM, VPN)
-
Evaluate and integrate new security technologies and tools
- Advise ISSO and ISSM on issues related to securing and monitoring classified DoD networks
- Creation and maintenance of data flow and system boundary diagrams
- Agile/Scrum process
Requirements
- Must be a U.S. citizen and have an active security clearance
- Bachelor's (BS) degree in Cybersecurity, Computer Science, Information Technology, or related field (or equivalent experience)
- Strong understanding of network protocols, security architecture, and security practices
- Experience with Linux-based and Windows-based systems
- Proficient in scripting (e.g., Python, PowerShell, Bash)
- Experience with automation tools (e.g., Ansible, Terraform, Chef, Puppet)
- Understanding of CI/CD
- In-depth knowledge of modern threat landscapes, vulnerabilities, mitigation techniques, and security tools and processes
- Familiarity with NIST 800-53, NIST 800-171, SOC 2 and/or ISO 27001
- Ability to write clear and concise cybersecurity guidance, procedures, and documentation
- Security+ Certified
Preferred Skills and Experience:
- DoD RMF security practices and regulations
- Virtualization (preferably VMware)
- Familiarity with open-source security tools
- Familiarity with ACAS, Tenable Security Center, and Tenable Nessus
Benefits & conditions
- Leadership training
- 401k with generous company matching
- Employee Stock Ownership Plan (ESOP)
- Career professional development
- Tuition reimbursement
- Flexible hours
- Work/Life balance
- Rewards and recognition
- Paid Time Off
- Parental Leave