IT Senior Security Engineer

AUGUST SCHELL ENTERPRISES, INC.

Bethesda (MD)

On-site

USD 150,000 - 210,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

The National Library of Medicine (NLM) is seeking an IT Senior Security Engineer to join the Security Compliance team in Bethesda, MD. This role focuses on implementing security controls, achieving FISMA compliance, and enabling secure cloud adoption across platforms.

The hands-on engineer collaborates with the ISSO and enterprise security teams across vulnerability management, cloud security, SIEM, and AI-enhanced tooling to strengthen the organization’s security posture and protect

Qualifications

  • Extensive experience securing on-premises and cloud environments (AWS, GCP, Azure) with strong knowledge of cloud security models and cross-platform operations in federal, regulated settings.
  • 10+ years in information technology security with 7+ years in hands-on security engineering and 3+ years in cloud security and endpoint administration.
  • Familiarity with AI/ML integration in security tooling for modern threat detection and remediation.
  • Expertise applying FISMA, NIST 800-53, FedRAMP, RMF; supporting ATO/POA&M processes in governance and compliance.
  • Experience with at least two security tools such as Tenable, Checkmarx, or Splunk, and vulnerability management workflows.
  • Bachelor’s degree in computer science or related field (or equivalent experience).
  • CISSP certification (or ability to obtain within 6 months).
  • Strong collaboration and guidance for multi-disciplinary teams managing servers, workstations, network and security appliances.

Responsibilities

  • Enhance and automate security and compliance checks; evaluate AI capabilities to improve coverage and efficiency.
  • Implement and maintain security controls for on-prem and cloud environments (AWS, GCP, Azure) with FISMA and NIH policy compliance.
  • Support identity access, privileged access, vulnerability management, encryption, network micro-segmentation, and centralized log management.
  • Integrate and optimize SIEM solutions (e.g., Splunk) for continuous monitoring and compliance visibility in hybrid environments.
  • Conduct threat modeling and security assessments of cloud deployments and migrations.
  • Provide security guidance and best practices to developers, operations, and system owners.
  • Analyze vulnerability data to identify systemic risks and drive remediation improvements.
  • Contribute to documentation and standard operating procedures for the security program.

Skills

Cloud security
FISMA/NIST
Vulnerability management
Splunk
Tenable
Checkmarx
AI/ML security tooling
Linux/Windows admin
Documentation
Threat modeling

Education

Bachelor's degree in CS/IT
CISSP certification
Master's degree (preferred)

Tools

Tenable
Checkmarx
Splunk

Job description

Senior Security Engineer

Location: Bethesda, MD (Requires Onsite 3–5 days per week as needs change)

Employment Type: Full-time

The National Library of Medicine (NLM) is seeking an IT Senior Security Engineer to join our Security Compliance team. In this role, you will work closely with the NLM Information Systems Security Office and play a critical part in safeguarding NLM's IT infrastructure.

The Senior Security Engineer plays a hands‑on role in a multi-disciplined security team, focusing on the implementation of security controls, ensuring compliance with the federal cybersecurity framework (FISMA), and supporting secure cloud adoption across multiple platforms. Collaborating closely with endpoint owners, infrastructure and network security teams, as well as enterprise security teams to meet NIH mandates, this engineer actively works across vulnerability management, application security, cloud security, SIEM, and bringing in new AI‑based tooling to strengthen the organization’s overall security posture. Receiving day-to‑day technical direction from the ISSO and collaborating with tool owners and system administrators—rather than managing any single platform outright—the ideal candidate brings a strong foundation in systems administration, deep hands‑on security engineering experience, and the ability to optimize the effectiveness of existing security tools. As part of a broader IT program providing end‑to‑end support including network, incident response, and security services, this role is critical in ensuring the availability, integrity, and confidentiality of mission‑critical systems.

Responsibilities
  • Enhance and automate security and compliance checks using scripting and available tools; evaluate emerging technologies, including AI capabilities, to improve security coverage and operational efficiency. Lead team efforts to integrate AI/ML-driven capabilities with the current security tools and operations to enhance and automate assessment and remediation using LLM within NLM
  • Implement and maintain security controls for on‑prem and cloud environments (AWS, GCP, Azure), ensuring compliance with FISMA, NIH policy, and federal security requirements.
  • Recommend and support security services for identity access, privileged access, vulnerability management, encryption, network micro‑segmentation, and centralized log management in both cloud and on‑premises systems.
  • Integrate and optimize enterprise security and SIEM solutions (e.g., Splunk, Tenable) for continuous monitoring, event correlation, and compliance visibility in hybrid environments.
  • Conduct threat modeling and security assessments of cloud deployments, identifying and mitigating vulnerabilities and supporting secure cloud migrations.
  • Provide security guidance, best practices, and compliance support to developers, operations teams, and system owners, promoting security awareness across the organization.
  • Analyze vulnerability and assessment data to identify systemic risks, remediation trends, and opportunities for process or tool improvement, collaborating with system administrators and security teams for practical, risk‑informed remediation.
  • Contribute and manage documentation, standard operating procedures, and technical guidance to support the broader security program and ensure consistent practices.
Required Qualifications
  • Extensive experience securing on‑premises and cloud environments (AWS, GCP, Azure), with strong working knowledge of cloud security models, logging, tagging strategies, ephemeral resource tracking, and cross‑platform operations; proven hands‑on security engineering background in federal, regulated settings.
  • 10+ years in securing information technology, plus 7+ years in hands‑on security engineering built on a systems administration foundation including at least 3 years focused on cloud security and administration of Linux and Windows endpoints
  • Familiarity with AI/ML integration in security tooling and operations, supporting modern approaches to threat detection and remediation.
  • Demonstrated expertise applying federal compliance frameworks (FISMA, NIST 800‑53, FedRAMP, RMF), supporting system authorization processes (ATO, POA&M), and navigating complex governance and compliance requirements.
  • Admin or engineering‑level experience with at least two security tools such as Tenable, Checkmarx, or Splunk, along with a strong understanding of vulnerability management, application security testing, and remediation workflows.
  • Bachelor’s degree in computer science, cybersecurity, information technology, or related technical field (or equivalent technical experience)
  • CISSP certification (or ability to obtain within 6 months).
  • Effective collaboration and guidance for multi‑disciplinary teams managing servers, workstations, network and security appliances within regulated environments; ability to adapt to shifting priorities and contribute to team goals.
  • Strong written and verbal communication skills, with a proven ability to produce clear security documentation and explain technical concepts to both technical and non‑technical stakeholders.
Desired Qualifications
  • Hands‑on work experience with AI/ML automation, security event correlation, asset inventory tracking and SEIM management (preferably in SPLUNK), utilizing scripting or programming such as PowerShell, Bash, Python or equivalent and use of APIs
  • Advanced Linux and Windows administration experience, Certified in AWS/AZURE/GCP
  • Experience with container security (like Docker & Kubernetes)
  • Master’s degree in computer science, Cybersecurity, Information Technology, or a related technical field
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Senior Security Engineer
IT Senior Security Engineer

August Schell • Bethesda (MD)

On-site
USD 140,000 - 170,000
IT Cloud Security Analyst
IT Cloud Security Analyst

AUGUST SCHELL ENTERPRISES, INC. • Bethesda (MD)

On-site
USD 120,000 - 150,000
IT Vulnerability Management Lead / Senior Security Analyst
IT Vulnerability Management Lead / Senior Security Analyst

August Schell • Bethesda (MD)

On-site
USD 120,000 - 180,000
IT Vulnerability Management Lead / Senior Security Analyst
IT Vulnerability Management Lead / Senior Security Analyst

AUGUST SCHELL ENTERPRISES, INC. • Bethesda (MD)

On-site
USD 130,000 - 170,000
IT Cloud Security Analyst
IT Cloud Security Analyst

Futrend Technology • Bethesda (MD)

On-site
USD 120,000 - 150,000
Senior Security Engineer: Cloud, Compliance & AI Enablement
Senior Security Engineer: Cloud, Compliance & AI Enablement

AUGUST SCHELL ENTERPRISES, INC. • Bethesda (MD)

On-site
USD 150,000 - 210,000
Senior Security Engineer — Cloud, Compliance & AI Tools
Senior Security Engineer — Cloud, Compliance & AI Tools

AUGUST SCHELL ENTERPRISES, INC. • Bethesda (MD), Northern (KY)

Hybrid
USD 150,000 - 210,000
System Security Engineer
System Security Engineer

Black Canyon Consulting • Bethesda (MD)

Hybrid
USD 80,000 - 110,000
Medical, dental and vision coverage
401k plan with employer contribution
Paid holidays and vacation
+1
NLM Cloud Engineer I
NLM Cloud Engineer I

Lexical Intelligence • Bethesda (MD)

Hybrid
USD 90,000 - 120,000
Full health and dental for employee
Retirement plan
HSA account
+2
NLM Security Specialist I - III
NLM Security Specialist I - III

Lexical Intelligence • Bethesda (MD)

On-site
USD 90,000 - 150,000
Health and dental insurance for you &/
Retirement and HSA
Paid federal holidays (11)