The Opportunity NTS is seeking an experienced Security Compliance Engineer with deep expertise in Linux system security, DISA STIG implementation, and regulated-environment compliance frameworks including FedRAMP and CMMC. You will own the technical execution of our compliance program-translating control requirements into hardened system configurations, automated scanning pipelines, and auditable evidence packages-while partnering with engineering teams to maintain secure-by-default infrastructure. This is a hands‑on engineering role. You will be expected to read STIGs, write Ansible playbooks, triage CVEs, and operate scanning tooling-not just manage checklists. Key Responsibilities (Principal Duties and Accountabilities *Essential Functions) STIG Implementation & System Hardening * Apply and maintain DISA STIGs across various Linux distributions (RHEL, Ubuntu, SUSE, etc) using OpenSCAP, Ansible STIG roles and/or manual remediation
- Develop and maintain automated hardening pipelines that produce STIG-compliant OS images via bootc+bib, KIWI/EIB and/or Packer for bare-metal, VM, and cloud deployment targets
- Configure and tune host-based security controls: SELinux (enforcing/targeted/MLS), auditd rules, fapolicyd application whitelisting, firewalld, and PAM
- Implement and validate CIS Benchmark controls as a complement to STIG baselines
- Maintain STIG checklists (CKL/CKLB) and produce POA&M artifacts for findings requiring waivers or scheduled remediation Vulnerability Management * Operate and maintain authenticated scanning infrastructure using Tenable Nessus / Security Center or equivalent; schedule, tune, and triage scan results at scale
- Perform continuous CVE triage using NVD, CVSS v3/v4, and EPSS scores to drive prioritized remediation workflows with engineering teams
- Track open vulnerabilities through full lifecycle: discovery, ticket creation, remediation verification, and closure evidence
- Develop metrics and dashboards for vulnerability posture reporting to technical and executive audiences
- Coordinate patch cadence with platform teams; validate patched images against scan baselines before promotion to production FedRAMP Authorization & Continuous Monitoring * Support FedRAMP authorization activities (Low, Moderate, or High baselines) including SSP development, control implementation statements, and evidence collection
- Operate and maintain ConMon programs: monthly vulnerability scanning, POA&M updates, significant change requests (SCRs), and annual assessments
- Collaborate with Third Party Assessment Organizations (3PAOs) during assessments; prepare technical staff and produce assessment-ready evidence packages
- Map NIST SP 800-53 Rev 5 controls to technical implementation across infrastructure, applications, and organizational processes
- Maintain the SSP, CIS, SAR, and SAP documentation sets through authorization lifecycle CMMC & DoD Compliance * Implement and assess CMMC Level 1-3 practices against NIST SP 800-171 and NIST SP 800-172 requirements
- Maintain the System Security Plan (SSP) and associated artifacts (FIPS boundaries, network diagrams, data flow documentation) for CUI-handling environments
- Support DIBCAC assessments and internal readiness reviews; manage corrective action tracking through resolution
- Define and enforce CUI handling procedures, labeling, and access control policies across systems and workflows
- Implement DoD RMF steps (Categorize ? Select ? Implement ? Assess ? Authorize ? Monitor) for new and existing systems Supply Chain & SBOM Security * Generate and maintain Software Bill of Materials (SBOM) artifacts in CycloneDX and SPDX formats for all platform components
- Integrate SBOM generation (Syft) and vulnerability correlation (Grype, Dependency-Track) into CI/CD pipelines
- Enforce software supply-chain controls: artifact signing with cosign / Sigstore, digest pinning, and provenance attestation
- Evaluate third-party components against supply-chain risk criteria prior to onboarding PKI, Identity & Cryptography * Manage PKI infrastructure for internal certificate issuance, renewal, and revocation; integrate with CAC/PIV authentication for privileged accessEnforce FIPS 140-2/3 validated cryptographic module usage across system components, TLS configurations, and disk encryption
- Configure and maintain SSSD, LDAP/AD integration, and PAM stacks for centralized identity and MFA enforcement
- Audit and harden SSH configurations, sudo policies, and privileged access management (PAM/PIM) controls SIEM, Audit & Incident Response * Maintain centralized logging pipelines (Splunk, Elastic/OpenSearch, or Wazuh) ingesting auditd, syslog, and application events
- Develop correlation rules and alerts for STIG-required audit events, authentication anomalies, and integrity violations
- Support incident response activities including evidence preservation, log analysis, and post‑incident documentation
- Conduct file integrity monitoring (AIDE or equivalent) and respond to integrity alerts within defined SLAs