Security Engineer

QualityWorks Consulting Group, LLC

Los Angeles (CA)

On-site

USD 124,000 - 207,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

QualityWorks Consulting Group, LLC is seeking a Cybersecurity Engineer for a 3-month on-site contract in the U.S. The role focuses on configuring and securing GovCloud, implementing DoD PKI and CAC authentication, and hardening a mixed cloud/on-premises environment.

You will verify controls, collect evidence, and deliver artifacts for compliance reviews. The position requires hands-on execution against runbooks, strict adherence to documented processes, and the ability to work within a

Qualifications

  • 3–6 years in systems engineering, security engineering, or systems administration with a security focus.
  • Hands-on certificate work: installing, renewing, and troubleshooting X.509/TLS certificates, trust stores, and chain-of-trust problems.
  • Direct experience working in AWS GovCloud, including its partition boundaries, credential separation, and service parity differences from commercial regions.
  • Familiarity with hardening baselines (STIGs, CIS benchmarks, or equivalent) and running or interpreting compliance scans.

Responsibilities

  • Configure and secure the GovCloud environment following the provided setup runbook.
  • Install and configure DoD PKI certificates for the platform and CAC authentication.
  • Execute on-premise and cloud setup procedures inside the accredited boundary and apply hardening baselines.
  • Run compliance and vulnerability scans, interpret results, and remediate findings per guidance.
  • Capture and organize evidence (logs, outputs, screenshots) for government review.

Skills

Security engineering
Systems administration
Documentation
Linux/Windows

Tools

AWS GovCloud
PKI
OpenSSL

Job description

QualityWorks Consulting Group


Cybersecurity Engineer


Job Description


Location On-site, U.S. — specific site shared during screening


Type Contract


Duration 3 months


Experience: Mid -level


Department : Technology


About the Role


We're deploying an autonomous software testing platform into a secure government environment spanning AWS GovCloud and on-premise infrastructure, and we need a security engineer inside the accredited boundary to make it real: configure and secure the GovCloud environment, install and configure DoD PKI, harden the stack, verify the security controls actually work, and produce the compliance evidence the government needs to accept it. This role is scoped for execution and verification rather than greenfield security architecture. The trust-model decisions, configuration procedures, and integration patterns are prepared in advance by our engineering team and handed to you as detailed runbooks, pre-validated in a sandbox before you ever open them. Your job is to run them correctly in the real environment, troubleshoot where the environment doesn't match the document, prove the controls hold, and elevate cleanly when something falls outside the documented path. If you're a careful systems or security engineer who executes precisely, documents well, and communicates clearly against a compliance deadline, you don't need a decade of PKI architecture experience to do this job well. We've deliberately built the role so you don't have to.


Security & Eligibility Requirements


These are hard conditions of the work, not preferences:



  • U.S. Person status. The work happens inside a government-accredited environment and cannot be performed by a non-U.S. Person or from outside the United States.

  • Ability to pass a Public Trust background investigation.

  • Willingness to complete DD Form 2875 system access paperwork immediately on offer acceptance.

  • Completion of the DoD Cyber Awareness Challenge and site-specific training before access.

  • Ability to obtain and maintain a Common Access Card (CAC).

  • DoD 8140/8570 IAT Level II certification (Security+ CE or equivalent) — held, or obtainable before access is granted.

  • On-site presence for the duration of the setup phase.


On timing: vetting and access provisioning run roughly 30 business days from submission. You won't have system access in your first few weeks — that time goes to paperwork, training, and working through the runbooks before you touch the environment. Candidates need to be comfortable with that ramp.


What You'll Do


AWS and GovCloud environment security



  • Configure and secure the GovCloud environment following the provided setup runbook: account structure, IAM roles and policies, VPC and security group configuration

  • Implement encryption and key management (KMS), S3 access controls, and secrets handling to the provided specification

  • Stand up and validate logging and monitoring — CloudTrail, Config, GuardDuty or equivalent — and confirm the audit trail satisfies the control requirements

  • Work within GovCloud partition boundaries and credential separation, and identify where service parity differs from commercial regions


PKI and CAC Authentication



  • Install and configure DoD PKI certificates for the platform, following the provided configuration runbook

  • Configure CAC/PIV-based authentication and validate it end to end with live credentials

  • Verify certificate chains, trust stores, and revocation checking (OCSP/CRL) behave as specified

  • Handle certificate lifecycle work in the environment: requests, installation, renewal, replacement


Environment Setup and Hardening



  • Execute the provided on-premise and cloud setup procedures inside the accredited boundary

  • Apply specified hardening baselines and STIG configurations

  • Run compliance and vulnerability scans, interpret the results, remediate findings per the documented guidance


Control Verification and Evidence



  • Execute documented test steps demonstrating each required security control is implemented and working

  • Capture evidence to our evidence standard — scan output, configuration exports, logs, screenshots — recorded in the master test log

  • Package security artifacts in the form the government's compliance reviewers expect

  • Track open findings to closure and report status on a set cadence


Client Interface and Escalation



  • Act as on-site point of contact for the client's ISSM/ISSO on security configuration questions

  • Coordinate site access, change windows, and scan schedules with client stakeholders

  • Raise anything outside the documented procedures through our escalation channel, with enough diagnostic detail for remote analysis

  • Maintain a daily written handoff so work continues across time zones

  • Feed deviations back so the runbooks stay accurate


What This Role Doesn't Own


Stated plainly, because it's the point of the role. These arrive already built:



  • Designing the PKI architecture or certificate trust model — you implement the documented design

  • Designing the cloud landing zone, network architecture, or platform integration patterns

  • Authoring security control narratives or the RMF/ATO package from scratch — you produce the evidence that feeds them

  • Writing the configuration runbooks and test procedures

  • Platform development and test-automation framework design


You have a dedicated engineering team behind all of it, reachable through a defined escalation channel with agreed response times. You are the only one on-site; you are not the only one on the problem.


What We're Looking For



  • 3–6 years in systems engineering, security engineering, or systems administration with a security focus

  • Hands-on certificate work: installing, renewing, and troubleshooting X.509/TLS certificates, trust stores, and chain-of-trust problems. Comfort debugging at the openssl s_client level — not CA design

  • Direct experience working in AWS GovCloud, including its partition boundaries, credential separation, and service parity differences from commercial regions

  • Solid Linux and/or Windows Server administration

  • Demonstrated ability to follow a detailed technical procedure exactly, and to notice and document when the environment doesn't match it

  • Familiarity with hardening baselines (STIGs, CIS benchmarks, or equivalent) and running or interpreting compliance scans

  • Disciplined written communication — evidence capture, status reports, and escalation write-ups someone remote can act on

  • U.S. Person status and ability to meet every vetting requirement above


Nice to Have (not required)



  • Prior on-site work in a DoD or federal environment; prior CAC holder

  • Prior experience with DD-2875 access processes

  • AWS Certified Security – Specialty, or Solutions Architect Associate

  • Experience in another FedRAMP or IL-accredited environment

  • Exposure to AWS GovCloud or another FedRAMP/IL-accredited environment

  • Supporting (not owning) role on a previous RMF or ATO effort

  • Familiarity with CI/CD, source control, and test management tooling

  • Experience working with a distributed team across time zones


What We Offer



  • Competitive contract compensation for the 3-month engagement

  • Direct backing from a dedicated engineering team, reachable through a defined escalation channel with agreed response times

  • Pre-validated runbooks and configuration procedures, so you execute against a proven plan rather than starting from a blank page

  • A clearly scoped, well-defined engagement with a set start and end date

  • The opportunity to work inside an accredited government environment on a mission-relevant platform

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

qualityworksconsulting • Los Angeles (CA)

On-site
USD 120,000 - 150,000
Cloud/Network Infrastructure Engineer, Senior
Cloud/Network Infrastructure Engineer, Senior

ecsfederal • Virginia (MN)

Hybrid
USD 123,000 - 184,000
Security Engineer, Cloud Security
Security Engineer, Cloud Security

Saronic • San Diego (CA)

On-site
USD 140,000 - 210,000
Security Engineer
Security Engineer

Inadev • Reston (VA)

Hybrid
USD 120,000 - 150,000
Cloud Subject Matter Expert / Cloud Security Architect
Cloud Subject Matter Expert / Cloud Security Architect

Intellect Solutions LLC • Rockville (MD), Northern (KY)

On-site
USD 150,000 - 210,000
Security clearance assistance
DevOps Engineer
DevOps Engineer

Windward • Washington, Baltimore (MD)

On-site
USD 180,000 - 240,000
DevSecOps Engineer
DevSecOps Engineer

Wilcore Technologies, Inc. • Northern (KY)

Hybrid
USD 120,000 - 160,000
Cloud Security Architect (GCC High)
Cloud Security Architect (GCC High)

Two Five Solutions, LLC. • Washington, Northern (KY)

Hybrid
USD 140,000 - 185,000
Security Operations Engineer
Security Operations Engineer

Elan Partners • United States

On-site
USD 120,000 - 150,000
Sr. Cybersecurity Automation Architect / SME
Sr. Cybersecurity Automation Architect / SME

NR Labs LLC • Washington, Northern (KY)

Hybrid
USD 140,000 - 190,000