Security Engineer

qualityworksconsulting

Los Angeles (CA)

On-site

USD 120,000 - 150,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

QualityWorks Consulting Group in Los Angeles is seeking a Cybersecurity Engineer to deploy and verify a government-bound security platform inside GovCloud and on-premise systems. You will harden the stack, install DoD PKI, and ensure controls are implemented and auditable on schedule.

You will execute prescriptive runbooks, validate configurations, manage certificates, and produce evidence packages for federal reviewers, working on-site through the critical setup phase.

Qualifications

  • U.S. Person status required.
  • Ability to pass a Public Trust background investigation.
  • Willingness to complete DD Form 2875 on offer acceptance.
  • Completion of the DoD Cyber Awareness Challenge and site training.
  • Ability to obtain CAC.
  • DoD 8140/8570 IAT Level II certification prior to access.
  • On-site presence for the setup phase.

Responsibilities

  • Configure GovCloud account structure, IAM roles, and VPC with security groups.
  • Implement encryption (KMS), S3 access controls, and secret handling as specified.
  • Stand up and validate logging/monitoring (CloudTrail, Config, GuardDuty).
  • Install DoD PKI certificates and CAC/PIV authentication end-to-end.
  • Run vulnerability scans, interpret results, and remediate findings per guidance.

Skills

Security engineering
AWS GovCloud
Linux/Windows
Follow procedures
Hardening baselines
Written communication
U.S. Person status

Tools

OpenSSL s_client

Job description

QualityWorks Consulting Group

Cybersecurity Engineer

Job Description

Location On-site, U.S. — specific site shared during screening

Type Contract

Duration 3 months

Experience: Mid -level

Department : Technology

About the Role

We're deploying an autonomous software testing platform into a secure government environment spanning AWS GovCloud and on-premise infrastructure, and we need a security engineer inside the accredited boundary to make it real: configure and secure the GovCloud environment, install and configure DoD PKI, harden the stack, verify the security controls actually work, and produce the compliance evidence the government needs to accept it. This role is scoped for execution and verification rather than greenfield security architecture. The trust-model decisions, configuration procedures, and integration patterns are prepared in advance by our engineering team and handed to you as detailed runbooks, pre-validated in a sandbox before you ever open them. Your job is to run them correctly in the real environment, troubleshoot where the environment doesn't match the document, prove the controls hold, and elevate cleanly when something falls outside the documented path. If you're a careful systems or security engineer who executes precisely, documents well, and communicates clearly against a compliance deadline, you don't need a decade of PKI architecture experience to do this job well. We've deliberately built the role so you don't have to.

Security & Eligibility Requirements

These are hard conditions of the work, not preferences:

  • U.S. Person status. The work happens inside a government-accredited environment and cannot be performed by a non‑U.S. Person or from outside the United States.
  • Ability to pass a Public Trust background investigation.
  • Willingness to complete DD Form 2875 system access paperwork immediately on offer acceptance.
  • Completion of the DoD Cyber Awareness Challenge and site‑specific training before access.
  • Ability to obtain and maintain a Common Access Card (CAC).
  • DoD 8140/8570 IAT Level II certification (Security+ CE or equivalent) — held, or obtainable before access is granted.
  • On‑site presence for the duration of the setup phase.

On timing: vetting and access provisioning run roughly 30 business days from submission. You won't have system access in your first few weeks — that time goes to paperwork, training, and working through the runbooks before you touch the environment. Candidates need to be comfortable with that ramp.

What You'll Do
AWS and GovCloud environment security
  • Configure and secure the GovCloud environment following the provided setup runbook: account structure, IAM roles and policies, VPC and security group configuration
  • Implement encryption and key management (KMS), S3 access controls, and secrets handling to the provided specification
  • Stand up and validate logging and monitoring — CloudTrail, Config, GuardDuty or equivalent — and confirm the audit trail satisfies the control requirements
  • Work within GovCloud partition boundaries and credential separation, and identify where service parity differs from commercial regions
PKI and CAC Authentication
  • Install and configure DoD PKI certificates for the platform, following the provided configuration runbook
  • Configure CAC/PIV‑based authentication and validate it end to end with live credentials
  • Verify certificate chains, trust stores, and revocation checking (OCSP/CRL) behave as specified
  • Handle certificate lifecycle work in the environment: requests, installation, renewal, replacement
Environment Setup and Hardening
  • Execute the provided on‑premise and cloud setup procedures inside the accredited boundary
  • Apply specified hardening baselines and STIG configurations
  • Run compliance and vulnerability scans, interpret the results, remediate findings per the documented guidance
Control Verification and Evidence
  • Execute documented test steps demonstrating each required security control is implemented and working
  • Capture evidence to our evidence standard — scan output, configuration exports, logs, screenshots — recorded in the master test log
  • Package security artifacts in the form the government's compliance reviewers expect
  • Track open findings to closure and report status on a set cadence
Client Interface and Escalation
  • Act as on‑site point of contact for the client's ISSM/ISSO on security configuration questions
  • Coordinate site access, change windows, and scan schedules with client stakeholders
  • Raise anything outside the documented procedures through our escalation channel, with enough diagnostic detail for remote analysis
  • Maintain a daily written handoff so work continues across time zones
  • Feed deviations back so the runbooks stay accurate
What This Role Doesn't Own

Stated plainly, because it's the point of the role. These arrive already built:

  • Designing the PKI architecture or certificate trust model — you implement the documented design
  • Designing the cloud landing zone, network architecture, or platform integration patterns
  • Authoring security control narratives or the RMF/ATO package from scratch — you produce the evidence that feeds them
  • Writing the configuration runbooks and test procedures
  • Platform development and test‑automation framework design

You have a dedicated engineering team behind all of it, reachable through a defined escalation channel with agreed response times. You are the only one on‑site; you are not the only one on the problem.

What We're Looking For
  • 3–6 years in systems engineering, security engineering, or systems administration with a security focus
  • Hands‑on certificate work: installing, renewing, and troubleshooting X.509/TLS certificates, trust stores, and chain‑of‑trust problems. Comfort debugging at the openssl s_client level — not CA design
  • Direct experience working in AWS GovCloud, including its partition boundaries, credential separation, and service parity differences from commercial regions
  • Solid Linux and/or Windows Server administration
  • Demonstrated ability to follow a detailed technical procedure exactly, and to notice and document when the environment doesn't match it
  • Familiarity with hardening baselines (STIGs, CIS benchmarks, or equivalent) and running or interpreting compliance scans
  • Disciplined written communication — evidence capture, status reports, and escalation write‑ups someone remote can act on
  • U.S. Person status and ability to meet every vetting requirement above
Nice to Have (not required)
  • Prior on‑site work in a DoD or federal environment; prior CAC holder
  • Prior experience with DD‑2875 access processes
  • AWS Certified Security – Specialty, or Solutions Architect Associate
  • Experience in another FedRAMP or IL-accredited environment
  • Exposure to AWS GovCloud or another FedRAMP/IL-accredited environment
  • Supporting (not owning) role on a previous RMF or ATO effort
  • Familiarity with CI/CD, source control, and test management tooling
  • Experience working with a distributed team across time zones
What We Offer
  • Competitive contract compensation for the 3-month engagement
  • Direct backing from a dedicated engineering team, reachable through a defined escalation channel with agreed response times
  • Pre‑validated runbooks and configuration procedures, so you execute against a proven plan rather than starting from a blank page
  • A clearly scoped, well‑defined engagement with a set start and end date
  • The opportunity to work inside an accredited government environment on a mission‑relevant platform
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

QualityWorks Consulting Group, LLC • Los Angeles (CA)

On-site
USD 124,000 - 207,000
Cloud/Network Infrastructure Engineer, Senior
Cloud/Network Infrastructure Engineer, Senior

ecsfederal • Virginia (MN)

Hybrid
USD 123,000 - 184,000
Security Engineer, Cloud Security
Security Engineer, Cloud Security

Saronic • San Diego (CA)

On-site
USD 140,000 - 210,000
Security Software Engineer On-site
Security Software Engineer On-site

Eccalon, LLC • Detroit (MI)

On-site
USD 110,000 - 145,000
Cloud Subject Matter Expert / Cloud Security Architect
Cloud Subject Matter Expert / Cloud Security Architect

Intellect Solutions LLC • Rockville (MD), Northern (KY)

On-site
USD 150,000 - 210,000
Security clearance assistance
Security Engineer
Security Engineer

Inadev • Reston (VA)

Hybrid
USD 120,000 - 150,000
DevOps Engineer
DevOps Engineer

Windward • Washington, Baltimore (MD)

On-site
USD 180,000 - 240,000
Cloud Security Architect (GCC High)
Cloud Security Architect (GCC High)

Two Five Solutions, LLC. • Washington, Northern (KY)

Hybrid
USD 140,000 - 185,000
DevSecOps Engineer
DevSecOps Engineer

Wilcore Technologies, Inc. • Northern (KY)

Hybrid
USD 120,000 - 160,000
Security Operations Engineer
Security Operations Engineer

Elan Partners • United States

On-site
USD 120,000 - 150,000