Security Engineer (Pipeline)

Page Mechanical Group, Inc.

Fort Meade (MD)

On-site

USD 145,000 - 155,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Medical, Dental & Vision
Mental Health Resources
401(k) with Company Matching
Life, Accident & Injury Insurance
Flexible Spending Account (FSA)
Health Savings Account (HSA)
Certification Prep & Exam Reimb.
Virtual Personal & Professional Dev

Job summary

Total Force Alliance, LLC seeks a Security Engineer/ISSE to own RMF execution for secure federal apps on Azure Government. You will develop and maintain SSP/POA&M, drive ATO processes, and coordinate with Government evaluators to sustain Authority to Operate across environments.

You will harden systems to DISA STIGs, implement zero-trust controls, manage PKI/DoD validation, and oversee continuous monitoring with SIEM tooling. A TS/SCI clearance and DoD 8140/8570 aligned credentials are required.

Qualifications

  • 7+ years in information system security engineering/cybersecurity for federal or DoD systems, with direct, hands-on RMF experience.
  • Owns RMF authorization artifacts (SSP, POA&M) for multiple environments.
  • Hands-on with eMASS and NIST 800-53 control implementation and assessment.
  • Experience hardening against DISA STIGs and validating compliance.
  • Cloud security knowledge across identity, network isolation, key management, and SIEM.
  • Understanding of CUI handling and DoD Cloud SRG impact levels.
  • DoD 8140/8570-compliant certification (e.g., CISSP, CASP+).
  • Strong technical writing to produce assessor-ready evidence.

Responsibilities

  • Own RMF execution and authorization activities under NIST 800-37/800-53 and DoDI 8510.01.
  • Author and maintain SSP, POA&M, and control-implementation evidence; manage packages in eMASS.
  • Interface with Government ISSM/AO and assessors for ATO/cATO processes.
  • Implement and validate DISA STIG hardening and track remediation to closure.
  • Design and operate continuous-monitoring with SIEM integration and cadence.
  • Protect data: encryption, key management, and no secrets in code or images.
  • Manage DoD PKI validation design with cloud and app teams.
  • Enforce CUI handling and cross-domain controls as applicable.
  • Implement least-privilege, zero-trust, and privileged-access controls.
  • Produce security documentation and as-built records for accreditation.

Skills

RMF execution
NIST 800-53
eMASS
Cloud security
DoD 8140/8570
CISSP/CASP
TS/SCI clearance
Security engineering

Education

CISSP-ISSEP

Tools

eMASS
Microsoft Sentinel
Azure Government
DISA STIGs
Key Vault / KMS

Job description

Security Engineer

(*Note: This position is a pipeline opportunity*)

We’re hiring aSecurity Engineer / Information System Security Engineer (ISSE)to own the security engineering and Risk Management Framework (RMF) execution for secure enterprise applications delivered to federal customers on Azure Government. You will implement and document security controls, produce the authorization artifacts, and drive the assessment-and-authorization activities that earn and sustain a system's Authority to Operate — while the Government Authorizing Official retains all authorization authority.

This is a critical-path role. Systems are configured, assessed, and separately authorized per environment, so you will carry the control implementation, the System Security Plan and POA&M, the hardening, and the continuous-monitoring posture — coordinating closely with cloud engineers, developers, and the Government. When accreditation is on the critical path, your work is what keeps delivery on schedule.

Location:

Candidate must be located in the Washington, DC, metro region and must be available onsite in Maryland as needed. This role supports secure Government environments; Candidates must have and maintain an active TS/SCI clearance with the Department of Defense. All personnel shall meet DoD 8140/8570 (DoDM 8140 / DCWF) baseline requirements.

Responsibilities:
  • Own RMF execution — categorize, select, implement, assess, and support authorization under NIST 800-37 / 800-53 and DoDI 8510.01.
  • Author and maintain the System Security Plan (SSP), POA&M, and full control-implementation evidence; manage the authorization package in eMASS (or the Government's system of record).
  • Serve as the security engineering interface to the Government ISSM/AO and assessors; prepare for and support all assessment-and-authorization activities.
  • Implement and validate hardening against applicable DISA STIGs (application/ASD, container, database, OS) and track remediation to closure.
  • Design and operate the continuous-monitoring posture — audit logging, SIEM integration (Microsoft Sentinel / Log Analytics), and control-assessment cadence — and maintain POA&M currency.
  • Engineer and verify the data-protection posture: encryption in transit and at rest, key management (Key Vault / managed identity, customer-managed keys, FIPS-validated cryptography), and no secrets in source or image.
  • Own the CAC/PIV / DoD PKI validation design (OCSP/CRL) with the cloud and application engineers.
  • Enforce CUI handling and, where applicable, cross-domain and classified-data controls and spillage prevention.
  • Implement least-privilege access, zero-trust controls, and privileged-access administration (Bastion / JIT / MFA / privileged access workstations).
  • Produce and maintain the security documentation and as-built records required for accreditation and customer handoff.
Requirements
  • 7+ years in information system security engineering/cybersecurity for federal or DoD systems, with direct, hands‑on RMF experience.
  • Demonstrated ownership of at least two systems through a full RMF authorization to an ATO/cATO — SSP, control implementation, POA&M, and package management.
  • Hands‑on experience with eMASS (or equivalent) and NIST 800-53 control implementation and assessment.
  • Experience hardening systems to DISA STIGs and validating compliance.
  • Working knowledge of cloud security architecture — identity, network isolation (private endpoints), key management, and SIEM/continuous monitoring.
  • Understanding of CUI handling (DoDI 5200.48) and the DoD Cloud Computing SRG impact levels.
  • DoD 8140/8570‑compliant certification for the ISSE role (e.g., CISSP, CASP+, or equivalent).
  • Strong technical writing and the ability to produce assessor‑ready evidence.
  • Ability to carry security engineering and authorization across multiple environments on a lean, senior team.
  • Candidates must have and maintain an active TS/SCI clearance with the Department of Defense.
Preferred Qualifications:
  • Direct experience accrediting workloads in Azure Government or classified Azure environments.
  • Experience with cross-domain solutions (CDS) and the SABI/TSABI process, or supporting a data‑transfer accreditation.
  • Experience standing up continuous monitoring with Microsoft Sentinel and integrating with a designated CSSP.
  • Familiarity with securing containerized workloads (AKS, hardened images, image signing/scanning).
  • Experience with AI/LLM security controls (data‑residency, scope‑bound retrieval, prompt‑injection defense) in a governed environment.
  • ISSM or RMF assessor experience; CISSP‑ISSEP.
About Total Force Alliance:

Total Force Alliance, LLC is an SBA‑certified Service‑Disabled Veteran (SDVOSB) and Economically Disadvantaged Woman‑Owned Small Business (EDWOSB) founded in 2023 and headquartered in Miami, Florida. We provide top‑notch talent recruitment and retention for niche skillsets and in‑demand talent for Enterprise IT Services: Operations, Engineering, Cybersecurity, ServiceNow Development, and Cloud Services. Our corporate culture and industry partnerships enable us to offer unrivaled salary, benefits, training and professional development to select IT professionals that can innovate and deliver technical solutions targeted to Federal Civilian, Health, Defense, Intelligence and Cyber strategic priorities.

Benefits:
  • Medical, Dental & Vision
  • Mental Health Resources
  • Paid Time Off & Holidays
  • 401(k) with Company Matching
  • Life, Accident & Injury Insurance
  • Flexible Spending Account (FSA)
  • Health Savings Account (HSA)
  • Certification Preparation & Exam Reimbursement
  • Virtual Personal & Professional Development Classes
Target Salary Range

$145,000 - $155,000

The anticipated salary range for this position is provided as a general guideline and is not a guarantee of compensation or salary. The final offer may vary based on several factors, including job responsibilities, education, certifications, relevant experience, geographic location, internal equity, market data, contractual requirements, and other applicable considerations. Accordingly, the final salary may fall outside the stated range, where permitted by applicable law.

Total Force Alliance, LLC is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other protected characteristics.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Systems Security Engineer SME
Information Systems Security Engineer SME

ECS • Stafford (VA)

On-site
USD 120,000 - 150,000
Senior Information Systems Security Engineer
Senior Information Systems Security Engineer

ECS • Washington

On-site
USD 120,000 - 150,000
Cloud Security Engineer
Cloud Security Engineer

Booz Allen Hamilton • Alexandria (VA)

On-site
USD 99,000 - 225,000
Health, life, and disability insurance
Retirement plans
Paid leave
Information System Security Manager (ISSM) – TS/SCI
Information System Security Manager (ISSM) – TS/SCI

Strategic Business Systems • Arlington (VA)

On-site
USD 160,000 - 220,000
Medical benefits
401(k) with company match
Paid time off
+2
Cybersecurity Engineer
Cybersecurity Engineer

LMI Government Consulting • Tysons (VA)

On-site
USD 102,000 - 170,000
Cybersecurity and RMF Engineer, Mid
Cybersecurity and RMF Engineer, Mid

Booz Allen Hamilton • Arlington (VA)

On-site
USD 69,400 - 158,000
Cloud Information System Security Manager (ISSM)
Cloud Information System Security Manager (ISSM)

Applied Research Solutions • Beavercreek Township (OH)

On-site
USD 110,000 - 160,000
Senior Cybersecurity Engineer / DevSecOps Engineer
Senior Cybersecurity Engineer / DevSecOps Engineer

PingWind, Inc. • United States

On-site
USD 92,000 - 127,000
Eleven Federal Holidays
Paid Time Off
Parental Leave
+10
Sr. Azure Security Engineer
Sr. Azure Security Engineer

Arena Technical Resources, LLC (ATR) • United States

On-site
USD 120,000 - 150,000
Cloud Security Engineer
Cloud Security Engineer

ECS • Fairfax (VA)

Hybrid
USD 120,000 - 160,000