If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.
Security Engineer-Senior
US
17 days ago Requisition ID: 1150
This position is contingent upon contract award
Wichita Tribal Enterprises (WTE), a Quivera Enterprises subsidiary, is seeking a Security Engineer – Senior. The Security Engineer – Senior is a senior-level technical cybersecurity professional responsible for designing, implementing, assessing, and maintaining security controls within complex federal information technology environments.
This position serves as a senior cybersecurity practitioner and subject matter expert supporting the Risk Management Framework (RMF), Assessment & Authorization (A&A), Security Technical Implementation Guide (STIG) compliance, continuous monitoring, vulnerability and risk management, and enterprise security engineering. The Security Engineer – Senior provides strategic cybersecurity leadership, develops and evaluates technical security documentation, and ensures information systems comply with National Institute of Standards and Technology (NIST) requirements, federal cybersecurity standards, Departmental policies, and mission requirements.
The ideal candidate will have relevant federal Government IT or consulting experience with a focus on IT security policies, federal STIG control processes, security architectures, and Standard Operating Procedures (SOPs). This position requires direct experience conducting RMF and security assessment activities in accordance with NIST SP 800-37 and performing technical security assessments of complex information systems, network infrastructure, and industrial control systems with minimal to no supervision.
Key Responsibilities
Risk Management Framework (RMF) & Assessment and Authorization
- Lead execution of all RMF lifecycle activities in accordance with NIST SP 800-37 and applicable federal and Departmental requirements.
- Support system categorization, security control selection, implementation, assessment, authorization, and continuous monitoring activities.
- Lead and support A&A activities for new and existing federal information systems.
- Develop, evaluate, review, and maintain System Security Plans (SSPs), System Security and Privacy Plans (SSPPs), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), Plans of Action and Milestones (POA&Ms), and other required A&A artifacts.
- Ensure security authorization documentation accurately reflects system architecture, security controls, identified risks, vulnerabilities, and remediation activities.
- Apply established federal A&A methodologies, NIST guidance, and cybersecurity industry best practices throughout the system lifecycle.
- Provide technical recommendations regarding system authorization readiness, security control effectiveness, and cybersecurity risk.
Security Categorization & Control Selection
- Collaborate with Information System Owners, security officers, developers, engineers, system administrators, and IT operations personnel to conduct system security categorizations.
- Perform or support system categorization activities in accordance with NIST SP 800-60, FIPS 199, and applicable federal requirements.
- Document security control selections and associated implementation requirements.
- Apply security control tailoring guidance in accordance with NIST SP 800-53, NIST SP 800-18, and applicable agency requirements.
- Evaluate system architecture and mission requirements to determine appropriate security control implementations.
- Review system changes to determine potential impacts to security categorization, controls, and authorization status.
Security Control Assessment
- Develop comprehensive Security Assessment Plans for federal information systems.
- Conduct technical security assessments of selected management, operational, and technical security controls.
- Assess security controls in accordance with NIST SP 800-53 and applicable federal and agency requirements.
- Evaluate security control design, implementation, operating effectiveness, and supporting evidence.
- Conduct technical security assessments of complex information systems, network infrastructure, and applicable industrial control systems with minimal to no supervision.
- Document security assessment findings, deficiencies, vulnerabilities, risks, and recommendations.
- Document assessment and concurrent risk assessment results within Security Assessment Reports.
- Evaluate compensating and alternative security controls when appropriate.
- Provide technical guidance regarding corrective actions and mitigation strategies.
POA&M & Remediation Management
- Develop and maintain Plans of Action and Milestones documenting identified cybersecurity weaknesses.
- Document recommended remediation or mitigation actions for identified findings.
- Assign or recommend weakness criticality ratings based on risk assessment results.
- Track identified security weaknesses and remediation activities through closure.
- Validate corrective actions and supporting evidence.
- Assist system owners and technical teams with prioritizing remediation activities based on risk, vulnerability severity, and mission impact.
- Identify recurring or systemic weaknesses and recommend enterprise-level corrective actions.
Risk & Vulnerability Management
- Perform cybersecurity risk assessments in accordance with NIST guidance and applicable agency requirements.
- Conduct vulnerability analyses of federal information systems and supporting infrastructure.
- Analyze vulnerabilities, weaknesses, threats, and technical findings to determine potential operational and mission impacts.
- Develop mitigation plans and recommend appropriate risk response strategies.
- Support vulnerability remediation activities and evaluate findings generated by security assessment and scanning tools.
- Provide technical recommendations regarding risk acceptance, mitigation, remediation, or compensating controls.
- Support contingency planning, disaster recovery, and configuration management activities from a cybersecurity perspective.
- Provide senior-level administrative and technical cybersecurity support to the Indian Affairs (IA) RMF and Continuous Monitoring Programs.
- Support the development, implementation, and maintenance of continuous monitoring strategies and processes.
- Conduct periodic assessments of security controls to determine continued effectiveness.
- Monitor security posture, vulnerabilities, configuration changes, POA&Ms, assessment findings, and other indicators of cybersecurity risk.
- Analyze continuous monitoring results and recommend corrective actions.
- Support ongoing authorization activities and security posture reporting.
- Identify cybersecurity trends, systemic weaknesses, and opportunities to improve enterprise security controls.
- Provide strategic security control implementation and assessment support.
Federal STIG & Security Compliance
- Apply federal Security Technical Implementation Guides (STIGs), secure configuration requirements, and agency-specific cybersecurity guidance.
- Support implementation, assessment, and verification of applicable STIG controls.
- Review system configurations and security baselines for compliance with federal requirements.
- Evaluate STIG findings and provide technical recommendations for remediation.
- Coordinate with technical teams to resolve configuration and security compliance deficiencies.
- Support configuration management activities to maintain secure system baselines.
- Evaluate system changes for potential impacts to security controls and authorization status.
- Develop and maintain security-related policies, technical standards, procedures, and implementation guidance.
Security Engineering
- Provide cybersecurity engineering support throughout the system development and operational lifecycle.
- Review system architectures, network designs, infrastructure configurations, and technical solutions for cybersecurity risks and compliance requirements.
- Recommend security controls and technical safeguards appropriate to system architecture, data sensitivity, and mission requirements.
- Integrate cybersecurity requirements into system design, development, implementation, operations, maintenance, and modernization activities.
- Provide direct information assurance and cybersecurity guidance regarding information systems, network infrastructure, and industrial control systems.
- Support secure configuration, vulnerability remediation, contingency planning, disaster recovery, and configuration management.
- Provide cybersecurity expertise during system upgrades, migrations, infrastructure changes, and modernization initiatives.
IA Security Program Support
- Provide multidisciplinary administrative and technical security support to the IA RMF and Continuous Monitoring Programs.
- Support Physical, Computer, Personnel, Information, Administrative, Operational, and Communications Security analysis, assessment, and reporting.
- Develop and maintain cybersecurity policies, procedures, standards, assessment documentation, and technical guidance.
- Provide strategic recommendations regarding security control implementation and assessment.
- Prepare cybersecurity reports, briefings, metrics, risk analyses, and recommendations for technical and leadership stakeholders.
- Participate in technical meetings, cybersecurity working groups, security reviews, and risk discussions.
- Collaborate with federal stakeholders, system owners, ISSOs, engineers, developers, administrators, and other cybersecurity professionals.
- Perform other related duties as assigned.
Required Qualifications
Education & Experience
Candidates must meet one of the following combinations of education and relevant professional experience:
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Engineering, or a related technical field and a minimum of four (4) years of relevant experience;OR
- Master's degree in a related technical discipline and a minimum of three (3) years of relevant experience;OR
- Minimum of six (6) years of relevant professional experience without a degree.
An industry-recognized technical certification may be accepted in lieu of up to two (2) years of experience, subject to contract requirements.
Required Knowledge, Skills & Abilities
- Relevant federal Government IT, cybersecurity, information assurance, or consulting experience.
- Direct experience delivering RMF and security assessment activities in accordance with NIST SP 800-37.
- Detailed knowledge of NIST SP 800-53 security and privacy controls.
- Knowledge of NIST SP 800-60, FIPS 199, NIST SP 800-18, and related federal cybersecurity guidance.
- Thorough knowledge of federal A&A/RMF methodologies and processes.
- Experience developing and maintaining SSPs/SSPPs, SARs, RARs, POA&Ms, Security Assessment Plans, and other system authorization artifacts.
- Experience implementing, assessing, and documenting management, operational, and technical security controls.
- Experience conducting technical security assessments of complex information systems and network infrastructure.
- Knowledge and experience with federal STIG control processes.
- Expert knowledge of risk assessment and risk management methodologies.
- Experience performing vulnerability analysis and developing mitigation plans.
- Knowledge of contingency planning and disaster recovery requirements.
- Experience with configuration management and secure configuration practices.
- Ability to conduct complex technical security assessments with minimal to no supervision.
- Strong analytical, technical writing, documentation, and problem-solving skills.
- Ability to communicate cybersecurity risks, technical findings, and remediation recommendations to technical and non-technical stakeholders.
- Ability to work independently and collaboratively within complex federal environments.
Preferred Qualifications
- Experience supporting Indian Affairs, the Department of the Interior, or another federal agency cybersecurity program.
- Experience developing federal IT security policies, architectures, technical standards, and SOPs.
- Experience supporting federal RMF and continuous monitoring programs.
- Experience implementing, assessing, or validating federal STIG controls.
- Experience assessing industrial control systems or Operational Technology (OT) environments.
- Experience supporting enterprise cybersecurity engineering initiatives.
- Experience working within complex federal IT modernization programs.
- Relevant industry-recognized cybersecurity certifications such as CISSP, CGRC, CISM, SecurityX/CASP+, Security+, or equivalent certifications.
Clearance & Security Requirements
- Must have the ability to successfully complete the required federal background investigation.
- Must have the ability to obtain and maintain the required Government security clearance, suitability determination, or Public Trust designation as required by the contract.
- Must comply with all applicable federal customer security, privacy, confidentiality, cybersecurity, and information assurance requirements.
Physical Demands
The physical demands described here are representative of those that must be met by an employee, with or without reasonable accommodation, to successfully perform the essential functions of this position.
This position is primarily performed in a professional office or technical environment and requires prolonged periods of sitting and working at a computer. The employee must be able to:
- Frequently use computers and standard office equipment.
- Communicate effectively through verbal, written, and electronic means.
- Maintain visual acuity necessary for reviewing technical documentation, security assessment results, system configurations, diagrams, and computer displays.
- Occasionally stand, walk, bend, reach, and lift or carry standard office or computer equipment.
- Work extended or irregular hours when required to support security assessments, system implementations, cybersecurity incidents, or other mission requirements.
Quivera Enterprises LLC and its subsidiaries are 100% tribally owned and SBA-certified Small Disadvantaged Businesses. We are proud to be an Equal Opportunity Employer and are committed to creating an inclusive workplace where all qualified applicants receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veteran status, or any other status protected by applicable federal, state, or local law.
As a tribally owned organization, Quivera Enterprises and its subsidiaries may apply Indian Preference in accordance with applicable tribal, federal, and contractual requirements where authorized by law.