Security Operations & Assessment Engineer

Gilder Search Group

Washington, Northern (District of Columbia, KY)

Hybrid

USD 110,000 - 170,000

Full time

14 days+
Application generator

Get a reply from this recruiter — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Pay for Life
AD&D
Short-term disability
Long-term disability
Health insurance premium contribution
401k after 3 months
Safe Harbor 3% yearly
Paid training & course reimbursement

Job summary

Aderas in Washington, DC is seeking a Security Operations and Forensics Associate to coordinate security operations, perform forensic analysis, and support investigations across the enterprise.

The role requires hands-on experience with FedRAMP/NIST frameworks, experience in continuous monitoring, and security tool deployment. U.S. citizenship with Secret/T3 clearance preferred.

Qualifications

  • Bachelor's degree or higher in Information Systems Management, Information Technology, Cybersecurity, Computer Science, Business, Management, Engineering, or another related discipline.
  • Certifications such as CISSP, CISA, CISM, CAP, CRISC, or CCSP preferred.
  • Min. Five (5) years of professional IT experience with a master's degree OR six (6) years of experience with a bachelor's degree.

Responsibilities

  • Coordinate security operations and assist investigations.
  • Perform forensic analysis on digital media to identify malicious content.
  • Maintain visibility into the enterprise and filter threat data into actionable intelligence.
  • Produce quarterly certification reporting aligned to CR26 formats.
  • Provide security engineering support for SOC tools and technologies.
  • Develop SAPs, ROEs, SARs, POA&M and ATO letters.
  • Advise CISO on SOC architecture and security controls.
  • Lead vulnerability assessments and remediation actions.

Skills

Automation workflows
FedRAMP
NIST RMF
NIST 800-53
Continuous monitoring
POA&M management
Documentation
Scripting

Education

Bachelor's degree

Tools

SIEM
Automation scripting

Job description

Primary Job Duties:
  • Work closely with the organization to coordinate security operations and deliver or request assistance or assist with investigations
  • Perform forensic analysis on various digital media devices and mediums to identify, reverse engineer, and obfuscate content related to an incident, such as malicious content.
  • Provide support to detect, prevent, and respond to threats posed by malicious, negligent, or compromised insiders by maintaining in-depth visibility into the DFC Enterprise and having a means of filtering and prioritizing threat data into concise, actionable intelligence.
  • Coordinate and produce quarterly certification reporting (in alignment with CR26) incorporating significant system updates, vulnerability posture, and incident lessons learned, aligned to required formats/timelines
  • Provide security engineering and subject matter expertise to conduct market research, product evaluation, testing, configuration, deployment, operations, and maintenance support for various SOC software tools and technologies
  • Create procedures and documentation for maintaining all SOC hardware and software
  • Facilitate and perform remediation actions based on the results of ongoing monitoring activities and the outstanding items in the POA&M
  • Provide technical expertise in cyber adversary capabilities and an assessment of the intentions of these groups to conduct Computer Network Exploitation (CNE) and Computer Network Attack (CNA) against U.S. private sector and Government networks and information systems.
  • Provide onsite and remote vulnerability assessment capabilities as a sustained, full-time program independent of incident detection, recovery, or reporting activities.
  • Provide both internal and external security testing in which assessors mimic real-world attacks to identify methods for circumventing the security features of an application, system, and network.
  • Work with the DFC CIRT or any other pertinent parties (including external vendors) at any DFC location to recover from any incident
  • Advise and assist the Chief Information Security Officer (CISO) with SOC architecture activities for all DFC SOC information systems initiatives supporting all SOC tools and capabilities.
  • Determine and document the security impact of proposed or actual changes to the information systems and their environment of operation
  • Assess the technical, management, and operational security controls employed within and inherited by the information systems including support for collaborative continuous monitoring and adaptation to agency-specific continuous monitoring strategies
  • Develop Security Assessment Plans (SAPs) and Rules of Engagement (ROE). Review and provide feedback on the System Security Plan (SSP). Develop Security Assessment Reports (SAR), Plan of Action & Milestones (POA&Ms) and Authorization to Operate (ATO) letters.
  • Reporting must incorporate vulnerabilities, significant changes, and incident lessons learned, and support quarterly certification reporting requirements
Required Experience/Skills
  • Assessment experience and actual technical knowledge.
  • Design/operate automation workflows that produce machine-readable compliance evidence and reporting inputs from SOC/security tools.
  • Maintain structured traceability from requirements/rules → control implementation → evidence → findings → POA&M closure validation.
  • Hands-on technical knowledge (FedRAMP, NIST RMF, NIST 800-53, NIST SP 800-37, FISMA, A&A, POA&M management, SSP/SAR updates).
  • Operational SOC experience (continuous monitoring, remediation, change impact analysis).
  • Automation and documentation capability (process improvement, scripting, repeatable procedures).
Required Education & Work Experience:
  • Bachelor's degree or higher in Information Systems Management, Information Technology, Cybersecurity, Computer Science, Business, Management, Engineering, or another related discipline
  • Certification such as CISSP, CISA, CISM, CAP, CRISC, or CCSP preferred
  • Min. Five (5) years of professional IT experience with a master's degree OR six (6) years of experience with a bachelor's degree

Clearance/Citizenship: U.S. Citizen with Secret/T3 clearance

Location: Hybrid in Washington, DC

Join the Aderas team!

Aderas is looking to recruit and retain only the best and brightest. If you like working with emerging technologies, using your unique personal skills to solve technical, functional, and organizational issues, and can easily adapt to the ever-changing IT market, then Aderas is the place for you! We are a vibrant company delivering implementation services & support for enterprise solutions and custom application development. We strive to form long-term partnerships with our clients to foster an environment based on trust, a proven history of delivery, and camaraderie.

Why Aderas?

We sincerely try to shape our employees' lives by administering a generous package of employee benefits. Our company culture encourages collaboration, creative thinking, and growth.

Beyond the tangible and intangible rewards, Aderas provides the following:
  • Pay for Life, AD&D, Short-term disability, and Long-term disability at no cost to the employee.
  • Employer contribution toward monthly health insurance premiums.
  • 401k plan which employees are eligible for after being with the company for 3 months.
  • Safe Harbor plan in which Aderas contributes 3% of employees' salaries once a year
  • A week of paid training and reimbursement for approved professional courses and tests.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, Information Security
Manager, Information Security

Aderant • United States

On-site
USD 140,000 - 200,000
Authorizing Official Designated Representative (AODR) Support Analyst
Authorizing Official Designated Representative (AODR) Support Analyst

ECS • Washington

Hybrid
USD 170,000 - 190,000
Cybersecurity - Cyber Defense Analyst - Malware, Vulnerability, Incidents
Cybersecurity - Cyber Defense Analyst - Malware, Vulnerability, Incidents

Erias Ventures, LLC • Fort Meade (MD)

On-site
USD 210,000 - 232,000
Above market pay
401k with vesting
Spot bonuses
+12
Manager, Information Security
Manager, Information Security

Aderant Holdings, Inc. • Northern (KY)

Hybrid
USD 120,000 - 190,000
Cybersecurity Systems Analyst, Intermediate
Cybersecurity Systems Analyst, Intermediate

TJ Consulting Group • Fort Walton Beach (FL)

On-site
USD 90,000 - 120,000
PTO
Holiday Pay
401K with Match
+6
Cybersecurity - Cyber Defense Analyst - Malware, Vulnerability, Incidents 7/2/2026 Fort Meade, MD
Cybersecurity - Cyber Defense Analyst - Malware, Vulnerability, Incidents 7/2/2026 Fort Meade, MD

Erias Ventures, LLC • Fort Meade (MD)

On-site
USD 210,000 - 232,000
100% Company Paid Vision and Dental Coverage
Flexible Work Schedules
Professional Development Bonuses
Cybersecurity Systems Analyst, Intermediate
Cybersecurity Systems Analyst, Intermediate

TJ Consulting Group • Tampa (FL)

On-site
USD 90,000 - 130,000
PTO
Holiday Pay
401K Match
+11
A&AS - Cybersecurity Specialist
A&AS - Cybersecurity Specialist

Sawdey Solution Services • Fort Belvoir (VA)

Hybrid
USD 135,000 - 180,000
Competitive compensation package
Health, dental, vision benefits
HSA with employer contributions
+6
Cybersecurity Systems Analyst, Sr.
Cybersecurity Systems Analyst, Sr.

TJ Consulting Group • Town of Texas (WI)

On-site
USD 120,000 - 122,000
PTO
Holiday Pay
401K with 4% match
+12
Cybersecurity Engineer
Cybersecurity Engineer

CyberJobs.Com • Springfield (VA)

On-site
USD 130,000 - 140,000
Health, Dental, Vision
401(k) match
Paid time off (PTO)
+1