Summary
We are looking for a highly talented, technical hands‑on Senior Security Engineer to develop and implement strategies to protect computer systems, networks, and other digital assets from malicious attacks. The role involves working with a team of IT professionals to design and deploy new security measures, update existing ones, and lead the development of solutions that patch holes and keep sensitive data safe.
Duties and Responsibilities
- Develop and integrate with other cybersecurity workflows, including ATO intake, assessment, and vulnerability scanning.
- Perform security reviews based on RMF controls compliance, client needs, and security best practices.
- Provide security input on Cloud Center of Excellence (CCOE) and Cloud Advisory Council (CAC) agenda items by participating in technical working groups, providing analysis, and recommendations.
- Conduct architecture design reviews, configuration and log reviews, and network traffic analyses.
- Produce a SAR report detailing the architecture strengths and findings.
- Design and deploy native cloud security services in AWS, Microsoft Azure, and Google Cloud.
- Validate the proof of value of cloud‑native, COTS, third‑party, or open‑source security capabilities through hands‑on deployment and evaluation against security requirements.
- Develop scripts or code to perform cloud security assessments using cloud‑native APIs or SDKs.
- Create enterprise‑cloud security blueprints that embed security within Infrastructure as Code (IaC) templates.
- Analyze the impact of emerging technologies on existing security systems and identify potential risks.
- Research new and emerging security practices and capabilities such as AI/ML to address compliance and mitigate risk.
- Improve cloud security monitoring by ingesting logs (API, application/database, flow logs) into a SIEM.
- Increase cloud vulnerability coverage in OS, application code, and infrastructure layers.
- Develop architecture for integrating findings into a centralized dashboard that provides product owners direct access to specific systems or cloud account findings.
Work With Cybersecurity Authorizations and Compliance Branch (CACB)
- Conduct studies and analysis of proposed operations modifications.
- Provide end‑to‑end architecture trade‑off assessments.
- Develop strategic and tactical plans.
- Conduct evaluation of new program requirements.
- Investigate and develop new technologies for possible operations modifications.
- Develop standards and solutions to meet client requirements.
Required Skills
- High level of attention to detail, needs minimal guidance, effective verbal and written communication.
- Equally adept at strategic planning and operational/technical level.
- Able to adapt to new and changing requirements or priorities and manage work and resources accordingly.
- At least 5 years (preferred 10 years) of experience with networks, systems, and applications: LAN/WAN, WAF/CDN/DDOS, network firewalls, IDS/IPS.
- Experience with virtualization, hypervisor security, and container security.
- Experience with application development, serverless security, microservices, and CI/CD.
- At least 5 years of designing and/or implementing security in the cloud (AWS required, Azure or GCP optional).
- Experience with multi‑cloud, hybrid cloud, IaaS, PaaS, SaaS, and shared responsibility model.
- Hands‑on knowledge of AWS services: IAM, KMS, S3, RDS, SNS/SQS, Organization, GuardDuty, SecurityHub, Detective, Config, CloudTrail, CloudWatch, Lambda.
- Hands‑on knowledge of Azure services: E3/E5, Active Directory, Blob, Azure Security Center, Key Vault, SSE, Monitor, Log Analytics, Policy.
- Experience with DevSecOps strategy and implementation and designing architecture per RMF, CSF, FISMA, and FedRAMP.
- Familiarity with ZTNA, SASE framework, ICAM (OKTA), CWPP, SOC operations, vulnerability threat management, and compliance.
- At least 2 years managing Agile, DevOps, Scrum, or Kanban.
- Cloud architecture, networking, and cybersecurity experience.
Education
Candidate must have a Bachelor of Science (or higher) in computer engineering, computer science, information technology, or cybersecurity. The résumé may reference another major, so long as the degree addresses at least one of the following: cybersecurity engineering, systems administration, information systems security, software development security, systems engineering, information systems, or IT.
Certifications
Certified Information Systems Security Professional (CISSP) is required. Candidates may also hold one or more of the following: Certified Cloud Security Professional, AWS Certified Solutions Architect – Associate, AWS Certified Security – Specialty, Microsoft Azure Solutions Architect, Google Professional Cloud Architect.
Clearance
Public Trust
Work Location & Core Hours
Washington, D.C. – Metro area, Full‑time