Sr. Security Engineer

Iris Consulting Corporation

Atlanta (GA)

Hybrid

USD 72,000 - 85,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Health insurance
Dental insurance
Vision insurance
Short/Long term disability
Group life pending eligibility

Job summary

Iris Consulting Corporation in Atlanta seeks a Senior Information Security Compliance Engineer to support government compliance programs, align with NIST/ISO controls, develop SSPs, and manage third-party risk.

You will conduct audits, craft policies, implement controls, coordinate with IT and facilities, and drive audit readiness with ongoing documentation.

Qualifications

  • Demonstrated experience in IT audit with ability to evaluate control evidence for regulatory and industry requirements.
  • Deep understanding of NIST SP 800-171 or comparable control frameworks (NIST SP 800-53, NIST CSF, ISO/IEC 27001/27002, FedRAMP, PCI DSS, CIS).
  • Ability to interpret regulatory requirements and summarize to senior leadership.
  • Strong written and verbal communication across channels and levels.
  • Self-starter capable of independent work and delivering actionable results.
  • Passion for learning government compliance standards.
  • Proficient in drafting policies and interpreting procedures.
  • Identifying, implementing, and managing security controls.
  • Experience collecting evidence for audits and assessments.
  • Solid grasp of IT security, network architecture, and cloud computing.
  • Prior experience in a GRC organization or similar role.

Responsibilities

  • Support government compliance program and regulatory alignment.
  • Develop and maintain System Security Plans (SSPs) and supporting documentation.
  • Perform risk assessments, audits, and control testing.
  • Identify and implement security controls across IT, cloud, and network domains.
  • Lead incident response coordination and evidence collection.
  • Draft and interpret security policies and procedures.
  • Coordinate with internal teams and third parties on compliance activities.
  • Monitor legal, regulatory, and industry changes impacting IT security.

Skills

IT audit
Regulatory compliance
NIST 800-171
Control frameworks
Policy drafting
GRC
Security controls
Audit evidence
Cloud security
Network security

Job description

Pay range: $52.32 – 62.32
Plus Health, Dental, Vision, Short Term/Long Term Disability, and Group Life pending eligibility.

Responsible for the design, testing, evaluation, implementation, support, management, and deployment of security systems/devices used to safeguard the organization’s information assets. Also responsible for analyzing the information security environment and assisting with the development of security measures to safeguard information against accidental or unauthorized modification, destruction, or disclosure.

  • Works with the technical team to recover data after a security breach.
  • Configures and installs firewalls and intrusion detection systems.
  • Develops automation scripts to handle and track incidents.
  • Investigates intrusion incidents, conducts forensic investigations and mounts incident responses.
  • Delivers technical reports and formal papers on test findings.
  • Installs firewalls, data encryption, and other security measures.
  • Maintains access by providing information, resources, and technical support.
  • Ensures authorized access by investigating improper access; revoking access; reporting violations; monitoring information requests by new programming; recommending improvements.
  • Updates job knowledge by participating in educational opportunities; reading professional publications; maintaining personal networks; participating in professional organizations.
  • Accomplishes information systems and organization mission by completing related results as needed.
  • Builds, deploys, and tracks security measurements for computer systems and networks.
  • Mitigates security vulnerabilities by implementing applicable solutions and tools.
  • Performs vulnerability testing, risk analyses, and security assessments.
  • Collaborates with colleagues on authentication, authorization, and encryption solutions.
  • Tests security solutions using industry standard analysis criteria.
  • Responds to information security issues during each stage of a project’s lifecycle.
  • Performs risk assessments and testing of data processing systems.
  • Establishes system controls by developing framework for controls and levels of access; recommending improvements
  • Establishes computer and terminal physical security by developing standards, policies, and procedures; coordinates with facilities security; recommends improvements.
  • Safeguards computer files by performing regular backups; developing procedures for source code management and disaster preparedness; recommends improvements.
  • Determines the sensitivity of the data in order to recommend the appropriate security needs.
  • Develops proposals for, and consider cost effective equipment options to satisfy security needs.
  • Communicates with the technical team, management team and users companywide if data security is breached.
  • Designs infrastructure to alert the technical team of detected vulnerabilities.
  • Evaluates new technologies and processes that enhance security capabilities.
  • Supervises changes in software, hardware, facilities, telecommunications and user needs.
  • Defines, implements, and maintains corporate security policies.
  • Analyzes and advises on new security technologies and program conformance.
  • Creates, tests, and implements network disaster recovery plans.
  • Recommends security enhancements and purchases.
  • Trains staff on network and information security procedures.
  • Develops security awareness by providing orientation, educational programs, and on-going communication.
  • Recommends modifications in legal, technical and regulatory areas that affect IT security.

Quals–

Senior Information Security Compliance Engineer

Location: *** – Atlanta Office Department: Information Security – Governance, Risk & Compliance

Work Environment: A hybrid work schedule, as defined by the department, is possible following the initial onboarding phase, depending on business needs and individual performance. The hybrid schedule may be modified at the manager’s discretion, business needs, and various audit / assessment activities requiring more focused onsite work.

Overview: This role is primarily responsible for supporting the organization’s government compliance program, ensuring adherence to applicable foreign and domestic regulatory requirements and maintaining alignment with mandated cybersecurity and IT compliance frameworks. In support of this mission, the position also contributes to broader Information Security Compliance efforts by executing special projects driven by evolving regulatory and cybersecurity requirements, processing and responding to third-party risk management questionnaires, developing and maintaining documentation of processes and procedures to support audit readiness and operational consistency, and assisting with additional Information Security Compliance activities as needed to strengthen the organization’s overall compliance posture.

Required Qualifications:
  • Demonstrated experience in Information Technology audit, with the ability to identify, evaluate, and validate control evidence sufficient to support and demonstrate compliance with regulatory and industry requirements.
  • Deep understanding of NIST SP 800-171 or comparable control frameworks (e.g., NIST SP 800-53, NIST Cybersecurity Framework, ISO/IEC 27001/27002, FedRAMP, PCI DSS, or CIS Critical Security Controls), with the ability to rapidly apply control-based concepts across regulatory environments.
  • Ability to research and interpret new regulatory requirements, providing concise summaries to senior leadership
  • Strong written and verbal communication skills across multiple channels and organizational levels
  • Self-starter with the ability to work independently and deliver clear, actionable results
  • Demonstrated passion for learning and applying government compliance standards
  • Skilled in drafting and interpreting policies and procedures
  • Proficient in identifying, implementing, and managing security controls
  • Knowledgeable in collecting and interpreting evidence and artifacts for audits and assessments
  • Solid grasp of IT domains including information security, network architecture, and cloud computing
  • Prior experience in Governance, Risk & Compliance (GRC) organization or comparable role
Preferred Qualifications:
  • Prior experience with U.S. Government IT compliance requirements
  • Experience developing and maintaining System Security Plans (SSPs)
  • Project management experience and ability to drive action across functional areas
  • Foundational understanding of emerging AI tools and technologies, with the ability to evaluate their application for enhancing productivity and automation while identifying associated risks, potential misuse, and impacts to the organization’s security and compliance posture
  • Experience in the aviation industry
Desired Certifications:
  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Systems Auditor (CISA)
  • Certified in Risk and Information Systems Control (CRISC)

Equal opportunity employer including disability/veterans.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. Security Engineer
Sr. Security Engineer

Motion Recruitment • Atlanta (GA), Northern (KY)

Hybrid
USD 90,000 - 130,000
Senior Information Security Engineer
Senior Information Security Engineer

Grayson Search Partners • Nashville (TN)

On-site
USD 120,000 - 150,000
Information Security Engineer
Information Security Engineer

eTrepid • Mechanicsville (MD)

On-site
USD 90,000 - 130,000
Senior Information Security Compliance Engineer
Senior Information Security Compliance Engineer

Crestron Electronics Inc. • Plano (TX)

On-site
USD 94,000 - 151,000
Senior IT Security Compliance Analyst
Senior IT Security Compliance Analyst

The Stafford Gray Group • Lansing (MI)

On-site
USD 90,000 - 120,000
Senior Security Engineer
Senior Security Engineer

Prestige Staffing • Georgia

On-site
USD 140,000 - 200,000
Senior Security Engineer
Senior Security Engineer

Zermount, Inc. • United States Virgin Islands

On-site
USD 100,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Hiring Our Heroes • Arlington (VA)

On-site
USD 120,000 - 150,000
Manager of Information Security and Compliance
Manager of Information Security and Compliance

iboss • United States

On-site
USD 100,000 - 130,000
Health, Vision, Dental
401(k) with company match
Unlimited Paid Time Off
+1
Sr. Security Analyst
Sr. Security Analyst

NLB Services • Atlanta (GA)

On-site
USD 110,000 - 170,000