Security Operations Engineer
Core
Own the day-to-day operation and continuous improvement of vulnerability and compliance scanning programs across commercial and FedRAMP environments.
Role type
Security Operations Engineer (Vulnerability & Compliance)
Builds
Security scanning tooling and processes for web applications, infrastructure, and container environments
Domain
Cybersecurity, Compliance (FedRAMP, NIST 800-53)
Required skills
Vulnerability scanning (Burp Suite, Nessus, Tenable), AWS cloud infrastructure, Container environments (Kubernetes, Docker), Compliance frameworks (FedRAMP, NIST 800-53), Ticket management (Jira), Scripting (Python, Bash)
Preferred skills
Wiz, eMASS, Automation, Alerting, Result normalization
Technologies
Burp Suite, Nessus, Sysdig, Wiz, AWS, Kubernetes, Docker, Chainguard, Jira, eMASS
Responsibilities
Operate and maintain vulnerability scanning tools across web applications, infrastructure/network, and container/runtime environments; Run scans on a regular cadence and on-demand for releases, audits, and special initiatives; Support FedRAMP continuous monitoring (ConMon) activities across US GovCloud environments; Assist with evidence collection and compliance tracking; Triage scan results, identify and filter false positives, prioritize findings by risk, and open/track remediation tickets; Partner with engineering teams to ensure SLA adherence and timely remediation; Produce reports and compliance artifacts for internal stakeholders and external auditors; Contribute to and maintain the compliance evidence repository; Improve scanning workflows through automation, scheduling, alerting, and result normalization (via careerplan.io/jobs/09-00A-F3-A6C-security-operations-engineer-at-island)
Seniority
Entry-level to Mid-level, hands-on IC
