Senior Information Systems Security Engineer - Alexandria
Core
Senior Information Systems Security Engineer supporting the Risk Management Framework (RMF) lifecycle, cloud security compliance, and security control implementation for government IT systems.
Role type
Senior IC Information Systems Security Engineer
Builds
Security controls, compliance documentation (SSPs, SARs, POA&Ms), and secure cloud environments (AWS GovCloud, Azure Government)
Domain
US Government / Cybersecurity / Cloud Infrastructure
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
RMF lifecycle management, cloud security compliance (FedRAMP DoD IL2/4/5/6), virtualized/cloud system security, identity and access management (ICAM), vulnerability analysis and mitigation, network security (WAN/LAN, firewalls), endpoint management, technical design review, documentation of security controls
Preferred skills
Experience with DevSecOps environments, collaboration with infrastructure and cloud engineering teams, coordination with Authorizing Officials (AOs)
Technologies
AWS GovCloud, Azure Government, Citrix, VMware Horizon, GitLab, Jenkins, Nexus, Trellix, MECM, InTune, ACAS, SolarWinds, PIV/CAC, MFA, SSO, RBAC, BCAP, SNAP
Responsibilities
Support the RMF lifecycle including categorization, control selection, assessment, and authorization; Develop and maintain System Security Plans (SSPs), Security Assessment Reports (SARs), and Plans of Action and Milestones (POA&Ms); Evaluate and document compliance for FedRAMP DoD baselines; Analyze and mitigate vulnerabilities from automated scans; Coordinate with ISSOs and Authorizing Officials to uphold Authority to Operate (ATO) status; Facilitate approvals for network interconnections (BCAP, SNAP); Support Product Teams in responding to and remediating findings from Cyber Operational Readiness Assessments (CORAs)
Seniority
Senior, hands-on IC