Responsibilities
- Serve as a security engineer embedded with an Agile program delivering GEOINT capabilities to the National Geospatial-Intelligence Agency (NGA)
- Engineer security into modern, cloud-native systems rather than bolting it on after the fact
- Design and implement security controls across applications, platforms, and infrastructure in accordance with RMF and NGA standards
- Integrate security tooling and automated compliance checks into CI/CD pipelines (DevSecOps)
- Perform system hardening, vulnerability assessment, and remediation across development and production environments
- Support security assessment and authorization activities in coordination with Government ISSMs and assessors
- Analyze findings, develop mitigation strategies, and maintain POA&Ms through closure
- Advise development teams on secure design, secure coding, and security architecture decisions
- Document security engineering artifacts supporting ATO and continuous monitoring
Requirements
- TS/SCI Security Clearance with ability to obtain Polygraph
- Bachelor's degree in Cybersecurity, Computer Science, or related technical discipline (equivalent experience accepted)
- 4+ years of security engineering or information assurance experience
- Experience implementing NIST RMF controls on DoD or IC systems
- Hands-on experience with STIG hardening, ACAS/Nessus, and security remediation
- DoD 8570/8140 IAT Level II certification (Security+ CE or equivalent)
- Ability to work on-site at a Government facility.
Core Competencies
Demonstrates expertise in security engineering within Agile environments, focusing on the integration of security controls and compliance in cloud-native systems. Proficient in implementing NIST RMF controls and conducting vulnerability assessments while maintaining security documentation and artifacts.
#J-18808-Ljbffr