Unknown Company

Mid Security Information Assurance Engineer

co • Posted 4 days ago
Onsite Full Time Engineering

Responsibilities

  • Serve as a security engineer embedded with an Agile program delivering GEOINT capabilities to the National Geospatial-Intelligence Agency (NGA)
  • Engineer security into modern, cloud-native systems rather than bolting it on after the fact
  • Design and implement security controls across applications, platforms, and infrastructure in accordance with RMF and NGA standards
  • Integrate security tooling and automated compliance checks into CI/CD pipelines (DevSecOps)
  • Perform system hardening, vulnerability assessment, and remediation across development and production environments
  • Support security assessment and authorization activities in coordination with Government ISSMs and assessors
  • Analyze findings, develop mitigation strategies, and maintain POA&Ms through closure
  • Advise development teams on secure design, secure coding, and security architecture decisions
  • Document security engineering artifacts supporting ATO and continuous monitoring

Requirements

  • TS/SCI Security Clearance with ability to obtain Polygraph
  • Bachelor's degree in Cybersecurity, Computer Science, or related technical discipline (equivalent experience accepted)
  • 4+ years of security engineering or information assurance experience
  • Experience implementing NIST RMF controls on DoD or IC systems
  • Hands-on experience with STIG hardening, ACAS/Nessus, and security remediation
  • DoD 8570/8140 IAT Level II certification (Security+ CE or equivalent)
  • Ability to work on-site at a Government facility.

Core Competencies

Demonstrates expertise in security engineering within Agile environments, focusing on the integration of security controls and compliance in cloud-native systems. Proficient in implementing NIST RMF controls and conducting vulnerability assessments while maintaining security documentation and artifacts.

#J-18808-Ljbffr
Back to Job Search