Principal Information Security Engineer
Job description
About the role
You will manage and develop artifacts required to obtain a government continuous authorization to operate for classified cloud environments. You will develop and integrate cybersecurity best practices for Kubernetes clusters and DevOps pipelines within a DevSecOps framework. You will create and update artifacts such as SSPs, hardware and software lists, PPSM, and SCTMs to ensure compliance. You will maintain communication with project engineers to translate Risk Management Framework security controls into technical requirements for delivery by software and platform engineers. You will engage directly with the security control assessor and the authorizing official to support authorization assessments and ATO readiness. You will support the implementation of technologies into CI/CD processes to establish secure-by-default standards and automate security controls. You will recommend security solution mitigations and enhancements that support information assurance guidelines and customer requirements for national security missions.
Key facts
What you'll do
- Orchestrate the development and maintenance of artifacts required to achieve and sustain a government continuous authorization to operate.
- Engineer and embed cybersecurity hardening measures across Kubernetes clusters and CI/CD pipelines to enforce secure-by-default postures.
- Author, revise, and sustain security artifacts including System Security Plans, hardware and software inventories, PPSM, and SCTM documentation.
- Synchronize with project engineers to convert Risk Management Framework security controls into actionable technical requirements for software and platform delivery.
- Liaise with the security control assessor and the authorizing official to facilitate authorization assessments and resolve findings.
- Drive the integration of security technologies into CI/CD workflows to automate controls and standardize secure deployment patterns.
- Advise on security mitigations and enhancements that align with information assurance policies and evolving customer mission requirements.
- Conduct vulnerability, risk, and security impact analysis for cloud CI/CD development systems, applications, networking, and orchestration throughout the system development life cycle.
- Contribute to the creation of audit and accountability plans that define methods, procedures, and planned reviews for continuing accreditation activities.
- Verify that all information systems meet or exceed applicable compliance requirements and regulatory mandates.
- Identify, report, and drive the remediation of security violations across the development and operational environments.
- Monitor and evaluate updates and upgrades to equipment, software, and procedures to maintain alignment with information assurance requirements and business objectives.
Requirements
- Must be a U.S. citizen with an active Top Secret clearance and eligibility for Sensitive Compartmented Information and Special Access Programs.
- Must hold a current DoDM 8570 IAT Level II or Level III certification, or DoD 8140.01 intermediate certifications under the Security Architect role.
- Must possess 5-8 years of experience in roles such as network/system administrator, system engineer, or Information Systems Security Engineer.
- Must demonstrate proven Risk Management Framework capabilities with a minimum of two years of specialized experience in at least one of the following domains.
- Must have hands-on experience with cloud platforms, preferring Azure or AWS environments.
- Must have direct experience with CI/CD pipelines and automation practices.
- Must have background in government software development and DevSecOps methodologies.
- Must have practical experience with Infrastructure as Code implementations.
- Must be experienced in operating within TS / SAP classified environments.
- Must have conducted security assessments and audits, with the ability to evaluate and enforce security controls.
- Must be fluent in applying the Risk Management Framework to classified information systems.
- Must have a solid understanding of the systems development life cycle as it applies to security engineering.
- Must exhibit exceptional verbal, written, interpersonal, and presentation skills while building customer relationships and mentoring team members.
- Must work independently with diligence and discipline on assigned duties in a high-impact national security context.
- Must have hands-on experience using vulnerability and security scanners such as ACAS, Nessus, and SonarQube.
- Must have experience integrating security technologies and solutions across information systems and platforms.
- Must have demonstrated experience guiding a package through all RMF phases from initiation to successful Authorization to Operate.
Nice to have
- Possess any Cloud Security Certifications such as CCSP, Microsoft Certified: Azure Security Engineering Associate, or AWS Certified Security
- Specialist.
- Hold Security Engineering or Architecture certifications including CISSP-ISSAP, CISSP-ISSEP, GDSA, or FITSP-D.
- Hold Software Development Security Certification such as CSSLP.
- Hold Orchestration Certifications such as CKA or Certified Container Security Expert.
- Demonstrate the ability to identify process improvements and implement continuous improvement solutions.
- Have experience creating a wide range of vulnerability and assessment scans using multiple tools.
- Have hands-on experience with eMASS, Xacta, SNOW, or LATTE ART platforms.
Practical notes
This role operates from Fort Meade, MD. The engagement details and compensation specifics are to be confirmed. Only U.S. citizens with appropriate clearances will be considered.