Security Engineer
Job description
About the role
The is responsible for architecting and maintaining robust security postures for critical government and commercial technology initiatives. This professional will own the end-to-end security lifecycle, from designing protective architectures to executing defensive operations and ensuring continuous compliance. They will serve as the technical authority responsible for defending complex infrastructure against evolving threats and enabling mission continuity. The role requires a deep commitment to safeguarding classified and sensitive information through proactive defense strategies. The Security Engineer will leverage extensive expertise to solve difficult security challenges across diverse operational environments. Success in this position is defined by the ability to prevent, detect, and respond to security incidents effectively. The individual in this role will be a foundational pillar in protecting the integrity, availability, and confidentiality of critical systems.
Key facts
What you'll do
- Execute comprehensive planning, implementation, and continuous monitoring of both physical and virtual network services and systems to ensure operational integrity.
- Configure and harden systems to rigorously align with established organizational security policies, procedures, and regulatory mandates.
- Manage user accounts with precision, ensuring proper lifecycle administration, authentication, and authorization controls are consistently applied.
- Oversee system configuration management processes to maintain secure and standardized baselines across all infrastructure components.
- Administer backup and recovery processes, validating the integrity and availability of data to support business continuity objectives.
- Develop and strengthen secure solutions specifically designed for modern cloud and hybrid infrastructures that support mission-essential functions.
- Review, implement, and maintain NIST 800-53 controls and System Security Plans (SSPs) to facilitate successful Authorization to Operate (ATO) processes.
- Conduct proactive vulnerability identification and remediation activities to minimize system threats and reduce the overall attack surface.
- Collaborate effectively with development, infrastructure, and compliance teams to integrate secure design principles and security-by-default methodologies.
- Create comprehensive security documentation, policies, and control evidence packages to support audits, assessments, and regulatory requirements.
- Engage actively in security audits, penetration testing, and incident response exercises to validate and improve the security posture.
- Implement and manage robust data protection, encryption, and identity/access controls to safeguard sensitive information at rest and in transit.
- Ensure strict adherence to organizational security and privacy policies to protect confidential information and maintain regulatory compliance.
- Correlate log data from diverse sources and generate actionable insights to enhance real-time security monitoring and threat detection capabilities.
Requirements
- Possess U.S. citizenship, which is mandatory for handling sensitive government information and accessing classified systems.
- Hold a Bachelor's or Master's degree in Cybersecurity, Information Systems, Computer Science, or a closely related technical field.
- Maintain an active Secret security clearance or demonstrate the ability to obtain and maintain one for the duration of the engagement.
- Demonstrate a minimum of five years of hands-on cybersecurity engineering experience within federal, military, or large enterprise operational settings.
- Show comprehensive familiarity with established security frameworks such as NIST SP 800 series publications and CNSSI guidance documents.
- Exhibit extensive hands-on experience with system hardening techniques, network security architecture, encryption protocols, vulnerability scanning methodologies, and incident response procedures.
- Operate securely and effectively within major cloud platforms including Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP).
- Utilize a broad range of security tools and technologies, including Security Information and Event Management (SIEM) systems, Extended Detection and Response (XDR) platforms, SAST/DAST tools, Security Technical Implementation Guides (STIG), and Security Content Automation Protocol (SCAP) standards.
- Implement and manage sophisticated identity and access control mechanisms, including role-based access control (RBAC), attribute-based access control (ABAC), and federated identity management models while enforcing least-privilege principles across all architectures.
- Correlate complex log data from multiple sources and generate high-fidelity insights to support advanced security monitoring, threat hunting, and operational intelligence activities.
Nice to have
- Hold industry-recognized certifications such as CCNA-Security, CompTIA Security+, or the Certified Information Systems Security Professional (CISSP) credential.
- Possess a deep understanding of Federal Executive and Military security requirements and the complex IT systems that support them.
- Produce audit-ready documentation, including detailed incident reports, comprehensive test reports, and compliance artifacts required for regulatory examinations.
- Demonstrate advanced proficiency with leading security platforms such as Microsoft Sentinel, Splunk, Tenable/Nessus, CrowdStrike Falcon, and Microsoft Defender for Endpoint.
- Secure and configure AI-based security tools and leverage machine learning capabilities to enhance threat detection and response operations.
- Contribute actively to the creation and maintenance of security documentation, control evidence, and compliance artifacts for diverse client engagements.
Practical notes
This Security Engineer listing at Steerbridge specifies the position location as Vienna, VA. Candidates must confirm the remote work policy, exact compensation details, and precise start date by reviewing the official apply page. The engagement is full-time, and all application procedures must be completed through the official posting. Prospective candidates are advised to apply directly on the official posting to verify current duties, compensation, and location specifics for the Security Engineer role at Steerbridge. The employment terms, including potential travel requirements, visa sponsorship needs, and application deadlines, must be confirmed