Performing hands-on engineering, administration, and securing of multiple operating systems (e.g., Windows, RHEL, Unix variants), and applying DISA STIGs across virtualization platforms (VMWare, Hyper-V), cloud environments (AWS, Azure, Google Cloud), and enterprise applications
Perform system administration tasks including audit and log management, availability monitoring and remediation, account management and access reviews, and configuration update scheduling and performance
Contribute to the design and development of secure system architectures, ensuring security is integrated through system and network lifecycles
Evaluate, implement, and document security architecture solutions, aligning with compliance requirements and organizational mission needs
Ensure technical compliance with applicable security frameworks, standards, and regulations (e.g., DISA STIGs, NIST 800-53, RMF)
Conduct, configure, and manage vulnerability scans
Conduct vulnerability remediations, patching, and system hardening
Collaborate with ISSOs, Assessors, System Owners, and other stakeholders to implement security controls
Support security assessments, audits, and accreditation/authorization (ATO) activities
Document security configurations, engineering solutions, and compliance evidence
Troubleshoot and resolve security-related technical issues in a timely manner
Advise the client regarding critical application data and vulnerability points; coordinate with industry partners and provide recommendations on incident response and recovery plans
Provide Incident Response (IR) activities including triage, investigating, interviewing, resolving, and reporting on events
Promote information security awareness across the program, ensuring security controls and processes are implemented
Present vulnerability analysis to system owners and leadership
Engage with client leadership regularly and interact with senior level team members
Position requires a Public Trust and is on-site in Washington, DC
Requirements
5-10 years of experience in information system engineering and configuration management
5 years of experience in control implementation and secure system engineering or design
Excellent communication skills
Hands on experience with security monitoring and evaluation, including audits, assessments, and risk management
Hands on experience with SIEM tools (e.g., Splunk)
Hands on experience with Vulnerability Scanning tools (e.g., Tenable, Nessus)
Hands on experience with EDR tools (e.g., Crowdstrike)
Hands on experience with Web App Scanning tools (e.g., Burpsuite, Acunetix)
Hands on experience with Active Directory
Hands on experience with SANs
Hands on experience with VMWare
Hands on experience with Networking Devices
Expertise in batch, bash, and/or PowerShell scripting
Able to deliver and present security compliance to a wide range of audiences (i.e., system owners, division leadership)
Experience configuring and operating enterprise storage across networks (SAN)
Server virtualization - design solutions and configuration (VMWare, VSphere, Hyper-V, etc)
Experience with Linux (RHEL 7/8), Windows Operating Systems, and Oracle/SQL Databases
Experience with Agile Methodologies
Experience with GRC Tools (e.g., CSAM)
Strong desire to learn, grow and is highly motivated
Certifications: OS specific certifications, Security+
Desired: Knowledgeable on different cloud providers: AWS, Azure, Oracle, GCP
Desired: Education: Bachelor’s degree in Engineering, Computer Science, or Information Systems
Generous cost sharing for medical insurance for the employee and dependents
100% company paid dental insurance for employees and dependents
100% company paid long-term and short term disability insurance
100% company paid vision insurance for employees and dependents
401k plan with generous match and 100% immediate vesting
Competitive Pay
Generous paid leave and holiday package
Tuition and training reimbursement
Life and AD&D Insurance
ATS Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
information system engineeringconfiguration managementsecure system engineeringsecurity monitoringvulnerability scanningscripting (batch, bash, PowerShell)server virtualizationcloud environments (AWS, Azure, Google Cloud)operating systems (Windows, RHEL, Unix)networking devices
Soft skills
communication skillscollaborationproblem-solvingpresentation skillsmotivationsecurity awareness