
ISSM / Security Automation Engineer
Tyto Athene, LLC20 days ago
Remote, United StatesSenior
Base Salary
$175k - $190k/yr
Responsibilities
- Lead NIST RMF implementation, system authorization, ongoing authorization, security control documentation, risk assessments, and continuous monitoring activities.
- Design, develop, and maintain automation using Python, PowerShell, Bash, APIs, and cloud-native technologies for control validation, evidence collection, compliance reporting, and remediation.
- Translate NIST SP 800-53 controls and organizational requirements into machine-readable policies, automated validation procedures, and continuous control monitoring.
- Integrate security into cloud architectures, Infrastructure as Code, CI/CD pipelines, containers, Kubernetes, and software delivery workflows.
- Build integrations connecting cloud platforms, vulnerability scanners, security tools, GRC platforms, ticketing systems, source-code repositories, and CI/CD systems.
- Automate vulnerability and configuration finding ingestion, correlation, prioritization, tracking, reporting, POA&M management, exceptions, and remediation.
- Develop dashboards, metrics, and automated reporting for vulnerabilities, configuration compliance, control status, POA&Ms, and organizational risk.
Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Software Engineering, or a related field, or equivalent professional experience.
- Experience as an ISSM, ISSO, Security Engineer, Cloud Security Engineer, DevSecOps Engineer, or similar technical cybersecurity professional.
- Strong knowledge of NIST SP 800-53, NIST SP 800-37, RMF, security authorization, security control assessment, and continuous monitoring.
- Hands-on experience developing production-quality automation, scripts, integrations, or software.
- Strong Python experience plus one or more of PowerShell, Bash, JavaScript, or Go.
- Experience working with JSON, YAML, vulnerability scanning, vulnerability management, cloud platforms, and cybersecurity or operational process automation.
- Ability to understand cloud and enterprise architectures and translate regulatory and cybersecurity requirements into technical engineering requirements.
- Preferred experience with AWS, Azure, GCP APIs or SDKs, Terraform, Ansible, GitHub Actions, GitLab CI/CD, Jenkins, Azure DevOps, Docker, Kubernetes, SIEM platforms, CSPM/CNAPP solutions, GRC platforms, ticketing systems, dashboards, data pipelines, automated testing, serverless architectures, event-driven automation, Compliance as Code, and Policy as Code.
- Preferred federal cybersecurity experience with FISMA, FedRAMP, DoD RMF, CMMC, SSPs, POA&Ms, Security Assessment Reports, SCAs, 3PAOs, or government Authorizing Officials.
- Preferred certifications include CISSP, CGRC, CISM, CCSP, Security+, AWS Solution Architect or Security Specialty, GCP Cloud Architect or Security Engineer, and Certified Kubernetes Security Specialist.
Benefits
- Health, dental, and vision insurance.
- 401(k) match.
- Paid time off.
- Short-term disability, long-term disability, and life insurance.
- Referral bonuses.
- Professional development reimbursement.
- Parental leave.
Tech Stack
AnsibleAWSAzureBashDockerGitHub ActionsGitLab CI/CDGoGoogle Cloud PlatformJavaScriptJenkinsKubernetesPowerShellPythonTerraform