11 days ago
Remote, United StatesSenior
Base Salary
$155k - $155k/yr
Responsibilities
- Define and lead enterprise security architecture, engineering standards, procedures, technologies, security requirements, and verification practices.
- Provide technical leadership and oversight to ISSO and ISSE teams performing security engineering, compliance, continuous monitoring, and remediation.
- Lead risk assessments, security-control assessments, security strategy, service design, vulnerability management, and cybersecurity program activities.
- Oversee Authorization to Operate and System Security Plan activities while ensuring Zero Trust, continuous-monitoring, and federal security compliance.
- Design and guide static and dynamic application security testing, penetration testing, vulnerability analysis, and remediation with development teams.
- Communicate security requirements, risks, vulnerabilities, compliance challenges, and remediation recommendations to government and cross-functional stakeholders.
Requirements
- Bachelor’s degree in Information Technology, Information Assurance, Cybersecurity, or a related field, with additional relevant experience permitted in place of the degree.
- At least 10 years of relevant experience, including five years leading large security-engineering, ISSO, or ISSE teams.
- Current Certified Information Systems Security Professional certification.
- At least five years of security-engineering experience supporting Agile, Scrum or SAFe, DevSecOps, and cloud-based projects.
- Extensive knowledge of ATOs, System Security Plans, Zero Trust, continuous monitoring, security-control assessment, risk management, and federal security policy.
- Hands-on experience with application security testing, penetration testing, encryption, communication protocols, access control, PKI, incident response, and defense-in-depth architectures.
- Information Systems Security Engineering Professional certification and experience with U.S. Census Bureau, Department of Commerce, or comparable civilian federal information systems are additional qualifications.
- Experience applying NIST Risk Management Framework, NIST SP 800-53, FISMA, FedRAMP, and federal Zero Trust requirements in cloud and DevSecOps environments.
- U.S. citizenship, successful background check, and ability to obtain and maintain a Government/Public Trust clearance, including fingerprinting when required.
- Strong communication, leadership, mentoring, customer-engagement, collaboration, analytical, and remediation-planning skills.
Benefits
- Medical, dental, and vision coverage.
- 401(k) with employer match.
- Paid time off and federal holidays.
- Corporate laptop.
- Training opportunities.
- 100% remote work, with travel to the Washington, DC metropolitan area as needed.
- The position is contingent upon contract award.
