LEAD SECURITY ENGINEER

location_onRockville, Maryland, United Statesschedule14 hours ago
sync_altWork style:Hybrid
trending_upExperience level:Lead
badgeEmployment:Contract
historyMinimum experience:8+ years
schoolEducation:High school
Apply Nowopen_in_new

Job description

Position Summary

Emagine IT is seeking a Lead Security Engineer to lead the security engineering workstream of the Government's cybersecurity program. As designated Key Personnel, this role directs technical security architecture, continuous monitoring, Zero Trust, and emerging-technology security across the Government's hybrid AWS environment, and leads the engineers who operate the Government's security tools and build the program's automation, dashboards, and DevSecOps pipeline. The Lead Security Engineer translates Department and agency security requirements into practical technical solutions for system owners and developers. Consistent with the CIO-SP3 Systems Engineer – Level III labor category, the role supervises, coordinates, and performs additions and changes to systems and attached devices, participates in planning, design, and technical review of new infrastructure, and diagnoses and resolves complex problems.

Key Responsibilities / Essential Functions

  • Supervise, coordinate, and/or perform additions and changes to security tools, network and operating system configurations, and attached devices, including investigation, analysis, recommendation, configuration, installation, and testing.
  • Provide direct support for day-to-day operations, including evaluation of system utilization, monitoring response time, and primary support for detection and correction of operational problems; diagnose and resolve complex problems.
  • Participate in planning, design, technical review, and implementation of new security infrastructure, and provide technical consultation, training, and support to IT staff as designated by the Government.
  • Design, implement, and maintain a NIST SP 800-137 continuous monitoring program for all Government systems, delivering the Continuous Monitoring Implementation Plan within 30 days of award.
  • Direct security monitoring and correlation across CrowdStrike, Splunk/ELK, Tenable, Tanium, Okta, and AWS native services, aligned to MITRE ATT&CK and OMB M-21-31 logging requirements.
  • Perform security impact analyses for change requests within 5 business days and analyze the Department Computer Security Incident Response Center (CSIRC) threat communications within one business day; support incident response coordination and 24-hour reporting of notifiable events.
  • Lead the Zero Trust Maturity Assessment (90 days) and Zero Trust Roadmap (120 days) and collaborate with the Department ZTA effort on system-level maturity scorecards.
  • Deliver the Post-Quantum Computing Transition Roadmap (6 months) and Analyses of Alternatives for new security technologies; advise the CISO on cryptographic modernization.
  • Develop cybersecurity policy and risk assessment procedures for AI/ML systems per EO 14306 and NIST AI RMF 1.0 and maintain the AI Security Risk Register.
  • Provide technical solutions to vulnerability findings and security gaps during system development; analyze Government design requirements and determine security technology deployment strategies.
  • Direct Task 6 engineering: DevSecOps strategy (6 months), GitLab CI/CD security scanning, security automation scripts, NIST CSF and Enterprise Security Metrics dashboards, and OSCAL artifacts.
  • Oversee CDM Phase 4 integration and Department CDM Dashboard submissions; serve as liaison to the Department CDM community of practice.
  • Lead, train, and certify proficiency of the Security Engineer and Security Engineer/Architect.

Required Qualifications

  • Education: Undergraduate degree.
  • Experience: At least 8 years of enterprise security architecture, security engineering, and system administration experience, and 2 to 3 years of cloud security experience.
  • Certification: One of CISSP, CAP, CEH, Security+, GCIH, OSCP, or equivalent.
  • Technical: Familiarity with CDM and DevOps concepts and capabilities, such as CI/CD and infrastructure as code.
  • Clearance & citizenship: U.S. citizen or lawful permanent resident. Ability to obtain and maintain a Public Trust suitability determination (Tier 4 likely given privileged access; to be confirmed with the Government), obtain a Government PIV card, and sign the Government Contractor Non-Disclosure Agreement and Government Rules of Behavior before receiving access to Government systems or data. Must complete Government security awareness, privacy, and records management training before performing work and annually thereafter.

Preferred Qualifications

  • Cloud security certification: AWS Certified Security – Specialty, Azure Security Engineer, or CCSP (PWS: highly preferred).
  • Experience with the CISA Zero Trust Maturity Model 2.0, SCuBA baselines, and CDM Phase 4.
  • Experience in federal health-sector environments handling PII/PHI.

Benefits

This position is eligible for Emagine IT's benefits package, which includes medical, dental, and vision insurance; a 401(k) with company match; paid time off and holidays; and professional development and certification support.

Work Location

This position is remote (full telework) using Government-furnished equipment, with occasional on-site attendance at the Government client's headquarters in the Washington, DC metropolitan area when requested by the Government (including the in-person contract kickoff).

Physical Requirements

This position is generally performed in a standard home-office or office environment. The physical demands described here are representative of those an employee must be able to meet, with or without reasonable accommodation, to successfully perform the essential functions of this role.

  • Ability to remain in a stationary position and operate a computer for extended periods.
  • Ability to communicate effectively by phone, video, and in writing with colleagues, government stakeholders, and leadership.
  • Ability to perceive and interpret information displayed on a computer screen, including dashboards, reports, and security tools.
  • Ability to occasionally travel to the Government client's headquarters in the Washington, DC metropolitan area for in-person meetings.
  • Ability to occasionally lift and/or move office materials weighing up to 15 pounds (e.g., laptop, documents).

Reasonable accommodations will be made to enable individuals with disabilities to perform the essential functions of this role. Applicants who require accommodation during the application or interview process should contact [email protected] to request one.

EEO Statement

Emagine IT is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, genetic information, or protected veteran status, or any other characteristic protected by applicable federal, state, or local law.

Other Duties

Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice.

About Emagine IT

Emagine IT is an information technology consulting services company that specializes in delivering technology solutions. Our reputation reflects the high quality of the talented Emagine IT team and the consultants working in partnership with our customers. Our mission is to understand and meet the needs of both our customers and consultants by delivering quality, value-added solutions. Our solutions are designed and managed to not only reduce costs, but to improve business processes, accelerate response time, improve services to end users, and give our customers a competitive edge, now and into the future.

Skills mentioned

Apply for this job

Use the application link supplied with this listing to apply to Employer not listed. Check the destination before entering personal information.

Apply Nowopen_in_new