Security Engineer
HyerTek Inc.
Job Type
Full-time
This is a critical-path role. Systems are configured, assessed, and separately authorized per environment, so you will carry the control implementation, the System Security Plan and POA&M, the hardening, and the continuous-monitoring posture - coordinating closely with cloud engineers, developers, and the Government. When accreditation is on the critical path, your work is what keeps delivery on schedule. Location: Candidate must be located in the Washington, DC, metro region and must be available onsite in Maryland as needed. This role supports secure Government environments; Candidates must have and maintain an active TS/SCI clearance with the Department of Defense. All personnel shall meet DoD 8140/8570 (DoDM 8140 / DCWF) baseline requirements. Responsibilities:
- Own RMF execution - categorize, select, implement, assess, and support authorization under NIST View phone number on click.appcast.io and DoDI 8510.01.
- Author and maintain the System Security Plan (SSP), POA&M, and full control-implementation evidence; manage the authorization package in eMASS (or the Government's system of record).
- Serve as the security engineering interface to the Government ISSM/AO and assessors; prepare for and support all assessment-and-authorization activities.
- Implement and validate hardening against applicable DISA STIGs (application/ASD, container, database, OS) and track remediation to closure.
- Design and operate the continuous-monitoring posture - audit logging, SIEM integration (Microsoft Sentinel / Log Analytics), and control-assessment cadence - and maintain POA&M currency.
- Engineer and verify the data-protection posture: encryption in transit and at rest, key management (Key Vault / managed identity, customer-managed keys, FIPS-validated cryptography), and no secrets in source or image.
- Own the CAC/PIV / DoD PKI validation design (OCSP/CRL) with the cloud and application engineers.
- Enforce CUI handling and, where applicable, cross-domain and classified-data controls and spillage prevention.
- Implement least-privilege access, zero-trust controls, and privileged-access administration (Bastion / JIT / MFA / privileged access workstations).
- Produce and maintain the security documentation and as-built records required for accreditation and customer handoff.
- 7+ years in information system security engineering/cybersecurity for federal or DoD systems, with direct, hands-on RMF experience.
- Demonstrated ownership of at least two systems through a full RMF authorization to an ATO/cATO - SSP, control implementation, POA&M, and package management.
- Hands-on experience with eMASS (or equivalent) and NIST 800-53 control implementation and assessment.
- Experience hardening systems to DISA STIGs and validating compliance.
- Working knowledge of cloud security architecture - identity, network isolation (private endpoints), key management, and SIEM/continuous monitoring.
- Understanding of CUI handling (DoDI 5200.48) and the DoD Cloud Computing SRG impact levels.
- DoD 8140/8570-compliant certification for the ISSE role (e.g., CISSP, CASP+, or equivalent).
- Strong technical writing and the ability to produce assessor-ready evidence.
- Ability to carry security engineering and authorization across multiple environments on a lean, senior team.
- Candidates must have and maintain an active TS/SCI clearance with the Department of Defense.
- Direct experience accrediting workloads in Azure Government or classified Azure environments.
- Experience with cross-domain solutions (CDS) and the SABI/TSABI process, or supporting a data-transfer accreditation.
- Experience standing up continuous monitoring with Microsoft Sentinel and integrating with a designated CSSP.
- Familiarity with securing containerized workloads (AKS, hardened images, image signing/scanning).
- Experience with AI/LLM security controls (data-residency, scope-bound retrieval, prompt-injection defense) in a governed environment.
- ISSM or RMF assessor experience; CISSP-ISSEP.
- Medical, dental, and vision insurance
- 401(k) with employer contribution
- Paid time off (PTO) and company holidays
- Flexible work arrangements
- Professional development and certification support
- Employee assistance program (EAP)
- Life and disability insurance
$140,000 - $155,000 per year
Vacancy posted more than 2 months ago
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer. Be the first to apply!
Related searches
- IT security engineer Columbia, MD
- aws cloud security engineer Columbia, MD
- senior application security engineer Columbia, MD
- network security engineer Columbia, MD
- information technology security engineer Columbia, MD
- security engineer Columbia, MD
- hardware security engineer
- entry level security engineer
- lead security engineer
- electronic security engineer
