SECURITY & COMPLIANCE ENGINEER (SCE)
Zermount, Inc.
ZERMOUNT POSITION DESCRIPTION (PD) SECURITY & COMPLIANCE ENGINEERING (SCE) POSITION OVERVIEW Zermount Inc. is seeking System Compliance Engineering (SCE) to support system risk analysis and ensure that federal information systems comply with Information Assurance and cybersecurity standards. The SCE ensures that federal information systems are secure in operation, not merely compliant with documentation. This role directly contributes to mission assurance by identifying, validating, and mitigating real-world cybersecurity risks across enterprise environments. The SCE operates at the intersection of compliance, engineering, and mission operations, transforming federal mandates (e.g., NIST RMF, FISMA, EO 14028, OMB directives) into measurable, technically enforced security outcomes. Rather than relying solely on static assessments, the role requires continuous evaluation of the system\'s security posture by directly analyzing configurations, logs, architectures, and control implementations. This position is designed for individuals with foundational technical expertise across multiple domains, including cloud platforms, network architecture, operating systems, identity systems, and databases. You must be able to independently assess systems, identify exploitable conditions, and validate whether implemented controls effectively reduce risk in real-world scenarios. The role is a core component of Zermount\'s Modern GRC mindset, emphasizing: Continuous monitoring of system compliance responsibilities Real-time risk identification and prioritization Direct integration with system teams to drive remediation Elimination of "check-the-box" compliance practices You will be responsible for producing decision-quality outputs that enable system owners, ISSOs, and leadership to make informed, risk-based decisions. This includes identifying control failures, recommending technically sound remediation strategies, and validating that corrective actions are effective and sustainable. DUTIES & RESPONSIBILITIES General Duties – Execute RMF lifecycle (Prepare–Monitor) while validating controls directly in operational environments Identify and document real-time risks through analysis of logs, telemetry, configurations, and architecture Validate implementation of security controls (STIGs, MFA, encryption, access control) using system-level evidence Identify exploitable misconfigurations, weak trust boundaries, and gaps across cloud, network, OS, and database layers Drive POA&M actions by prioritizing risk based on exploitability and mission impact, ensuring closure within defined timelines Perform continuous monitoring (ISCM/CDM) with emphasis on actual system behavior vs. reported compliance Translate NIST, EO 14028, OMB, and TIC 3.0 requirements into specific technical remediation actions Validate remediation actions with repeatable verification methods (not documentation review) Produce executive-quality outputs (risk findings, remediation plans, executive summaries) Maintain system artifacts and documentation only as a byproduct of validated technical work SUBJECT MATTER EXPERTISE (SME) SME Area #1 – Primary Expertise: Technical Risk Validation (Modern GRC Execution) Expert-level means: Ability to independently assess systems using direct technical inspection techniques, leveraging logs, configs, architecture documents, etc. Deep working knowledge of critical frameworks and directives such as: NIST RMF (800-37, 800-53, etc.) FISMA, EO 14028, OMB M-21-31 / M-22-09 FIPS 199/200 TIC 3.0 and Zero Trust principles (CISA ZT MM, NIST 800-207, etc.) Ability to identify threat surfaces within specific systems, not just control gaps Ability to convert compliance requirements into specific and actionable remediation actions that the system teams can be used to successfully remediate findings Required Tools Experience: Vulnerability scanning tools such as: Tenable, Qualys, CrowdStrike, etc. Log analysis platforms such as: Splunk, Microsoft Sentinel, IBM QRadar, etc. Configuration and system inspection tools such as: Ansible, Terraform, Puppet etc. GRC platforms such as: Archer, ServiceNow, etc. SME Area #2 – Secondary Expertise: Multi-Domain Technical Depth You must have deep knowledge of one or more of the following technical domains and must demonstrate the ability to leverage this experience to inform and complete compliance-related tasks. Technical Domains Cloud: AWS/Azure (IAM, logging, network security, misconfigurations) Network: Segmentation, firewalls, boundary protections, Zero Trust enforcement points Systems: Windows/Linux hardening, identity systems (AD, MFA) Databases/Data: Access control, encryption, auditing QUALIFICATIONS Minimum Requirements 5+ years of cybersecurity experience supporting U.S. Government systems 4+ years performing RMF, ISSO, Assessment, or GRC functions with direct technical validation responsibilities Demonstrated hands-on experience in at least two technical domains (cloud, network, systems, or databases) Proven ability to analyze: System configurations, ATOs, and other supporting security documentation Logs/telemetry Architecture documentation and data flow diagrams Preferred Qualifications Experience implementing or assessing Zero Trust architectures Experience with CDM, ISCM, and enterprise logging programs Familiarity with threat-informed defense concepts Experience in hybrid cloud environments Competency Technical risk identification and prioritization Independent problem-solving in ambiguous environments Ability to translate policy into technical action Clear communication with both engineers and leadership Education & Certifications Bachelor of Science (B.S.) in Computer Science, IT, Cybersecurity, or a related field, and a minimum of 5 years of IT cybersecurity experience, including direct support for the US Government and 4 years acting as an ISSO, Assessor, Compliance, RMF, or GRC with a technical validation role. Without a B.S. in a relevant field - A minimum of 10 years of IT Cybersecurity experience, including direct support for the US Government, and 4 years acting as an ISSO, Assessor, Compliance, RMF, or GRC with a technical validation role. At least one of the following security certifications is required: Certified Authorization Professional (CAP) Certified Information Security Auditor (CISA) Certified Information Security Manager (CISM) Certified Information Systems Security Professional (CISSP), or Certified Chief Information Security Officer (CCISO) Governance Risk & Compliance Certification (CGRC) Or alternatively approved certifications Clearance Level Minimum of active Secret Clearance and ability to obtain and maintain DHS suitability WORK LOCATION The position is primarily remote – Continental U.S only Primary location when on site: Arlington, VA, and Springfield, VA Must be willing to travel - Not to exceed 10% of the time HOURS OF OPERATION 8:00 am EST – 4:30 pm EST Times may fluctuate based on client and business requirements REPORTING STRUCTURE Reports To: Security Compliance Engineering Team Lead Direct Reports: N/A #J-18808-Ljbffr
- ...Koitecc Solutions is seeking a seasoned M365 Security and Compliance Administrator to enhance the security posture of the Microsoft 365 environment in a federal agency setting. This role includes duties such as leading security governance, implementing email security policies...Suggested
$60k
...partner supporting mission‑critical programs across national security, defense, and public service delivery. Our work focuses on sustaining... ...: Experience supporting documentation, reporting, and compliance activities Understanding of network monitoring tools and...SuggestedContract workRemote work$107.9k - $195.05k
...Description Leidos is seeking an experienced M365 Security and Compliance Administrator to join our Information Technology team. This role... ..., particularly in a federal agency context. This senior engineering role sits at the center of the organization's device, identity...SuggestedLocal areaImmediate startNight shiftDay shift- Zermount, Inc. is looking for a System Compliance Engineer in Arlington, VA. This remote role involves ensuring federal information systems meet cybersecurity standards by performing technical validations and risk assessments. Candidates should have 5+ years of experience...SuggestedRemote job
- ...believe the highest-impact work in national security and technology is a team sport. At... ...consequential as any field in science or engineering. That means we bring intellectual... .... We are seeking a highly experienced Compliance / Security Engineer to lead Authorization...SuggestedFull timeTemporary workInterim roleLocal area
$90k - $150k
...lifesaving drugs, forecast supply chain disruptions, locate missing children, and more. The Role As a Compliance Engineer, you will help our engineers implement Palantir Security Controls across our entire product line. You’ll work closely with many different teams to shape...Work experience placementWork at officeRemote workWork from homeRelocation package- ...Senior Strategic Consultant - DOS Training Security Engineering Dexis is a dynamic professional services firm dedicated to partnering with government and community leaders both in the U.S. and internationally to achieve critical social outcomes in a rapidly changing...Contract workWork at office
$237.6k - $297k
...We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and integrity of our products and services. You will conduct in-depth code reviews, implement security best practices, and influence the...Full time$104k - $156k
...Type Remote/Hybrid Job Overview As an Advanced Security Engineer focused on Endpoint Security, you will design, build, and operate... ...(SC-300). ~ Knowledge of Zero Trustprinciplesand compliance standards (e.g., GDPR, HIPAA). ~ Exposure to other...Remote work- ...public-sector customers who demand experience and proven security models to protect their data. ShorePoint subscribes... ...more. Who we're looking for: We are seeking Compliance and Continuous Monitoring Engineer - Vulnerability Management (Top Secret Clearance) with...
- ...Honeywell Aerospace is hiring a Sr Export Compliance Officer in Washington, DC. This role involves providing crucial export compliance guidance and ensuring adherence to US export laws and regulations. The candidate will work on a hybrid schedule, collaborating with technical...
- A security compliance firm in Washington, DC is searching for an experienced acoustic testing specialist. This role involves ensuring facilities comply with ICD/ICS 705 standards through expert testing and documentation. Candidates must have an active U.S. Top Secret clearance...
- ...VMware and Hyper-V. This position supports operational excellence in a large-scale enterprise environment and requires collaboration with various IT teams to mitigate security threats. Competitive compensation and benefits are included. #J-18808-Ljbffr AHU Technologies
- ...Graduate Engineer, Electronic Security Engineer Together, we own our company, our future, and our shared success. As an employee-owned company... ...check, drug screen, and motor vehicle records search, in compliance with any applicable laws and regulations. Salary Plan...
- ...Program Manager, the Web Developer Embeds security across the SDLC for mission-critical... ...ensures NIST 800-53 / FISMA / FedRAMP compliance and supports audits and authorization.... ...WAF management 3+ Web AppSec / AppSec Engineering / SSDLC Modern web tech incl. .NET (...Work from homeFlexible hours
$90k - $150k
...A leading technology company in Washington, DC is seeking a Compliance Engineer to implement security controls across its product line. This role involves navigating complex US Government regulatory frameworks and ensuring compliance with standards such as FedRAMP and...$160k - $180k
Governance, Risk, Compliance (GRC) Engineer Washington, DC Electrosoft Services, Inc. is an award-winning company that provides comprehensive technology-based solutions and services to federal customers. While cybersecurity is our specialty, we also focus on ICAM, enterprise...For contractors$164.38k - $212.75k
...Information Assurance, Information System Security, Risk Assessments Certifications:... ...opportunity as a Cybersecurity Systems Engineer/Information Systems Security Engineer (ISSE... ...Support audit liaison activities, and compliance oversight activities to strengthen the security...Temporary workFor contractorsInterim roleSummer workImmediate startRemote workWorldwideRelocationFlexible hours- ...The Senior Federal Information Systems Security Engineer (ISSE) serves as a technical integrator responsible for ensuring that system-to-... ...hours per week as needed to support mission timelines Maintain compliance with all corporate and federal cybersecurity policies...Contract workWork experience placementRelocation
$166k - $253k
...months, not years. ABOUT THE JOB We're seeking a Security Software Engineer to develop novel security tooling for securing embedded Linux... ...Knowledge of security frameworks and compliance standards. Experience in mobile development, specifically...Full timeWork experience placementImmediate start- ...We are seeking a Security Engineer with experience in endpoint protection, federal cybersecurity compliance, and security operations. The ideal candidate will support endpoint security initiatives, incident response activities, and security monitoring within a Federal...
$71.2k - $158.2k
...Senior Federal Information Systems Security Engineer (ISSE) The Senior Federal Information Systems Security Engineer (ISSE) serves as... ...per week as needed to support mission timelines · Maintain compliance with all corporate and federal cybersecurity policies · Protect...Contract workTemporary workWork experience placementRelocationFlexible hours- ...Senior Security Operations Engineer Job Title: Senior Security Operations Engineer Location: Washington, DC Note: This is an onsite position... ...monitoring, workload protection, identity security, and compliance monitoring capabilities. Perform hands-on system integration...
- ...About the Role The Security Operations Engineer supports the day-to-day operation of security technologies that safeguard corporate systems... ...procedures up to date to support operational readiness and compliance expectations. Vulnerability Management Support...
- ...A cybersecurity solutions provider in Washington, DC is looking for an experienced cybersecurity engineer. The role involves implementing and operating advanced security solutions for governmental and commercial clients. Applicants should have over 5 years of systems...
- ...A dynamic technology services company is seeking a skilled Network Security Engineer to ensure optimal operation of their network infrastructure. This role focuses on troubleshooting Cisco routing and switching environments, managing Palo Alto firewalls, and performing...
$106k - $126k
...Evaluates application security in all phases of the software development life cycle. Works... ...to support security standards and compliance requirements. Have the technical depth... ...Bachelor's Degree in Computer Science, Engineering, or other Engineering or Technical discipline...Contract workWork at office- ...Sr. Endpoint Security Engineer Category: Analytics and Emerging Digital Technologies Main location: United States, District of... ...to incidents, and conducting security assessments to ensure compliance with best practices. Your expertise will contribute to the development...Full timeLocal area
$55 - $65 per hour
...IT - Systems Engineer III Location: Home, District of Columbia (Onsite) Employment... ...Information Systems Engineer focused on Endpoint Security and Certification & Accreditation (C&A).... ...implement security solutions to ensure compliance with federal standards. Key...Contract work- ...is seeking a Cybersecurity Architect & Engineer SME who can create government solutions... ...and Cloud). The role focuses on designing secure enterprise architectures, engineering automated... ...in security posture, automation, and compliance maturity. DUTIES AND RESPONSIBILITIES...Remote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to SECURITY & COMPLIANCE ENGINEER (SCE). Be the first to apply!
- security infrastructure engineer Arlington, VA
- senior cloud security engineer Arlington, VA
- senior application security engineer Arlington, VA
- physical security engineer Arlington, VA
- endpoint security engineer Arlington, VA
- sr information security engineer Arlington, VA
- senior security operations engineer Arlington, VA
- IT security engineer Arlington, VA
- information technology security engineer Arlington, VA
- security software engineer Arlington, VA


