Security Engineer
ClearanceJobs
Compliance And Continuous Monitoring Engineer - Vulnerability ManagementShorePoint is a fast-growing, industry recognized and award-winning cybersecurity services firm with a focus on high-profile, high-threat, private and public-sector customers who demand experience and proven security models to protect their data. ShorePoint subscribes to a "work hard, play hard" mentality and celebrates individual and company successes. We are passionate about our mission and going above and beyond to deliver for our customers. We are equally passionate about an environment that supports creativity, accountability, diversity, inclusion and a focus on giving back to our community. The Perks: As recognized members of the Cyber Elite, we work together in partnership to defend our nation's critical infrastructure while building meaningful and exciting career development opportunities in a culture tailored to the individuals technical and professional growth. We are committed to the belief that our team members do their best work when they are happy and well cared for. In support of this philosophy, we offer a comprehensive benefits package, including major carriers for health care providers. Highlighted benefits offered: 144 hours of PTO, 11 holidays, 85% of insurance premium covered, 401k, continued education, certifications maintenance and reimbursement and more.We are seeking Compliance and Continuous Monitoring Engineer - Vulnerability Management (Top Secret Clearance) with expertise in security assessments, vulnerability management and continuous monitoring. The ideal candidate will support assessment and authorization activities, conduct technical security evaluations and ensure enterprise systems remain compliant with federal cybersecurity standards. The Compliance and Continuous Monitoring Engineer (Vulnerability Management) role will provide hands-on scanning, reporting and compliance support to strengthen the enterprise cybersecurity posture. This is a unique opportunity to shape the growth, development and culture of an exciting and fast-growing company in the cybersecurity market.Work closely with organizations to ensure full comprehension of security controls; conduct site visits as required.Assist with compliance assessments using tailored control matrices; provide expert assessment support.Conduct annual reviews of security controls to ensure continued compliance.Establish footholds on endpoints to provide day-to-day visibility into enterprise security posture.Develop and maintain processes and best practices for evaluating assessment and authorization data.Use industry-standard automation tools to review system configurations and security control compliance.Conduct NIST control assessments in support of system authorization and continuous monitoring.Develop and maintain Security Assessment Reports (SARs) and Risk Assessment Reports (RARs).Employ a scan-patch-scan methodology to ensure proper remediation of vulnerabilities.Conduct vulnerability scanning on a weekly to bi-weekly basis using industry-standard tools.Report scan data to system administrators to support timely remediation.Perform false positive and vulnerability analysis to validate findings and prioritize remediation.Configure applications to ingest, process and report vulnerability data from assessments and self-assessments.Conduct long-term trend analysis to identify changes in enterprise security posture.Provide dashboard views and executive-level reports to communicate risk, vulnerability and compliance posture.Configure authenticated and unauthenticated scans of web servers (e.g., Apache, IIS) to identify vulnerabilities such as outdated software, misconfigurations, exposed services and SSL/TLS weaknesses.Assess both in-house and COTS web applications to identify OWASP Top 10 risks, including SQL injection, cross-site scripting (XSS) and insecure headers.Lead technical troubleshooting sessions with administrators and leadership to analyze findings, validate issues and drive remediation efforts.Maintain a general understanding of network architecture diagrams to support vulnerability analysis and remediation planning.Strong understanding of federal frameworks including NIST 800-53 and 800-53A. Knowledge of SANS and OWASP Top 10 vulnerabilities and best practices. Ability to synthesize and analyze large volumes of vulnerability and scan data. Ability to clearly articulate findings in written and verbal form.Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Mathematics, Engineering or a related field or additional 10+ years of IT experience in lieu of degree.One or more of the following certifications: (ISC)2 Certified Information Security Professional (CISSP), GIAC, GCIA or GCIHProven ability to analyze complex requirements and translate them into clear, actionable tasks and processes through critical thinking.Ability to perform vulnerability and compliance assessments on all devices identified during enterprise network scans, including operating systems oracle and MySQL databases and web applications.Proficiency with enterprise-class scanning tools such as Tenable Nessus and Tenable Security Center, database scanning tools such as AppDetective and DbProtect and web scanning tools such as Web Inspect, with strong knowledge of security best practices and common vulnerabilities for each technology, including SANS and OWASP Top 10.Experience performing enterprise-level assessment scanning of networks, databases and web applications.Ability to configure and perform host, port and service discoveries on large enterprise networks and identify target operating systems and applications or services from discovery results.Proficiency in configuring, troubleshooting and administering Tenable Security Center, Tenable Nessus standalone, AppDetective and Web Inspect.Strong understanding of security policies used by intelligence organizations, as well as NIST guidelines (e.g., 800-53 and 800-53A).Ability to think critically and creatively and to synthesize and analyze large volumes of scan data.Strong written and verbal communication skills with the ability to present findings clearly and comprehensively.Applicants must possess an Top-Secret clearance with SCI eligibility and ability to pass a Counterintelligence (CI) polygraph.Experience with open-source and commercial testing tools, including Nessus, NMAP, AppDetective, Hailstorm, Guardium and Web Inspect.Onsite (Washington, DC.)
$178.4k - $226.7k
Corporate Services Security (CPSS) is the Amazon security team aligned with Finance & Global Business Services (FGBS), People eXperience... ...Services. Apart from work, we provide opportunities for our engineers to pursue projects they are passionate about while maintaining...SuggestedInternshipFlexible hours$107.93k - $188.9k
Position Summary Deloitte’s Cyber Defense and Resilience offering is seeking a SIEM Engineer to support security monitoring, detection engineering, and incident analysis across complex enterprise environments. This role will focus on building and optimizing SIEM...SuggestedRemote work$136k - $184k
Amazon’s Threat Hunting team is looking for a Security Engineer, Threat Hunting who is excited by the idea of searching for and uncovering undetected threat activities at petabyte scale. In this role, you will work alongside other Threat Hunting engineers to proactively...SuggestedInternshipFlexible hoursShift work$178.4k - $226.7k
AHAS reduces the risk of human and operator access to AWS production systems and customer environments. As the Senior Security Engineer embedded with an AHAS software development team, you own the security design decisions for the operator-access tooling this team builds...SuggestedInternshipRemote workFlexible hours$159.3k - $202.4k
Amazon is seeking qualified Security Engineers to join our innovative, high energy Information Security team. In this role you will work within the Amazon Security Incident Response Team (SIRT). SIRT Security Engineers respond to security events, conduct analysis of threats...SuggestedInternshipFlexible hours$120k - $130k
Job DescriptionEverforth ECS is seeking an Identity Security Engineer to work in our Washington, DC office / remote. The role is contingent upon additional funding.We are seeking a technically experienced Identity Security Engineer to join our security operations division...Work at officeRemote work- ...project management, applications development, infrastructure, Cyber security, and enterprise content/data management services. We have... ...Washington, DCJob DescriptionThe Identity and Authentication Security Engineer/Admin will be responsible for technical support to security...Remote work
$110k - $135k
...00 colleagues worldwide, all of whom are equity owners of the firm.Brown Advisory is currently seeking an Identity and Access Security Engineer to lead and mature the firm's identity security controls across Okta, Microsoft Entra ID, Active Directory, CyberArk, BloodHound...Full timeTemporary workFor contractorsH1bWorldwide- ...Modernisation, and Industry-Specific Software Solutions, DXC modernises, secures, and operates some of the world’s most complex technology... ...and New Zealand market, we are enhancing the Security Engineering Team who work within the Secured Infrastructure capacity to deliver...Full timeLocal area
$145k - $200k
Washington, D.C.Information Security /Full-time /HybridA World-Changing CompanyPalantir builds the world’s leading software for data-driven... ...the way a real attacker would. As an Offensive Security Engineer, you will test internal applications and infrastructure, chain...Full timeWork experience placementWork at officeRemote workWork from homeRelocation package- ...Responsibilities The U.S. Cybersecurity and Infrastructure Security (CISA) mission is to lead the national effort to protect and enhance... ...as well as its MEOs. This task order is to provide Enterprise Engineering and Operations Support Services (EEOSS) to CISA/OCIO to...Full timeNight shift
$5,000 per month
...Candidates who are not U.S. citizens are not eligible for this role. Imagine One Technology & Management, Ltd. is seeking two (2) Security Engineers. This position is contingent upon award of the associated work and will be performed in Dahlgren, Virginia.The Security...Work at office$230k - $385k
...artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are... ...customers in the public sector. As a Forward Deployed Security Engineer (FDSecE) you will be responsible for securing these novel applications...Work at officeLocal areaRemote workRelocation packageFlexible hours- ...Toll Brothers is seeking a Lead Security Engineer to join our Cyber & Information Security team at our Fort Washington, PA corporate office. You will lead security engineering initiatives, define standards, and drive incident response across identity, endpoints, networks...Work at office
- ...regulatory requirements to include but not limited to extensive engineering of Windows and Linux operating systems.Installing, configuring... ...systems, third party applications and operating system security patches.Troubleshooting operating systems, applications, and databases...
$155k
...Security Tools Engineer LeadRIVA Solutions is seeking an experienced Security Tools Engineer Lead to manage and sustain ITA cybersecurity tools and lead technical activities supporting enterprise threat detection, vulnerability management, application security, incident...Temporary workFlexible hours- ...Security Engineering LeadAt Accenture Federal Services, nothing matters more than helping the US federal government make the nation stronger and safer and life better for people. Our 13,000+ people are united in a shared purpose to pursue the limitless potential of technology...
- ...Bart & Associates, LLC is seeking a Senior Information Systems Security Engineer in Washington, DC, to lead cybersecurity engineering efforts for the FBI. This role includes overseeing RMF compliance, guiding risk management activities, and mentoring teams. Candidates...
- ...The task order for the Senior Cloud-based Endpoint Management Engineer position has been updated with revised primary responsibilities... ...device management issuesDevelop and deploy configuration profiles, security policies, and app management solutions for iPhones and iPads...Local area
$237.6k - $297k
...We are seeking a Senior Security Engineer with a specialty in Detection and Incident Response to join our Security Engineering team. This role sits at the intersection of security operations and software engineering - you won't just investigate incidents, you'll build...Full time$99k - $225k
...expert team focused on implementing and operating next‑generation security solutions for government and commercial clients. Perform hands... ...to solve complex security challenges. The role expands from engineering solutions to protect data and networks, supporting mission...Full timeContract work- ...A government services organization is seeking a skilled CrowdStrike Engineer to provide expertise in security engineering and cloud operations. The role entails architecting, configuring, and maintaining enterprise EDR/NGAV platforms. Candidates should possess a Bachelor...
- ...Onyx Government Services is seeking a knowledgeable Lead Security Engineer to lead application security across a large-scale, cloud-native federal modernization program for the U.S. Census Bureau. The role focuses on embedding security into every phase of the System Development...Work at office
- ...Jobtailor in the Washington, DC area seeks a senior IT/engineering lead to drive Apple/macOS engineering, design and optimize enterprise... ...will implement passwordless authentication, enforce endpoint security, and collaborate with cybersecurity and infrastructure teams to...
- ...Entarian seeks an experienced TIC System Engineer to design, implement, and maintain secure network perimeter defenses across multi-cloud environments. You will support TIC 3.0 and Zero Trust principles, configure F5 load balancers (LTM/GTM), Palo Alto firewalls, Panorama...
$90 - $95 per hour
...Permanent Resident Ability to obtain a Public Trust Clearance is required Summary: Immediate need for a techno-functional Senior Security Engineer to take the lead on an Optimal ZTA (Zero Trust Architecture) implementation and tackle challenges related to cloud security...Permanent employmentContract workImmediate start3 days per week- Deloitte's Cyber Defense and Resilience offering is seeking a SIEM Engineer to support security monitoring, detection engineering, and incident analysis across complex enterprise environments. This role will focus on building and optimizing SIEM content, improving alert...Remote work
- ...business development efforts for upcoming opportunities with the U.S. Department of State's Bureau of Diplomatic Security (DS) – Training – Technical Security Engineering. The Advisor will play a critical role in refining our understanding of the client landscape, validating...Contract workWork at office
$320k - $405k
...Extend device-trust and zero-trust access controls while balancing security protections with employee workflow needs. Build identity... ...software security reviews. Partner with Security, IT, and Engineering on telemetry, detections, shared standards, and secure...Full timeWork at officeVisa sponsorshipFlexible hours$135k - $200k
Washington, D.C.Information Security /Full-time /HybridA World-Changing CompanyPalantir builds the world’s leading software for data-driven... ...children, and more.The Role As a Senior Identity Security Engineer on Palantir's Identity Security team, you will own the security...Full timeWork experience placementWork at officeRemote workWork from homeRelocation packageShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer. Be the first to apply!
- security engineering manager Washington DC
- application security engineer Washington DC
- sr information security engineer Washington DC
- sr security engineer Washington DC
- senior application security engineer Washington DC
- information system security engineer Washington DC
- principal security engineer Washington DC
- physical security engineer Washington DC
- security engineer Washington DC
- aws cloud security engineer Washington DC


