Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

SECURITY & COMPLIANCE ENGINEER (SCE)

Zermount, Inc.

ZERMOUNT POSITION DESCRIPTION (PD) SECURITY & COMPLIANCE ENGINEERING (SCE)

POSITION OVERVIEW

Zermount Inc. is seeking System Compliance Engineering (SCE) to support system risk analysis and ensure that federal information systems comply with Information Assurance and cybersecurity standards. The SCE ensures that federal information systems are secure in operation, not merely compliant with documentation. This role directly contributes to mission assurance by identifying, validating, and mitigating real-world cybersecurity risks across enterprise environments. The SCE operates at the intersection of compliance, engineering, and mission operations, transforming federal mandates (e.g., NIST RMF, FISMA, EO 14028, OMB directives) into measurable, technically enforced security outcomes. Rather than relying solely on static assessments, the role requires continuous evaluation of the system\'s security posture by directly analyzing configurations, logs, architectures, and control implementations. This position is designed for individuals with foundational technical expertise across multiple domains, including cloud platforms, network architecture, operating systems, identity systems, and databases. You must be able to independently assess systems, identify exploitable conditions, and validate whether implemented controls effectively reduce risk in real-world scenarios. The role is a core component of Zermount\'s Modern GRC mindset, emphasizing: Continuous monitoring of system compliance responsibilities Real-time risk identification and prioritization Direct integration with system teams to drive remediation Elimination of "check-the-box" compliance practices You will be responsible for producing decision-quality outputs that enable system owners, ISSOs, and leadership to make informed, risk-based decisions. This includes identifying control failures, recommending technically sound remediation strategies, and validating that corrective actions are effective and sustainable.

DUTIES & RESPONSIBILITIES

General Duties – Execute RMF lifecycle (Prepare–Monitor) while validating controls directly in operational environments Identify and document real-time risks through analysis of logs, telemetry, configurations, and architecture Validate implementation of security controls (STIGs, MFA, encryption, access control) using system-level evidence Identify exploitable misconfigurations, weak trust boundaries, and gaps across cloud, network, OS, and database layers Drive POA&M actions by prioritizing risk based on exploitability and mission impact, ensuring closure within defined timelines Perform continuous monitoring (ISCM/CDM) with emphasis on actual system behavior vs. reported compliance Translate NIST, EO 14028, OMB, and TIC 3.0 requirements into specific technical remediation actions Validate remediation actions with repeatable verification methods (not documentation review) Produce executive-quality outputs (risk findings, remediation plans, executive summaries) Maintain system artifacts and documentation only as a byproduct of validated technical work

SUBJECT MATTER EXPERTISE (SME)

SME Area #1 – Primary Expertise: Technical Risk Validation (Modern GRC Execution) Expert-level means: Ability to independently assess systems using direct technical inspection techniques, leveraging logs, configs, architecture documents, etc. Deep working knowledge of critical frameworks and directives such as: NIST RMF (800-37, 800-53, etc.)

FISMA, EO 14028, OMB M-21-31 / M-22-09

FIPS 199/200

TIC 3.0 and Zero Trust principles (CISA ZT MM, NIST 800-207, etc.) Ability to identify threat surfaces within specific systems, not just control gaps Ability to convert compliance requirements into specific and actionable remediation actions that the system teams can be used to successfully remediate findings Required Tools Experience: Vulnerability scanning tools such as: Tenable, Qualys, CrowdStrike, etc. Log analysis platforms such as: Splunk, Microsoft Sentinel, IBM QRadar, etc. Configuration and system inspection tools such as: Ansible, Terraform, Puppet etc. GRC platforms such as: Archer, ServiceNow, etc. SME Area #2 – Secondary Expertise: Multi-Domain Technical Depth You must have deep knowledge of one or more of the following technical domains and must demonstrate the ability to leverage this experience to inform and complete compliance-related tasks. Technical Domains Cloud: AWS/Azure (IAM, logging, network security, misconfigurations) Network: Segmentation, firewalls, boundary protections, Zero Trust enforcement points Systems: Windows/Linux hardening, identity systems (AD, MFA) Databases/Data: Access control, encryption, auditing

QUALIFICATIONS

Minimum Requirements 5+ years of cybersecurity experience supporting U.S. Government systems 4+ years performing RMF, ISSO, Assessment, or GRC functions with direct technical validation responsibilities Demonstrated hands-on experience in at least two technical domains (cloud, network, systems, or databases) Proven ability to analyze: System configurations, ATOs, and other supporting security documentation Logs/telemetry Architecture documentation and data flow diagrams Preferred Qualifications Experience implementing or assessing Zero Trust architectures Experience with CDM, ISCM, and enterprise logging programs Familiarity with threat-informed defense concepts Experience in hybrid cloud environments Competency Technical risk identification and prioritization Independent problem-solving in ambiguous environments Ability to translate policy into technical action Clear communication with both engineers and leadership Education & Certifications Bachelor of Science (B.S.) in Computer Science, IT, Cybersecurity, or a related field, and a minimum of 5 years of IT cybersecurity experience, including direct support for the US Government and 4 years acting as an ISSO, Assessor, Compliance, RMF, or GRC with a technical validation role. Without a B.S. in a relevant field - A minimum of 10 years of IT Cybersecurity experience, including direct support for the US Government, and 4 years acting as an ISSO, Assessor, Compliance, RMF, or GRC with a technical validation role. At least one of the following security certifications is required: Certified Authorization Professional (CAP) Certified Information Security Auditor (CISA) Certified Information Security Manager (CISM) Certified Information Systems Security Professional (CISSP), or Certified Chief Information Security Officer (CCISO) Governance Risk & Compliance Certification (CGRC) Or alternatively approved certifications Clearance Level Minimum of active Secret Clearance and ability to obtain and maintain DHS suitability

WORK LOCATION

The position is primarily remote – Continental U.S only Primary location when on site: Arlington, VA, and Springfield, VA Must be willing to travel - Not to exceed 10% of the time

HOURS OF OPERATION

8:00 am EST – 4:30 pm EST Times may fluctuate based on client and business requirements

REPORTING STRUCTURE

Reports To: Security Compliance Engineering Team Lead Direct Reports: N/A #J-18808-Ljbffr Zermount, Inc.

Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the SECURITY & COMPLIANCE ENGINEER (SCE) in Arlington, VA vacancy
  • Zermount, Inc. is looking for a System Compliance Engineer in Arlington, VA. This remote role involves ensuring federal information systems meet cybersecurity standards by performing technical validations and risk assessments. Candidates should have 5+ years of experience... 
    Suggested
    Remote job

    Zermount, Inc.

    Arlington, VA
    4 days ago
  • Secureframe, Inc. seeks a Sales Solutions Engineer to enhance customer engagement and drive GTM...  ...advising customers throughout IT audit and compliance initiatives. The ideal candidate should have 4+ years in technical security consulting or sales, along with strong knowledge... 
    Suggested
    Remote job
    Flexible hours

    Secureframe, Inc.

    Washington DC
    5 days ago
  • $107.9k - $195.05k

    Leidos is seeking an experienced M365 Security and Compliance Administrator to join our Information Technology team. This role requires a seasoned...  ..., particularly in a federal agency context. This senior engineering role sits at the center of the organization’s device,... 
    Suggested
    Full time
    Night shift
    Day shift

    Leidos

    Washington DC
    2 days ago
  • $110k - $135k

     ...Proven Recruiting is looking for a Compliance Engineer to join their fast-growing cybersecurity organization. In this remote role, you will assist government contractors in achieving CMMC compliance. Ideal candidates have over 5 years in systems and network experience,... 
    Suggested
    For contractors
    Remote work

    Proven Recruiting

    Arlington, VA
    1 day ago
  •  ...business development efforts for upcoming opportunities with the U.S. Department of State's Bureau of Diplomatic Security (DS) - Training - Technical Security Engineering. The Advisor will play a critical role in refining our understanding of the client landscape, validating... 
    Suggested
    Contract work
    Work at office

    DEXIS

    Washington DC
    5 days ago
  • $159.3k - $202.4k

     ...Description Amazon Healthcare Security's (HealthSec) AI team is hiring a Security Engineer II to secure GenAI applications and enable secure AI adoption across...  ...AI systems handling healthcare data meet HIPAA compliance and Amazon's security bar while improving... 
    Flexible hours

    Amazon

    Arlington, VA
    5 days ago
  • $159.3k - $202.4k

     ...Amazon's Threat Hunting team is looking for a Security Engineer, Threat Hunting who is excited by the idea of searching for and uncovering undetected threat activities at petabyte scale. In this role, you will work alongside other Threat Hunting engineers to proactively... 
    Flexible hours
    Shift work

    Amazon

    Arlington, VA
    4 days ago
  • $178.4k - $226.7k

     ...Corporate Services Security (CPSS) is the Amazon security team aligned with Finance & Global Business Services (FGBS), People eXperience...  ...Services. Apart from work, we provide opportunities for our engineers to pursue projects they are passionate about while maintaining... 
    Internship
    Flexible hours

    Amazon

    Arlington, VA
    4 days ago
  • $136k - $184k

     ...At Amazon Healthcare Security, we are on a mission to make healthcare secure and easy. We...  ...convenient. We are looking for a Security Engineer to join our team. As a Security...  ...Experience in information security and compliance - Experience with vulnerability risk and... 
    Temporary work
    Internship
    Flexible hours

    Amazon

    Arlington, VA
    7 hours ago
  • $237.6k - $297k

     ...Security Engineer, Product Security We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and integrity of our products and services. You will conduct in-depth code reviews, implement security... 
    Full time

    Scale AI

    Washington DC
    7 hours ago
  •  ...public-sector customers who demand experience and proven security models to protect their data. ShorePoint subscribes...  ...more. Who were looking for: We are seeking Compliance and Continuous Monitoring Engineer - Vulnerability Management (Top Secret Clearance)with... 

    ShorePoint Inc

    Washington DC
    3 hours ago
  •  ...Network Security Engineer (Cisco, Palo Alto) About Us: We are a dynamic technology services company based in Washington, DC, specializing in cutting-edge network solutions. We are seeking a skilled Network Engineer to join our team to ensure the seamless operation... 
    Remote work

    Elios

    Washington DC
    1 day ago
  • $60 - $68 per hour

     ...Overview Novacoast Staffing is currently assisting a financial government institution in its search for an experienced Firewall Security Engineer that is experienced in Palo Alto Firewalls for a contract role that is expected to go a minimum of 2 years with option to... 
    Hourly pay
    Contract work
    Immediate start

    Novacoast

    Washington DC
    1 day ago
  • $90k - $150k

     ...lifesaving drugs, forecast supply chain disruptions, locate missing children, and more. The Role As a Compliance Engineer, you will help our engineers implement Palantir Security Controls across our entire product line. You’ll work closely with many different teams to shape... 
    Work experience placement
    Work at office
    Remote work
    Work from home
    Relocation package

    Palantir

    Washington DC
    5 days ago
  • $237.6k - $297k

    We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and integrity of our products and services. You will conduct in-depth code reviews, implement security best practices, and influence the... 
    Full time

    Scale AI, Inc.

    Washington DC
    1 day ago
  •  ...VMware and Hyper-V. This position supports operational excellence in a large-scale enterprise environment and requires collaboration with various IT teams to mitigate security threats. Competitive compensation and benefits are included. #J-18808-Ljbffr AHU Technologies

    AHU Technologies

    Washington DC
    4 days ago
  • A security compliance firm in Washington, DC is searching for an experienced acoustic testing specialist. This role involves ensuring facilities comply with ICD/ICS 705 standards through expert testing and documentation. Candidates must have an active U.S. Top Secret clearance... 

    ContinuityGS

    Washington DC
    4 days ago
  • $166k - $253k

     ...months, not years. ABOUT THE JOB We're seeking a Security Software Engineer to develop novel security tooling for securing embedded Linux...  ...Knowledge of security frameworks and compliance standards. Experience in mobile development, specifically... 
    Full time
    Work experience placement
    Immediate start

    Anduril Industries

    Washington DC
    1 day ago
  •  ...Senior Security Operations Engineer Job Title: Senior Security Operations Engineer Location: Washington, DC Note: This is an onsite position...  ...monitoring, workload protection, identity security, and compliance monitoring capabilities. Perform hands-on system integration... 

    Tri-Force Consulting Services Inc. | IT Recruitment & Staffi...

    Washington DC
    2 days ago
  • $164.38k - $212.75k

     ...Information Assurance, Information System Security, Risk Assessments Certifications:...  ...opportunity as a Cybersecurity Systems Engineer/Information Systems Security Engineer (ISSE...  ...Support audit liaison activities, and compliance oversight activities to strengthen the security... 
    Temporary work
    For contractors
    Interim role
    Summer work
    Immediate start
    Remote work
    Worldwide
    Relocation
    Flexible hours

    General Dynamics Information Technology

    Washington DC
    7 hours ago
  • $71.2k - $158.2k

     ...Senior Federal Information Systems Security Engineer (ISSE) The Senior Federal Information Systems Security Engineer (ISSE) serves as...  ...per week as needed to support mission timelines · Maintain compliance with all corporate and federal cybersecurity policies · Protect... 
    Contract work
    Temporary work
    Work experience placement
    Relocation
    Flexible hours

    Oracle

    Arlington, VA
    2 days ago
  • $125k - $150k

     ...service and strategic capability, embedding security, automation, and operational rigor...  ...About the Role The Security Operations Engineer is a hands-on technical role responsible...  ...while enabling speed, reliability, and compliance. Our aim is to hire this position to... 
    Permanent employment
    Work at office
    Local area
    Remote work
    Worldwide
    Flexible hours

    Umbra

    Arlington, VA
    7 hours ago
  •  ...About the Role The Security Operations Engineer supports the day-to-day operation of security technologies that safeguard corporate systems...  ...procedures up to date to support operational readiness and compliance expectations. Vulnerability Management Support... 

    Nexus IT Group

    Washington DC
    1 day ago
  • $160k - $180k

    Governance, Risk, Compliance (GRC) Engineer Washington, DC Electrosoft Services, Inc. is an award-winning company that provides comprehensive technology-based solutions and services to federal customers. While cybersecurity is our specialty, we also focus on ICAM, enterprise... 
    For contractors

    Electrosoft

    Washington DC
    5 days ago
  • Honeywell Aerospace is hiring a Sr Export Compliance Officer in Washington, DC. This role involves providing crucial export compliance guidance and ensuring adherence to US export laws and regulations. The candidate will work on a hybrid schedule, collaborating with technical... 

    Honeywell Aerospace

    Washington DC
    5 days ago
  •  ...Security Engineer Location: Washington, D.C (On-site M-F at JBAB) Duration: Full Time Clearance: Security Clearance: TS/SCI + required and able to receive their PSD/Yankee White, or Active Yankee White Clearance Company Description Our... 
    Full time

    Scout Solutions Inc Defunct

    Washington DC
    5 days ago
  • $90 - $100 per hour

     ...4 hours Job Description: Short Description: IT Security Engineer Complete Description: Description The...  ...network design projects and procurement or outsourcing plans for compliance with standards and architectural plans. Operational... 
    Hourly pay
    Permanent employment
    Temporary work
    For contractors
    Work experience placement
    Remote work
    Work from home
    Flexible hours

    AHU Technologies, Inc.

    Washington DC
    3 days ago
  •  ...Security Firewall Engineer We are looking for a Security Firewall Engineer with vast Palo Alto experience and whose responsibilities will include designing, implementing, managing, and maintaining our clients network security systems. The role focuses on ensuring the... 

    Samprasoft

    Washington DC
    1 day ago
  •  ...Security Engineer Tempo is a layer-1 blockchain purpose-built for stablecoins and real-world payments, born from Stripe's experience in...  ...infrastructure. As a security engineer, you won't just be ticking compliance boxes; you will be writing Rust fuzzers, simulating economic... 
    Full time

    Tempo LLC

    Washington DC
    1 day ago
  • $90k - $150k

     ...generating creative solutions to ambiguous security requirements. Our mission is deploying...  .... As a Forward Deployed Security Engineer, you support a variety of projects which...  ...with strategic insights on technical and compliance risks Partner with Business Development... 
    Work experience placement
    Work at office
    Remote work
    Work from home
    Relocation package

    Palantir Technologies

    Washington DC
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to SECURITY & COMPLIANCE ENGINEER (SCE). Be the first to apply!