Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

SECURITY & COMPLIANCE ENGINEER (SCE)

Zermount, Inc.

ZERMOUNT POSITION DESCRIPTION (PD) SECURITY & COMPLIANCE ENGINEERING (SCE)

POSITION OVERVIEW

Zermount Inc. is seeking System Compliance Engineering (SCE) to support system risk analysis and ensure that federal information systems comply with Information Assurance and cybersecurity standards. The SCE ensures that federal information systems are secure in operation, not merely compliant with documentation. This role directly contributes to mission assurance by identifying, validating, and mitigating real-world cybersecurity risks across enterprise environments. The SCE operates at the intersection of compliance, engineering, and mission operations, transforming federal mandates (e.g., NIST RMF, FISMA, EO 14028, OMB directives) into measurable, technically enforced security outcomes. Rather than relying solely on static assessments, the role requires continuous evaluation of the system\'s security posture by directly analyzing configurations, logs, architectures, and control implementations. This position is designed for individuals with foundational technical expertise across multiple domains, including cloud platforms, network architecture, operating systems, identity systems, and databases. You must be able to independently assess systems, identify exploitable conditions, and validate whether implemented controls effectively reduce risk in real-world scenarios. The role is a core component of Zermount\'s Modern GRC mindset, emphasizing: Continuous monitoring of system compliance responsibilities Real-time risk identification and prioritization Direct integration with system teams to drive remediation Elimination of "check-the-box" compliance practices You will be responsible for producing decision-quality outputs that enable system owners, ISSOs, and leadership to make informed, risk-based decisions. This includes identifying control failures, recommending technically sound remediation strategies, and validating that corrective actions are effective and sustainable.

DUTIES & RESPONSIBILITIES

General Duties – Execute RMF lifecycle (Prepare–Monitor) while validating controls directly in operational environments Identify and document real-time risks through analysis of logs, telemetry, configurations, and architecture Validate implementation of security controls (STIGs, MFA, encryption, access control) using system-level evidence Identify exploitable misconfigurations, weak trust boundaries, and gaps across cloud, network, OS, and database layers Drive POA&M actions by prioritizing risk based on exploitability and mission impact, ensuring closure within defined timelines Perform continuous monitoring (ISCM/CDM) with emphasis on actual system behavior vs. reported compliance Translate NIST, EO 14028, OMB, and TIC 3.0 requirements into specific technical remediation actions Validate remediation actions with repeatable verification methods (not documentation review) Produce executive-quality outputs (risk findings, remediation plans, executive summaries) Maintain system artifacts and documentation only as a byproduct of validated technical work

SUBJECT MATTER EXPERTISE (SME)

SME Area #1 – Primary Expertise: Technical Risk Validation (Modern GRC Execution) Expert-level means: Ability to independently assess systems using direct technical inspection techniques, leveraging logs, configs, architecture documents, etc. Deep working knowledge of critical frameworks and directives such as: NIST RMF (800-37, 800-53, etc.)

FISMA, EO 14028, OMB M-21-31 / M-22-09

FIPS 199/200

TIC 3.0 and Zero Trust principles (CISA ZT MM, NIST 800-207, etc.) Ability to identify threat surfaces within specific systems, not just control gaps Ability to convert compliance requirements into specific and actionable remediation actions that the system teams can be used to successfully remediate findings Required Tools Experience: Vulnerability scanning tools such as: Tenable, Qualys, CrowdStrike, etc. Log analysis platforms such as: Splunk, Microsoft Sentinel, IBM QRadar, etc. Configuration and system inspection tools such as: Ansible, Terraform, Puppet etc. GRC platforms such as: Archer, ServiceNow, etc. SME Area #2 – Secondary Expertise: Multi-Domain Technical Depth You must have deep knowledge of one or more of the following technical domains and must demonstrate the ability to leverage this experience to inform and complete compliance-related tasks. Technical Domains Cloud: AWS/Azure (IAM, logging, network security, misconfigurations) Network: Segmentation, firewalls, boundary protections, Zero Trust enforcement points Systems: Windows/Linux hardening, identity systems (AD, MFA) Databases/Data: Access control, encryption, auditing

QUALIFICATIONS

Minimum Requirements 5+ years of cybersecurity experience supporting U.S. Government systems 4+ years performing RMF, ISSO, Assessment, or GRC functions with direct technical validation responsibilities Demonstrated hands-on experience in at least two technical domains (cloud, network, systems, or databases) Proven ability to analyze: System configurations, ATOs, and other supporting security documentation Logs/telemetry Architecture documentation and data flow diagrams Preferred Qualifications Experience implementing or assessing Zero Trust architectures Experience with CDM, ISCM, and enterprise logging programs Familiarity with threat-informed defense concepts Experience in hybrid cloud environments Competency Technical risk identification and prioritization Independent problem-solving in ambiguous environments Ability to translate policy into technical action Clear communication with both engineers and leadership Education & Certifications Bachelor of Science (B.S.) in Computer Science, IT, Cybersecurity, or a related field, and a minimum of 5 years of IT cybersecurity experience, including direct support for the US Government and 4 years acting as an ISSO, Assessor, Compliance, RMF, or GRC with a technical validation role. Without a B.S. in a relevant field - A minimum of 10 years of IT Cybersecurity experience, including direct support for the US Government, and 4 years acting as an ISSO, Assessor, Compliance, RMF, or GRC with a technical validation role. At least one of the following security certifications is required: Certified Authorization Professional (CAP) Certified Information Security Auditor (CISA) Certified Information Security Manager (CISM) Certified Information Systems Security Professional (CISSP), or Certified Chief Information Security Officer (CCISO) Governance Risk & Compliance Certification (CGRC) Or alternatively approved certifications Clearance Level Minimum of active Secret Clearance and ability to obtain and maintain DHS suitability

WORK LOCATION

The position is primarily remote – Continental U.S only Primary location when on site: Arlington, VA, and Springfield, VA Must be willing to travel - Not to exceed 10% of the time

HOURS OF OPERATION

8:00 am EST – 4:30 pm EST Times may fluctuate based on client and business requirements

REPORTING STRUCTURE

Reports To: Security Compliance Engineering Team Lead Direct Reports: N/A #J-18808-Ljbffr Zermount, Inc.

Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the SECURITY & COMPLIANCE ENGINEER (SCE) in Arlington, VA vacancy
  • $60k

     ...partner supporting mission-critical programs across national security, defense, and public service delivery. Our work focuses on sustaining...  ...: Experience supporting documentation, reporting, and compliance activities Understanding of network monitoring tools and... 
    Suggested
    Contract work
    Remote work

    MAXIMUS

    Washington DC
    9 days ago
  • Zermount, Inc. is looking for a System Compliance Engineer in Arlington, VA. This remote role involves ensuring federal information systems meet cybersecurity standards by performing technical validations and risk assessments. Candidates should have 5+ years of experience... 
    Suggested
    Remote job

    Zermount, Inc.

    Arlington, VA
    4 days ago
  • $107.9k - $195.05k

    Leidos is seeking an experienced M365 Security and Compliance Administrator to join our Information Technology team. This role requires a seasoned...  ..., particularly in a federal agency context. This senior engineering role sits at the center of the organization’s device,... 
    Suggested
    Night shift
    Day shift

    Koitecc Solutions

    Washington DC
    2 days ago
  • A leading cybersecurity compliance firm is searching for a Sales Solutions Engineer to support customer engagement and drive compliance initiatives. This remote...  ...Successful candidates will have over 4 years of technical security experience and a strong understanding of... 
    Suggested
    Remote job
    Flexible hours

    Secureframe

    Washington DC
    3 days ago
  •  ...business development efforts for upcoming opportunities with the U.S. Department of State's Bureau of Diplomatic Security (DS) - Training - Technical Security Engineering. The Advisor will play a critical role in refining our understanding of the client landscape, validating... 
    Suggested
    Contract work
    Work at office

    Dexis Online

    Washington DC
    5 days ago
  • Elevenlabs is seeking a compliance-focused professional to support government compliance certifications across regulated industries. This...  ..., and candidates should have a strong background in vendor security assessments and compliance management tools. Key responsibilities... 
    Remote job

    Elevenlabs

    Washington DC
    1 day ago
  •  ...public-sector customers who demand experience and proven security models to protect their data. ShorePoint subscribes...  ...more. Who we're looking for: We are seeking Compliance and Continuous Monitoring Engineer - Vulnerability Management (Top Secret Clearance) with... 

    ShorePoint Inc

    Washington DC
    3 days ago
  • $40 per hour

    A cybersecurity firm is seeking experienced cybersecurity professionals to evaluate AI-generated security content, solve technical problems, and provide feedback to improve AI systems. This is a flexible remote position, allowing you to work on chosen projects within a... 
    Remote job
    Hourly pay
    Flexible hours

    DataAnnotation

    Washington DC
    4 days ago
  •  ...Network Security Engineer (Cisco, Palo Alto) About Us: We are a dynamic technology services company based in Washington, DC, specializing in cutting-edge network solutions. We are seeking a skilled Network Engineer to join our team to ensure the seamless operation... 
    Remote work

    Elios

    Washington DC
    1 day ago
  •  ...Web Developer Security Engineer At Ardent, we hire people who want more than a job — they want to serve a mission that matters. Our teams...  ...and remediating application vulnerabilities, supporting compliance initiatives, and implementing security controls that help ensure... 
    Local area
    Remote work
    Flexible hours

    Ardent Services

    Washington DC
    12 days ago
  • $71.2k - $158.2k

     ...Job Description The Senior Federal Information Systems Security Engineer (ISSE) serves as a technical integrator responsible for ensuring...  ...week as needed to support mission timelines • Maintain compliance with all corporate and federal cybersecurity policies •... 
    Contract work
    Temporary work
    Work experience placement
    Relocation
    Flexible hours

    Oracle

    Arlington, VA
    2 days ago
  •  ...Senior Security Operations Engineer Job Title: Senior Security Operations Engineer Location: Washington, DC Note: This is an onsite position...  ...monitoring, workload protection, identity security, and compliance monitoring capabilities. Perform hands-on system integration... 

    Tri-Force Consulting Services Inc. | IT Recruitment & Staffi...

    Washington DC
    2 days ago
  •  ...About the Role The Security Operations Engineer supports the day-to-day operation of security technologies that safeguard corporate systems...  ...procedures up to date to support operational readiness and compliance expectations. Vulnerability Management Support... 

    Nexus IT Group

    Washington DC
    1 day ago
  •  ...Security Engineer We are looking for a Security Engineer to join our team on an effort supporting our Federal Government Client in Washington...  ...and the client to ensure your system is within FISMA compliance. Provide security artifacts to ensure your systems security... 

    Ryde Technologies

    Washington DC
    13 days ago
  • $120k - $180k

     ...Corporate Security Engineer State Affairs is the nation's leading news and policy intelligence platform focused on state governments....  ...management, endpoint security, security alert triage, device compliance, security automation, and corporate IT security operations.... 
    Work at office
    Local area

    State Affairs

    Washington DC
    1 day ago
  • $65 - $75 per hour

     ...associated with endpoint vulnerability scanning; Work Cyber related security operations ITSM (ServiceNow) assigned tickets to completion;...  .... Manages workstation anti-virus software, DAT, and engineer updates. Performs virus scans and updates as scheduled.... 
    Full time

    Aditi Consulting

    Washington DC
    4 days ago
  • $63 - $70 per hour

     ...Security Engineer Tech Tammina LLC Job Description Hi, Trying to reach you.. I just came across your resume and want to see if you...  ...tools 2. Tenable Security Center; vulnerability and compliance assessments, results analysis, process improvement 3. SourceFIRE... 
    Hourly pay
    Contract work
    Relocation
    Work visa

    Tech Tammina

    Washington DC
    17 hours ago
  •  ...Senior Security Engineer We are seeking a Senior Security Engineer to strengthen cloud and software environments, ensuring compliance with U.S. government security standards. This role is critical in securing mission-critical cloud applications and maintaining compliance... 

    Executive Recruiting

    Washington DC
    17 hours ago
  •  ...Title: Senior Security Engineer Location : Arlington, VA Duration: 12 months Enterprise Security Architecture and Innovation works to ensure that enterprise-wide technologies are secure, by design, to protect and enable the business. This team provides advisory... 

    Maintec Technologies

    Arlington, VA
    17 hours ago
  •  ...Security Engineer - Zscaler ID 2026-9435 Type Full Time W/Benefits Ret Match Location : Location US-VA-Arlington...  ...Governance policies to prevent data exposure, ensure compliance across SaaS applications, and drive innovation for management... 
    Full time
    Night shift

    ERT

    Arlington, VA
    2 days ago
  • $105.28k - $195.52k

     ...Senior Waf Security Engineer – Edge/Perimeter Welcome to Warner Bros. Discovery… the stuff dreams are made of. When we say, "the stuff...  ...accessibility page for instructions to submit your request. In compliance with local law, we are disclosing the compensation, or a... 
    Temporary work
    Work experience placement
    Work at office
    Local area

    Warner Bros.

    Washington DC
    1 day ago
  •  ...Full-Time Description RiVidium is seeking a Security Engineer (ISSE) to support our planned MODES III team supporting Military...  ...Support secure configurations, control implementation, compliance activities, and technical remediation. Coordinate with... 
    Full time
    Contract work
    Part time

    Rividium Inc

    Alexandria, VA
    1 day ago
  •  ...Security Engineer Detection & Response Security is at the foundation of OpenAI's mission to ensure that artificial general intelligence...  ...response will be provided to inquiries unrelated to job posting compliance. We are committed to providing reasonable accommodations... 

    OpenAI

    Washington DC
    1 day ago
  •  ...Evolver Federal is seeking a Senior Security Engineer to fulfill a requirement for a potential government client. The Senior Security Engineer...  ...data. This role prioritizes continuous monitoring, FISMA compliance, and OIG audit readiness while engineering secure... 
    Contract work
    Flexible hours

    Evolver

    Washington DC
    1 day ago
  •  ...Sr. Security Engineer Job Description Overview CoStar Group (NASDAQ: CSGP) is a leading global provider of commercial and residential...  ...efforts in coordination with legal, privacy, and compliance teams. Develop reusable SaaS security review patterns and... 
    Full time
    Work at office
    Work from home
    Monday to Thursday

    CoStar Realty Information, Inc.

    Arlington, VA
    4 days ago
  •  ...Senior Network Security Engineer II As a Senior Network Security Engineer II you will lead the design, implementation, and maintenance...  ...functional teams to ensure the highest levels of security and compliance for our network architecture while aligning with the company... 
    Remote work
    Flexible hours

    Aledade, Inc.

    Washington DC
    20 days ago
  •  ...solutions, tested leadership, and trusted results to enable national security missions worldwide. Job Description ***** This position is...  ...***** Overview SOSi is seeking a Cybersecurity Security Engineer III to support cybersecurity engineering activities in... 
    Full time
    Contract work
    Work at office
    Worldwide
    Monday to Friday
    Weekend work
    Afternoon shift

    SOS International LLC

    Washington DC
    5 days ago
  •  ...Threat Detection Security Engineer Job Description Overview CoStar Group (NASDAQ: CSGP) is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces. Included in the S&P 500 Index and the NASDAQ 100,... 
    Full time
    Work at office
    Work from home
    Monday to Thursday

    CoStar Group

    Arlington, VA
    3 days ago
  •  ...Everforth ECS Federal is seeking a Mid-Level Endpoint Security Engineer to support a mission-focused federal cybersecurity program in...  ...security activity, enforce approved workflows, and support compliance for mission-critical systems. The Endpoint Security Engineer... 
    Contract work

    ECS Limited

    Washington DC
    4 days ago
  •  ...website at: Position Tit le: Sr. Operational Technology (OT) Security Engineer Location : NCR Clearance : TS /SCI OneZero...  ...for Federal Information Security Modernization Act (FISMA) compliance, execution of the Risk Management Framework (RMF) process to... 
    Full time
    Contract work
    Work at office

    OneZero Solutions

    Washington DC
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to SECURITY & COMPLIANCE ENGINEER (SCE). Be the first to apply!