Senior Security Engineer
eSimplicity Inc
Job Type
Full-time
eSimplicity is a modern digital services company that partners with government agencies to improve the lives and protect the well-being of all Americans, from veterans and service members to children, families, and seniors. Our engineers, designers, and strategists cut through complexity to create intuitive products and services that equip federal agencies with solutions to courageously transform today for a better tomorrow
This position is contingent upon contract award
Responsibilities:
- Designing, implementing, and maintaining security controls across the Salesforce-based MESH platform and AWS cloud environment in accordance with CMS Acceptable Risk Safeguards (ARS) 5.1, FedRAMP Moderate, and NIST SP 800-53 Rev 5
- Embedding security into the DevSecOps CI/CD pipeline by integrating SAST, DAST, IAST, and software composition analysis tools (e.g., Snyk, AppOmni, Tenable, AWS Security Hub) into GitHub Actions and Copado workflows
- Operating the end-to-end vulnerability management lifecycle including detection, triage, prioritization, remediation tracking, and reporting; ensuring critical and high findings are remediated within CMS/HHS-defined timeframes
- Performing and documenting Security Impact Analyses (SIAs) for proposed changes to the MESH platform and integrations such as T-MSIS, MBES/MacFin, Microsoft 365, and CMS DataConnect
- Authoring, maintaining, and updating Authority to Operate (ATO) artifacts in CFACTS, including System Security Plans (SSPs), POA&Ms, Privacy Impact Assessments, Contingency Plans, and Incident Response Plans
- Hardening Salesforce GovCloud configurations by enforcing role-based access, permission sets, OAuth/MFA, and Salesforce Shield controls; reviewing third-party AppExchange packages for security risk prior to installation
- Configuring and tuning continuous monitoring and detection tooling (Splunk, AWS GuardDuty, CloudTrail, Security Hub) and leading incident response from detection through post-mortem review
- Leading least-privilege access reviews and identity lifecycle workflows across CMS IDM/Okta, EUA, AWS IAM, Salesforce, and CI/CD pipelines; automating recurring access reviews and onboarding/offboarding tasks
- Building dashboards and reports in Splunk, Power BI, or Jira that give CMS leadership and product teams visibility into vulnerabilities, compliance posture, access reviews, and audit readiness
- Translating CMS, HHS, and federal AI governance requirements into actionable secure design patterns for AI/ML capabilities embedded in MESH (e.g., AI-assisted submission analysis, NLP search, predictive analytics)
- Participating in Agile ceremonies as a security subject matter expert, ensuring user stories include clear security acceptance criteria and that security enablers are represented in the team Definition of Done
- Mentoring developers, QA, and DevOps engineers on secure coding practices (OWASP ASVS), threat modeling, and continuous compliance
- Cooperating with CMS-directed audits, penetration tests, and 3PAO assessments; coordinating responses to agency security data calls within required timeframes
- All candidates must pass public trust clearance through the U.S. Federal Government. This requires candidates to either be U.S. citizens or pass clearance through the Foreign National Government System which will require that candidates have lived within the United States for at least 3 out of the previous 5 years, have a valid and non-expired passport from their country of birth and appropriate VISA/work permit documentation
- Bachelor's degree in Computer Science, Information Systems, Engineering, or other related scientific or technical discipline
- 8+ years of hands-on security engineering experience supporting cloud-hosted federal information systems
- Demonstrated experience implementing and maintaining ATOs under CMS or HHS, including authoring SSPs, POA&Ms, and continuous monitoring artifacts in CFACTS or equivalent GRC tooling
- Strong working knowledge of NIST RMF, NIST SP 800-53 Rev 5, FedRAMP Moderate baseline, and CMS ARS 5.1 controls
- Hands-on experience with AWS security services (IAM, GuardDuty, CloudTrail, Security Hub, KMS, Config) and Salesforce security best practices (profiles, permission sets, Salesforce Shield, OAuth/MFA, AppOmni)
- Experience integrating security gates into CI/CD pipelines using GitHub Actions, Copado, Jenkins, Terraform, or equivalent
- Hands-on configuration and tuning of vulnerability and security testing tools such as Snyk, Tenable Nessus, Invicti, OWASP ZAP, AppOmni, and Splunk
- Hands-on scripting and automation skills (Python, Bash, PowerShell, REST APIs)
- Working knowledge of FIPS 140 validated encryption, HIPAA, the Privacy Act of 1974, and Section 508 considerations as they apply to federal information systems
- Experience with Atlassian Jira and Confluence and CMS-style agile delivery environments
- Federal Government contracting work experience, particularly with CMS or other HHS Operating Divisions
- Prior work supporting Medicaid, Medicare, MACBIS, or other CMS Center for Medicaid and CHIP Services programs
- Industry security certifications such as CISSP, CISM, CRISC, GIAC (GCSA, GCIH, GWAPT), or CEH
- Cloud security certifications such as AWS Certified Security - Specialty, AWS Solutions Architect, CCSP, or CCSK
- Salesforce certifications such as Administrator, Platform Developer, or Salesforce Certified Security & Privacy Architect
- Experience securing AI/ML pipelines and applying federal AI governance guidance, explainability (XAI), and model risk management practices
- The ability to brief technical and non-technical leadership
Occasional travel for training and project meetings. It is estimated to be less than 5% per year.
Candidates are expected to participate in on-call rotations, during business hours, and as needed (for high-priority incidents) outside of normal business hours.
Benefits:
eSimplicity offers a comprehensive benefits package, including medical, dental, and vision coverage, 401(k) retirement benefits, paid time off, paid holidays, life and disability insurance, and additional wellness and employee support programs. Eligibility may vary based on employment status and applicable plan terms.
Reasonable Accommodation:
eSimplicity is committed to providing reasonable accommodations to qualified individuals with disabilities during the application and hiring process. Applicants who need assistance or an accommodation should contact Human Resources. Equal Employment Opportunity:
eSimplicity is an Equal Opportunity Employer, including disability and protected veteran status. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran status, disability, or any other legally protected status
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Senior Security Engineer in Columbia, MD vacancy
- ...A technology solutions provider in Columbia, MD, is seeking a Senior Security Engineer to architect and maintain security controls across varied environments. Ideal candidates will have over 8 years of experience securing enterprise IT systems and expert knowledge of...SeniorFlexible hours
$1,500 - $3,000 per month
...personal and family goals with flexibility. Tulzi offers secure network systems and software engineering solutions in both public and private sectors. With... ...cycle. Clearance Required: TS/SCI Title: Senior Security Engineer Location: Columbia, MD...SeniorHourly payTemporary workLocal area- ...A leading technology firm in Columbia, MD, is searching for a Senior Security Engineer. This role requires expertise in architecting and maintaining security infrastructure across diverse environments. Candidates must have over 8 years of relevant experience and demonstrate...Senior
$155k - $175k
...PAE Government Services Inc. is seeking a skilled security engineer to manage enterprise-level security for various network environments. The role involves architecting security controls, leading patch management, and mentoring junior engineers while ensuring compliance...Senior- ...H. T. PROF Group is seeking a Senior Information Systems Security Engineer in Columbia, MD. This role involves providing technical security engineering guidance and ensuring compliance with government frameworks. Responsibilities include developing System Security Plans...Senior
- ...A leading technology company is looking for a General-Purpose Offensive Security Operations Reverse Engineer in Columbia, MD. The successful candidate will design, develop, prototype, and integrate solutions for mission-centric results while collaborating with analysts...Senior
$120.8k - $265.8k
...Join to apply for the Senior Network Security Engineer role at CACI International Inc Job Category: Information Technology Time Type: Full time Minimum Clearance Required to Start: TS/SCI with Polygraph Employee Type: Regular Percentage of Travel...SeniorFull timeContract workWork experience placementLocal areaWorldwide$120.8k - $265.8k
...Job Title: Senior Network Security Engineer Job Category: Information Technology Time Type: Full time Minimum Clearance Required to Start: TS/SCI with Polygraph Employee Type: Regular Percentage of Travel Required: Up to 10% Type of Travel: Local *...SeniorFull timeContract workWork experience placementLocal areaFlexible hours- ...HRB is looking for a Senior Security Engineer to lead and implement security solutions for complex IT environments. This hands-on role requires expertise in architecting and maintaining security technologies, ensuring compliance across organizational policies. Ideal candidates...Senior
- ...A leading technology company in Maryland, Columbia, is seeking a Safety Engineer to configure IT and network components in a security-critical environment. Responsibilities include collaborating with stakeholders, ensuring compliance, and conducting acceptance tests to...Senior
- ...Leidos in Bethesda, Maryland is seeking a motivated individual to support the Lead Information System Security Officer with System Security Plans. Candidates must have a Bachelor's degree and 8 years of relevant experience in Information Security. Responsibilities include...Senior
$175k - $250k
...Senior Information Security Engineer Maryland, United States Seeking experienced offensive security professionals to conduct security assessments, red team operations, and network exploitation activities in support of client security requirements. What You'll...SeniorWork experience placement$180k - $230k
...Senior ISSE (Information Systems Security Engineer) Location: Columbia, MD Type: Direct Hire ID: TX(***) ***-**** Salary Range: $180,000 – $230,000 Clearance Required: TS/SCI with Full Scope Polygraph Position Overview This role provides technical security engineering guidance...Senior$168k - $240k
...(BBJ) Best Places to Work 2019, runner up in 2020 and a finalist in 2021! Belay Technologies is seeking an Information Security System Engineer (ISSE) to join our intel team. The Information Systems Security Engineer (ISSE) shall perform, or review, technical security...SeniorContract workWork experience placementFlexible hours$168k - $240k
...Best Places to Work 2019, runner-up in 2020, and a finalist in 2021! Belay Technologies is seeking a Sr. Information System Security Engineer (ISSE) with a solid understanding of security practices and policies as well as hands-on vulnerability testing experience. The...SeniorContract workWork experience placementFlexible hours$150k - $250k
...Senior Reverse Engineer - Embedded Security An innovative technology company is seeking a Senior Reverse Engineer. In this role, you will lead interesting and complex security research initiatives focusing on hardware and software integrity. You will collaborate with...SeniorRelocation$131.3k - $237.35k
...A technology solutions provider based in Columbia, Maryland seeks a Python Developer to join their team of security researchers. The ideal candidate will have experience in Python development, Docker, and AWS. Responsibilities include troubleshooting applications and...Senior$165.03k - $240k
Enlighten is seeking a highly skilled Software Security Engineer in Columbia, Maryland. This role involves spearheading a team to implement advanced software capabilities within a hybrid work environment. The ideal candidate will possess significant Systems/Software Engineering...Senior- ...Everfox Holdings LLC is seeking a Principal Cyber Engineer for their Columbia, MD location. The role involves solving complex cybersecurity challenges supporting the U.S. Government, utilizing Linux and scripting expertise to ensure customer success. The successful...Senior
- ...A leading technology company based in the U.S. is seeking a Principal Endpoint Security Systems Engineer. This role focuses on designing, deploying, and maintaining robust endpoint security capabilities in a hybrid cloud environment. The ideal candidate will have extensive...Senior
- ...us support all our customers. With certified experts consulting our clients, we can address the customer’s mission. Senior Security Engineer Required Qualifications: AD (+10) years of relevant experience BA/BD (+6) years of relevant experience Master'...SeniorFor contractors
- ...Eccalon LLC in Hanover, MD is seeking a Senior Cybersecurity Engineer / Security Architect to implement advanced cybersecurity solutions for high-assurance environments handling sensitive information. The successful candidate will possess a strong background in multilevel...SeniorFull time
$170k - $185k
...Job Description Job Description Title: Senior Offensive Security Engineer Reports to: Director, Product Security and Incident Response Location: Remote Compensation Range: $170,000.00 to $185,000.00 base plus bonus and equity What We Do: Cybercrime...SeniorFull timeRemote workWorldwideHome office- ...GliaCell Technologies is hiring a Senior Software Engineer / Reverse Engineer in Laurel, MD, to develop advanced security tools for a federal client. The role involves building Python applications, reverse engineering web traffic, and collaborating with analysts and developers...Senior
$100k - $245k
Join the Johns Hopkins Applied Physics Lab as a Senior System Security Engineer, contributing to critical defense and security missions. You will lead interdisciplinary teams in designing and engineering resilient solutions. The role requires a Bachelor's degree and 7+...Senior$176k - $282k
...Senior Cyber Software Engineer Job Locations US-MD-Annapolis Junction Requisition ID 2025-161988 Position Category... ...Advisor implements, tests, and operates advanced software security techniques in compliance with technical reference architecture...SeniorContract workShift work$146k - $234k
...Cyber Software Engineer, Senior Advisor Job Locations US-MD-Annapolis Junction Requisition ID 2025-162162 Position... ...Proficiency with Java development is required. ~ Security Clearance: Active TS/SCI clearance with polygraph is required...SeniorContract workShift work$168k - $240k
...Best Places to Work 2019, runner-up in 2020, and a finalist in 2021! Belay Technologies is seeking a Sr. Information System Security Engineer (ISSE) with a solid understanding of security practices and policies as well as hands-on vulnerability testing experience. The...SeniorContract workWork experience placementFlexible hours$149.6k - $254.32k
...Senior ISSE/Lead Penetration Tester Break the System to Build a Stronger One Join BAE... ..., where your skills in offensive security protect the world's most critical infrastructure... ...you. As part of a team of Security Engineers you will develop and lead Security Testing...SeniorFull timeLocal area$180k
...ISSE/Penetration Tester, Senior Job ID WOOD-0197 # Positions 1... ...26 7:44 PM) Category Systems Engineering Overview Senior ISSE/Penetration... ...are seeking a Senior Information Systems Security Engineer (ISSE) / Penetration Tester to...SeniorFull timeRemote workFlexible hoursShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Security Engineer. Be the first to apply!
Related searches
- senior cloud security engineer Columbia, MD
- senior application security engineer Columbia, MD
- sr information security engineer Columbia, MD
- senior security operations engineer Columbia, MD
- IT security engineer Columbia, MD
- information technology security engineer Columbia, MD
- sr security engineer Columbia, MD
- aws cloud security engineer Columbia, MD
- network security engineer Columbia, MD
- security engineer Columbia, MD

