Security Engineer
Koniag Services, Inc.
Koniag Data Solutions, a Koniag Government Services company, is seeking an experienced Security Engineer to support enterprise cybersecurity operations and IT administrative and operational support services for a federal government client. This position requires an active security clearance or the ability to obtain and maintain a government background investigation and all requisite IT access authorizations prior to performing work. Specific clearance requirements will be confirmed at time of offer. Primary work will be performed at the client site in Washington DC and approved remote/telework locations.
We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.
This role serves as a critical technical function responsible for the design, implementation, administration, and continuous improvement of enterprise security controls, security architecture, and cybersecurity capabilities across a complex, geographically distributed federal IT environment spanning on‑premises infrastructure, cloud platforms, and enterprise applications.
The ideal candidate is a technically proficient and security‑focused engineer with deep expertise in enterprise security architecture, security control implementation, vulnerability management, identity and access management, network security, cloud security, and Federal cybersecurity compliance frameworks. This individual must possess the technical depth, analytical rigor, and operational discipline required to design and sustain robust, defensible security capabilities that protect Government data, systems, and mission operations in a highly regulated federal IT environment.
The Security Engineer will serve as a key technical contributor responsible for the design, implementation, administration, and continuous improvement of enterprise security controls, security architectures, and cybersecurity capabilities across the full program environment. This individual works closely with infrastructure engineers, network engineers, cloud operations teams, application developers, DevSecOps engineers, cybersecurity leadership, and Government stakeholders to ensure that security is embedded throughout all layers of the enterprise IT environment—from endpoint and network through application, cloud, and identity—enabling the Government to maintain a strong, measurable, and continuously improving security posture in alignment with Federal cybersecurity frameworks and Zero Trust Architecture principles.
Principal responsibilities will include but are not limited to:
Security Architecture & Engineering
- Design, implement, and maintain enterprise security architectures and security control frameworks across on‑premises, cloud, and hybrid IT environments, ensuring alignment with NIST SP 800‑53, NIST SP 800‑207 Zero Trust Architecture, applicable DISA STIGs, CIS Benchmarks, and client‑specific security requirements.
- Conduct security architecture reviews for new and existing systems, applications, and infrastructure changes, identifying security risks, recommending compensating controls, and ensuring security requirements are addressed prior to deployment.
- Develop and maintain security architecture documentation, including security architecture diagrams, data flow diagrams, network security diagrams, and security control implementation narratives, ensuring documentation is current and accurately reflects the operational environment.
- Support the design and implementation of Zero Trust Architecture principles across the enterprise environment, including micro‑segmentation, identity‑based access controls, continuous validation, least‑privilege enforcement, and encrypted communications.
- Provide expert security engineering guidance to infrastructure engineers, cloud operations teams, application developers, and DevSecOps engineers, ensuring security requirements are accurately translated into technical implementations across all program workstreams.
- Evaluate emerging security technologies, tools, and capabilities, providing recommendations to program leadership and Government stakeholders on opportunities to enhance the enterprise security posture.
Security Control Implementation & Administration
- Implement, configure, and maintain enterprise security controls across endpoint, network, application, cloud, and identity layers, ensuring controls are properly configured, continuously monitored, and aligned with applicable security baselines and compliance requirements.
- Administer and maintain enterprise security platforms and tools, including Security Information and Event Management (SIEM) systems, Endpoint Detection and Response (EDR) platforms, Data Loss Prevention (DLP) tools, Privileged Access Management (PAM) solutions, Web Application Firewalls (WAF), and network security monitoring platforms.
- Implement and maintain endpoint security controls, including EDR configuration and tuning, application whitelisting, host‑based intrusion detection, and endpoint hardening in accordance with applicable DISA STIGs and CIS Benchmarks.
- Implement and maintain network security controls, including firewall rule management, intrusion detection and prevention system (IDS/IPS) configuration and tuning, network segmentation, and network access control (NAC) policies.
- Implement and maintain cloud security controls across AWS (commercial and GovCloud) and Microsoft Azure Government environments, including identity and access management (IAM), network security groups, encryption at rest and in transit, security logging and monitoring, and cloud security posture management (CSPM) capabilities.
- Implement and maintain identity and access management security controls, including multi‑factor authentication (MFA), privileged access management (PAM), role‑based access control (RBAC), and identity federation configurations, in coordination with the Microsoft infrastructure and cloud operations teams.
- Develop and maintain security baseline configurations and hardening standards for all major platform types, including Windows Server, Linux, network devices, cloud workloads, and enterprise applications, ensuring baselines are current and consistently applied across the environment.
Vulnerability Management
- Own and manage the enterprise vulnerability management program, ensuring vulnerabilities are continuously identified, accurately assessed, prioritized, tracked, and remediated in accordance with defined timelines and risk‑based prioritization criteria.
- Conduct and oversee regular vulnerability scanning activities across all in‑scope systems, applications, and cloud environments using industry‑standard scanning platforms, ensuring scan coverage is comprehensive and scan results are accurate and current.
- Analyze vulnerability scan results, applying contextual risk assessment to prioritize remediation activities based on exploitability, asset criticality, exposure, and potential business impact.
- Develop and maintain the vulnerability remediation tracking register, ensuring all open vulnerabilities are assigned, tracked to resolution, and reported accurately in program status reports and compliance documentation.
- Coordinate with infrastructure engineers, cloud operations teams, application developers, and system administrators to ensure timely and effective vulnerability remediation, providing technical guidance and remediation recommendations as needed.
- Develop and maintain vulnerability management reporting capabilities, producing regular vulnerability status reports and trend analyses for program leadership and Government stakeholders.
- Support penetration testing activities, including scoping, coordination, and remediation tracking for findings identified during authorized penetration tests and red team exercises.
Security Monitoring & Incident Response Support
- Support the configuration, tuning, and maintenance of the enterprise SIEM platform, developing and refining detection rules, correlation queries, dashboards and alerting configurations to improve threat detection coverage and reduce false positive rates.
- Monitor security event feeds and SIEM alerts, triaging security events and escalating confirmed or suspected security incidents to the incident response team in accordance with defined escalation procedures and SLA requirements.
- Develop and maintain security monitoring use cases and detection logic aligned with the MITRE ATT&CK framework, ensuring detection coverage is continuously improved as the threat landscape evolves.
- Support cybersecurity incident response activities, providing security engineering expertise to containment, eradication, and recovery efforts, and implementing security control improvements to prevent recurrence.
- Conduct threat hunting activities, proactively searching for indicators of compromise, adversarial TTPs, and undetected threats within the enterprise environment using available log sources, endpoint telemetry, and threat intelligence.
- Support digital forensics activities as needed, providing security engineering context and technical analysis to support forensic investigation efforts.
- Support Authority to Operate (ATO) activities, including the implementation, documentation, and continuous monitoring of required NIST SP 800‑53 security controls, system security plan (SSP) development and maintenance, security assessment support, and plan of action and milestones (POA&M) management.
- Develop and maintain security assessment and authorization documentation, including system security plans, security control implementation statements, risk assessment reports, and continuous monitoring plans.
- Manage the program's POA&M, ensuring all identified security weaknesses are accurately documented, assigned, tracked, and remediated in accordance with defined timelines and risk acceptance decisions.
- Conduct continuous monitoring activities, including regular security control assessments, configuration compliance scanning, and security posture reporting, ensuring the Government maintains current and accurate visibility into the security state of all in‑scope systems.
- Support compliance with applicable Federal cybersecurity frameworks and requirements, including FISMA, NIST SP 800‑53, FedRAMP, HSPD‑12/FIPS 201, NIST SP 800‑207 Zero Trust Architecture, OMB M‑22‑09, applicable DISA STIGs, and client‑specific cybersecurity policies.
- Support supply chain risk management (SCRM) activities, ensuring third‑party software components, cloud services, and vendor technologies are assessed for supply chain risk in accordance with applicable Federal requirements.
- Ensure all security engineering activities involving personally identifiable information (PII), CUI, or other sensitive data categories are conducted in accordance with applicable privacy protection requirements and data handling restrictions.
Security Automation & Tooling
- Develop and maintain security automation scripts, playbooks, and tooling to improve the efficiency, consistency, and effectiveness of security operations activities, including vulnerability scanning, compliance checking, alert triage, and incident response.
- Integrate security tools and capabilities with SIEM, SOAR, ITSM, and DevSecOps pipeline platforms to enable automated detection, alerting, ticketing, and response workflows.
- Develop and maintain security metrics collection and reporting automation, ensuring program leadership and Government stakeholders receive accurate, timely, and actionable security posture data.
- Evaluate and recommend security automation opportunities, identifying manual security processes that can be improved through scripting, orchestration, or tool integration.
Documentation, Reporting & Knowledge Sharing
- Develop and maintain comprehensive security engineering documentation, including security architecture diagrams, security control implementation guides, hardening standards, operational runbooks, and standard operating procedures.
- Prepare and present security status reports, vulnerability trend analyses, and security posture briefings for program leadership and Government stakeholders, communicating complex security information clearly and actionably.
- Contribute security findings, indicators of compromise, and threat intelligence to the program's knowledge management repository, supporting broader detection, prevention, and response capabilities.
- Provide technical guidance and mentorship to program personnel on security engineering practices, tools, and Federal compliance requirements.
- Support the development and delivery of security awareness training materials for program personnel and Government stakeholders as directed.
Education and Experience:
Required:
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related field from an accredited college or university. Equivalent combination of education and directly relevant experience may be considered.
- Minimum of 5 years of hands‑on experience in security engineering, cybersecurity operations, or a closely related discipline within a federal government IT contracting or enterprise security environment.
- Demonstrated hands‑on experience implementing and administering enterprise security controls across endpoint, network, application, and cloud environments.
- Experience supporting ATO activities, including NIST SP 800‑53 security control implementation, SSP development, POA&M management, and continuous monitoring.
- Experience with enterprise vulnerability management, including vulnerability scanning, risk‑based prioritization, remediation tracking, and reporting.
- Active security clearance or the ability to obtain and maintain a government background investigation and all requisite IT access authorizations. Specific clearance requirements will be confirmed at time of offer.
Preferred:
- Prior experience serving as a Security Engineer on a federal IT O&M program of comparable scale and complexity.
- Experience supporting FedRAMP authorization activities and implementing cloud security controls within AWS GovCloud and/or Microsoft Azure Government environments.
- Experience with Zero Trust Architecture implementation within a federal enterprise IT environment.
Required Skills and Competencies:
- Exceptional technical problem‑solving skills with demonstrated ability to design, implement, and maintain robust, defensible security architectures and security controls across complex, multi‑platform federal IT environments.
- Deep knowledge of Federal cybersecurity frameworks and compliance requirements, including NIST SP 800‑53, FISMA, FedRAMP, HSPD‑12/FIPS 201, NIST SP 800‑207 Zero Trust Architecture, OMB M‑22‑09, applicable DISA STIGs, and CIS Benchmarks.
- Demonstrated experience administering and tuning enterprise security platforms, including SIEM, EDR, DLP, PAM, WAF, IDS/IPS, and network security monitoring tools.
- Strong proficiency in vulnerability management, including enterprise vulnerability scanning platform administration, risk‑based vulnerability prioritization, and remediation tracking and reporting.
- Experience implementing and maintaining cloud security controls across AWS and/or Microsoft Azure Government environments, including IAM, network security, encryption, logging, and cloud security posture management.
- Knowledge of Zero Trust Architecture principles and demonstrated experience implementing Zero Trust controls, including micro‑segmentation, identity‑based access control, least‑privilege enforcement, and continuous validation.
- Experience supporting ATO activities, including NIST SP 800‑53 security control implementation and documentation, SSP development and maintenance, POA&M management, and continuous monitoring program execution.
- Proficiency with at least one scripting or programming language, including Python, PowerShell, Bash, or equivalent, for security automation, tool integration, and operational scripting.
- Experience developing and maintaining SIEM detection rules, correlation queries, and dashboards aligned with the MITRE ATT&CK framework.
- Strong understanding of identity and access management security principles, including MFA, PAM, RBAC, identity federation, and enterprise directory services (Microsoft Entra ID / Active Directory).
- Excellent written and verbal communication skills with demonstrated ability to develop clear, accurate security documentation and present complex security information to both technical and non‑technical audiences.
- Familiarity with supply chain risk management (SCRM) requirements and practices as applied to third‑party software, cloud services, and vendor technologies in a federal IT context.
Desired Skills and Competencies:
- Certified Information Systems Security Professional (CISSP) or equivalent senior cybersecurity certification.
- GIAC Security Essentials (GSEC), GIAC Certified Enterprise Defender (GCED), GIAC Certified Incident Handler (GCIH), or equivalent GIAC cybersecurity certification.
- CompTIA Security+, CompTIA CySA+, or CompTIA CASP+ certification.
- AWS Certified Security – Specialty or Microsoft Certified: Azure Security Engineer Associate certification, or equivalent cloud security certification.
- Certified Information Security Manager (CISM) or equivalent security management certification.
- Experience with Security Orchestration, Automation, and Response (SOAR) platform development and administration, including playbook development and automated response workflow implementation.
- Experience with penetration testing methodologies and tools, including scoping, execution coordination, and remediation tracking for authorized penetration tests and red team exercises.
- Familiarity with threat intelligence platforms and the practical application of threat intelligence to detection engineering, threat hunting, and security control improvement activities.
- Experience with deception technology platforms, including honeypots and honeytokens, as supplementary detection and early warning capabilities within enterprise security environments.
- Familiarity with privacy engineering principles and the practical application of privacy‑by‑design concepts to security architecture and control implementation activities.
- Experience developing and delivering security awareness training materials for program personnel and Government stakeholders in a federal IT environment.
- Knowledge of enterprise application security principles, including OWASP Top 10, secure coding practices, and web application security testing methodologies.
- Familiarity with Section 508 compliance requirements for security tools, dashboards, and reporting products delivered under federal contracts.
- Experience with FedRAMP continuous monitoring program execution, including automated evidence collection, control assessment scheduling, and monthly reporting requirements.
- MITRE ATT&CK Defender (MAD) certification or demonstrated equivalent expertise applying the MITRE ATT&CK framework to detection engineering, threat hunting, and security architecture activities.
Our Equal Employment Opportunity Policy:
The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.
The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or to apply to a position on our website, please contact Heaven Wood via e‑mail at View email address on click.appcast.io or by calling View phone number on click.appcast.io to request accommodations.
Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of KGS, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution‑oriented business partnerships and a commitment to exceptional service delivery. We ensure long‑term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit
Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88‑352
#J-18808-Ljbffr$237.6k - $297k
...We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and integrity of our products and services. You will conduct in-depth code reviews, implement security best practices, and influence the...SuggestedFull time$300k - $320k
...Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build... ...to build beneficial AI systems. About The Team The Security Engineering team's mission is to safeguard our AI systems and...SuggestedWork at officeVisa sponsorshipFlexible hours- ...Advanced Analytics, Artificial Intelligence/Machine Learning, Cyber Security and Cutting-Edge Technology across the US Government. Be a part... ...! Position Overview The SentinelOne Endpoint Security Engineer is responsible for the administration, management, and...SuggestedMonday to FridayFlexible hours
- ...Job Title: Security Engineer Location: On-site 4 days/week in Herndon or remote options Type: Contract Compensation: Work Model: 1099; 1 year, up to 5 years possible Hours: 40 Security Clearance: Public Trust Tier 2 / MBI Monitor systems for...SuggestedContract workLocal areaRemote work
$145k - $175k
...RiVidium Inc. is seeking a highly qualified Web Developer Security Engineer to support a federal client. This position is contingent upon contract award and funding approval. As such, this job posting is intended to identify qualified candidates for a potential future...SuggestedContract work- ...innovation - empowering our teams to deliver meaningful outcomes in complex, high-security environments. Who We’re Looking For (Position Overview) The Application Security Security Engineer protects mission-critical web applications, application programming...Full timeWorldwide
- Join to apply for the Security Engineer role at Jobright.ai 3 days ago Be among the first 25 applicants Join to apply for the Security Engineer role at Jobright.ai Jobright is an AI-powered career platform that helps job seekers discover the top opportunities in the US....Full timeRemote work
$140k - $170k
Security & Compliance Engineer Join to apply for the Security & Compliance Engineer role at Nominal. About Nominal Nominal is building the software infrastructure powering the world’s most advanced hardware systems—from spacecraft and autonomous vehicles to next‑generation...Permanent employmentH1bVisa sponsorshipWork visa- Join to apply for the Security Engineer role at HireCapital Join to apply for the Security Engineer role at HireCapital Direct message the job poster from HireCapital Technical Recruiter placing talent at innovative and mission-driven organizations Title: Security Engineer...Permanent employmentFull timeWork at officeRemote work
$80k - $130k
...different experience levels. Your work may focus on network defenses, security platforms, system hardening, access controls, or integrating... ...Approximately 1–5 years of relevant experience in security engineering, network or systems engineering with a security focus, or a...Full timeLocal area$115k - $203k
...Senior Security EngineerOverviewCoStar Group is a leading global provider of commercial and residential real estate information, analytics... ...edge in real estate.We are seeking a Senior Security Engineer with experience in Network, SaaS, and AI Security to help evolve...Hourly payFull timeWork at officeWork from homeMonday to Thursday$150.96k - $170.61k
...per year Requirements: We require at least 6 years of network security experience. We are looking for deep hands-on expertise with enterprise... ...someone able to provide technical leadership, mentor other engineers, and drive security engineering initiatives. We require the...Full timeWork at officeRemote workFlexible hours$107.9k - $195.05k
...Description General program information and/or position overview. Leidos is seeking a Senior Security Engineer to serve as the technical lead for day-to-day security activities supporting enterprise and isolated environments. This position will provide technical...Work experience placementLocal areaImmediate start$69.55k - $125.73k
...Description General program information and/or position overview. Leidos is seeking a Junior Security Engineer to support day-to-day security activities across enterprise and isolated environments. This position will provide hands-on support for security operations, vulnerability...Work experience placementLocal areaImmediate start- ...contest us, deterrence is assured, and the free world remains secure. Founded in 2024, Twenty Technologies ( industrializes offensive... ..., and In‑Q‑T el. Role Summary We are seeking IT Security Engineer to join our growing technology engineering team. This is a...Full timeContract workFlexible hours
$110k - $155k
...delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and consistent... ...this role, you will serve as the Information Systems Security Engineer (ISSE) for multiple classified systems operating at SPA's Headquarters...Contract workWork experience placementWork at officeImmediate startFlexible hours$120k - $206k
...Absolute Business Solutions Corp Current job opportunities are posted here as they become available. Information Systems Security Engineer (ISSE) Absolute Business Solutions Corp (ABSC) is not just another technology company. We’re a community of innovators,...Full timeLocal areaImmediate startRemote workFlexible hours$160k - $170k
...Galapagos Federal Systems LLC is looking for an enthusiastic, well-qualified individual to fill the Information Systems Security Engineer position. This role offers the opportunity to work with a diverse and talented group of individuals committed to driving success...Flexible hours- ...We are seeking an Information Systems Security Engineer (ISSE) to design, build, and integrate security into all information systems supporting the program, serving as the hands-on technical expert who translates Intelligence Community security requirements into engineered...Full timeRemote workHome officeRelocation packageFlexible hours
$99k - $225k
...Information System Security Engineer The Opportunity: You will lead cybersecurity engineering efforts across the full system lifecycle for DoD collateral, SAP and SCI environments. This role ensures security requirements are integrated into system architectures,...Full timeContract workPart timeWork at officeLocal areaRemote work- A leading resource firm is looking for a Senior Security Engineer in Bethesda, MD, to implement Zero Trust Architecture for a federal client. The ideal candidate possesses 8+ years in Cybersecurity, including strong expertise in ZTA security engineering. Responsibilities...Contract work
- Sev1Tech LLC is seeking a Trusted Internet Connections (TIC) System Engineer in Arlington, Virginia. This role focuses on designing and maintaining secure network perimeter defenses while emphasizing TIC 3.0 and Zero Trust principles. Responsibilities include implementing...
- Tria Federal is seeking a Senior Network Security Engineer to lead Cisco ISE deployments and migration from ForeScout CounterACT. The role requires strong security policy design, hands-on ISE configuration, and collaboration across security and network teams. On-site work...
$90 - $95 per hour
...Permanent Resident Ability to obtain a Public Trust Clearance is required Summary: Immediate need for a techno-functional Senior Security Engineer to take the lead on an Optimal ZTA (Zero Trust Architecture) implementation and tackle challenges related to cloud security...Permanent employmentContract workImmediate start3 days per week- ...resource. If you are a problem-solving people-person, apply today! Position Overview: We are seeking an experienced Senior Security Engineer to work in Washington DC to join our team supporting an Enterprise Security Operations Center (ESOC) and Computer Security Incident...For contractorsWork at officeLocal area
$175k - $235k
...Staff Security EngineerPrimer exists to make the world a safer place. We do this by providing trusted decision-ready AI to the world's... ...Francisco, Pasadena, CA and Arlington, VA.As a Staff Security Engineer, you will be a valuable member of the IT and Information Security...Contract workRemote workFlexible hours- Booz Allen Hamilton is looking for a Systems Engineer to design and develop systems that support critical national security objectives. You will apply your technical expertise to modernize systems for the Department of War, translating operational needs into clear technical...Remote job
$5,000 per month
...not U.S. citizens are not eligible for this role. Imagine One Technology & Management, Ltd. is seeking four (4) Senior Security Systems Engineers with specific experience working with Submarine-Launched Ballistic Missiles (SLBMs). These positions are contingent upon...Interim role$102.7k - $164.6k
...SUMMARY ***CANDIDATE MUST BE US Citizen (due to contractual/access requirements)*** Highmark Health is seeking a Senior Security Engineer to join our Enterprise Application Security team and play a pivotal role in shaping how security is built into our software...Full timeFor contractorsWork at officeLocal areaShift work$86.8k - $198k
Security Engineer, Senior The Opportunity: Everyone is trying to “harness the cloud”, but not everyone knows how to secure it. As a cloud security architect, you know how to assess and implement requirements that ensure the safety of information systems and protect them...Full timeContract workPart timeLocal areaRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer. Be the first to apply!
- dlp security engineer Washington DC
- application security engineer Washington DC
- principal security engineer Washington DC
- security software engineer Washington DC
- aws cloud security engineer Washington DC
- sr security engineer Washington DC
- endpoint security engineer Washington DC
- security engineer intern Washington DC
- sr information security engineer Washington DC
- security infrastructure engineer Washington DC

