Security Engineer
QualityWorks Consulting Group, LLC
QualityWorks Consulting Group
Cybersecurity Engineer
Job Description
Location On-site, U.S. — specific site shared during screening
Type Contract
Duration 3 months
Experience: Mid -level
Department : Technology
About the Role
We're deploying an autonomous software testing platform into a secure government environment spanning AWS GovCloud and on-premise infrastructure, and we need a security engineer inside the accredited boundary to make it real: configure and secure the GovCloud environment, install and configure DoD PKI, harden the stack, verify the security controls actually work, and produce the compliance evidence the government needs to accept it. This role is scoped for execution and verification rather than greenfield security architecture. The trust-model decisions, configuration procedures, and integration patterns are prepared in advance by our engineering team and handed to you as detailed runbooks, pre-validated in a sandbox before you ever open them. Your job is to run them correctly in the real environment, troubleshoot where the environment doesn't match the document, prove the controls hold, and elevate cleanly when something falls outside the documented path. If you're a careful systems or security engineer who executes precisely, documents well, and communicates clearly against a compliance deadline, you don't need a decade of PKI architecture experience to do this job well. We've deliberately built the role so you don't have to.
Security & Eligibility Requirements
These are hard conditions of the work, not preferences:
- U.S. Person status. The work happens inside a government-accredited environment and cannot be performed by a non-U.S. Person or from outside the United States.
- Ability to pass a Public Trust background investigation.
- Willingness to complete DD Form 2875 system access paperwork immediately on offer acceptance.
- Completion of the DoD Cyber Awareness Challenge and site-specific training before access.
- Ability to obtain and maintain a Common Access Card (CAC).
- DoD 8140/8570 IAT Level II certification (Security+ CE or equivalent) — held, or obtainable before access is granted.
- On-site presence for the duration of the setup phase.
On timing: vetting and access provisioning run roughly 30 business days from submission. You won't have system access in your first few weeks — that time goes to paperwork, training, and working through the runbooks before you touch the environment. Candidates need to be comfortable with that ramp.
What You'll Do
AWS and GovCloud environment security
- Configure and secure the GovCloud environment following the provided setup runbook: account structure, IAM roles and policies, VPC and security group configuration
- Implement encryption and key management (KMS), S3 access controls, and secrets handling to the provided specification
- Stand up and validate logging and monitoring — CloudTrail, Config, GuardDuty or equivalent — and confirm the audit trail satisfies the control requirements
- Work within GovCloud partition boundaries and credential separation, and identify where service parity differs from commercial regions
PKI and CAC Authentication
- Install and configure DoD PKI certificates for the platform, following the provided configuration runbook
- Configure CAC/PIV-based authentication and validate it end to end with live credentials
- Verify certificate chains, trust stores, and revocation checking (OCSP/CRL) behave as specified
- Handle certificate lifecycle work in the environment: requests, installation, renewal, replacement
Environment Setup and Hardening
- Execute the provided on-premise and cloud setup procedures inside the accredited boundary
- Apply specified hardening baselines and STIG configurations
- Run compliance and vulnerability scans, interpret the results, remediate findings per the documented guidance
Control Verification and Evidence
- Execute documented test steps demonstrating each required security control is implemented and working
- Capture evidence to our evidence standard — scan output, configuration exports, logs, screenshots — recorded in the master test log
- Package security artifacts in the form the government's compliance reviewers expect
- Track open findings to closure and report status on a set cadence
Client Interface and Escalation
- Act as on-site point of contact for the client's ISSM/ISSO on security configuration questions
- Coordinate site access, change windows, and scan schedules with client stakeholders
- Raise anything outside the documented procedures through our escalation channel, with enough diagnostic detail for remote analysis
- Maintain a daily written handoff so work continues across time zones
- Feed deviations back so the runbooks stay accurate
What This Role Doesn't Own
Stated plainly, because it's the point of the role. These arrive already built:
- Designing the PKI architecture or certificate trust model — you implement the documented design
- Designing the cloud landing zone, network architecture, or platform integration patterns
- Authoring security control narratives or the RMF/ATO package from scratch — you produce the evidence that feeds them
- Writing the configuration runbooks and test procedures
- Platform development and test-automation framework design
You have a dedicated engineering team behind all of it, reachable through a defined escalation channel with agreed response times. You are the only one on-site; you are not the only one on the problem.
What We're Looking For
- 3–6 years in systems engineering, security engineering, or systems administration with a security focus
- Hands-on certificate work: installing, renewing, and troubleshooting X.509/TLS certificates, trust stores, and chain-of-trust problems. Comfort debugging at the openssl s_client level — not CA design
- Direct experience working in AWS GovCloud, including its partition boundaries, credential separation, and service parity differences from commercial regions
- Solid Linux and/or Windows Server administration
- Demonstrated ability to follow a detailed technical procedure exactly, and to notice and document when the environment doesn't match it
- Familiarity with hardening baselines (STIGs, CIS benchmarks, or equivalent) and running or interpreting compliance scans
- Disciplined written communication — evidence capture, status reports, and escalation write-ups someone remote can act on
- U.S. Person status and ability to meet every vetting requirement above
Nice to Have (not required)
- Prior on-site work in a DoD or federal environment; prior CAC holder
- Prior experience with DD-2875 access processes
- AWS Certified Security – Specialty, or Solutions Architect Associate
- Experience in another FedRAMP or IL-accredited environment
- Exposure to AWS GovCloud or another FedRAMP/IL-accredited environment
- Supporting (not owning) role on a previous RMF or ATO effort
- Familiarity with CI/CD, source control, and test management tooling
- Experience working with a distributed team across time zones
What We Offer
- Competitive contract compensation for the 3-month engagement
- Direct backing from a dedicated engineering team, reachable through a defined escalation channel with agreed response times
- Pre-validated runbooks and configuration procedures, so you execute against a proven plan rather than starting from a blank page
- A clearly scoped, well-defined engagement with a set start and end date
- The opportunity to work inside an accredited government environment on a mission-relevant platform
- ...McAfee ConsultantDowney, CA - Remote12+ monthsA Security Engineer serves as the security engineer of complex technology implementations in a product-centric environment; is comfortable with bridging the gap between legacy development or operations teams and working toward...Suggested
- ...Key Responsibilities Serve as the security lead for complex technology implementations within a product-focused environment. Collaborate... ...Education: Bachelor’s degree in Information Technology, Engineering, or a related field. Additional relevant experience may be...Suggested
$209k - $313k
...Senior Security EngineerSnap Inc is a technology company. We believe the camera presents the greatest opportunity to improve the way people... ...privacy at the forefront.We're looking for a Senior Security Engineer to join our Detection and Response (D&R) team!What you'll do:...SuggestedLive inWork at officeLocal area$160k - $215k
...here, and we need builders, innovators and problem solvers to help us create it. Who you are Metropolis is seeking a Senior Security Engineer to establish and lead a dedicated infrastructure and network security engineering function within our Corporate IT and...SuggestedTemporary workWork at officeLocal areaRemote work$178k - $313k
...addition to Bitmoji , Saturn, and other digital services. Snap Security teams protect the trust and safety of our global community by... ...at the forefront. We’re looking for a Senior Security Engineer to join the Infrastructure Security team at Snap Inc! What you...SuggestedFull timeLive inWork at officeLocal area$178k - $313k
...addition to Bitmoji , Saturn, and other digital services. Snap Security teams protect the trust and safety of our global community by... ...with privacy at the forefront. We’re looking for a Security Engineer to join our Offensive Security Team! What you’ll do: ~...Full timeLive inWork at officeLocal area- ...Description Job Description Description: Hybrid 4 Days a week on-site in Burbank, CA Our client has an opportunity for a Security Engineer, Incident Response on an initial 3-month contract with expected extensions. The role will provide additional coverage while...Hourly payFull timeContract workLocal area
$165k - $235k
...actively developing the technologies to make this possible, with the ultimate goal of enabling human life on Mars. SR. NETWORK SECURITY ENGINEER (VPN) SpaceX is looking for a Sr. Network Security Engineer with deep expertise in network security technologies and a...Permanent employmentTemporary workRemote workFlexible hoursWeekend work$130k - $180k
...SpaceX is actively developing the technologies to make this possible, with the ultimate goal of enabling human life on Mars. SECURITY ENGINEER SpaceX is looking for a Security Engineer to join Information Security to help protect and drive the SpaceX mission....Permanent employmentFull timeTemporary workRemote workWeekend work$104.9k - $157.3k
...who currently reside in one of the following approved locations: West Los Angeles, CA. Green Dot Corporation is seeking a Security Engineer to join the Information Security (InfoSec) team. This role will focus on vulnerability management, threat detection, and remediation...Work at officeRemote work3 days per week$113.4k - $162k
...Senior Security EngineerWe're looking for talented professionals to join us in bringing smart money management and payment solutions to... ...Dot Corporation is seeking for an experienced Senior Security Engineer with a strong focus on assessing Security Architecture with hands...Full timeWork at officeRemote work3 days per week$130k - $150k
...We are seeking an experienced Security Engineer to join the Information Security team. This is a hands-on position with significant responsibility and visibility across the organization and will report directly to the Director of Information Security.The IT Security Engineer...$115k - $160k
...spirit and a commitment to absolute integrity. East West Bank gives people the confidence to reach further. Overview The Cyber Security Engineer supports the development and maintenance of a corporate-wide information security program to help protect the organization’s...$150k - $220k
...new era demands a fundamentally different class of spacecraft. Engineered to survive the harshest radiation environments and to fully... ...operations rather than resolving them ticket by ticket Partner with security operations on identity threat detection and response,...Permanent employmentLocal areaShift work$150k - $190k
...new era demands a fundamentally different class of spacecraft. Engineered to survive the harshest radiation environments and to fully... ...automated testing Act as incident commander for corporate security incidents, coordinating stakeholders and delivering timelines,...Permanent employmentRemote workShift work$130k - $195k
...SpaceX is actively developing the technologies to make this possible, with the ultimate goal of enabling human life on Mars. IT SECURITY ENGINEER - TOP SECRET CLEARANCE SpaceX is looking for an IT Security Engineer with deep knowledge and broad experience across...Permanent employmentFull timeTemporary workFlexible hours- ...Job Description Job Description Security Systems Engineer About the Role We are looking for an experienced Security Systems Engineer to join our team to help design, configure, program, commission, and troubleshoot electronic security systems. This is...For contractorsRemote work
- ...Job Description Job Description Screen Engine/ASI — the leading technology innovator in media and entertainment market research, is seeking a Cloud Security Engineer to help secure, monitor, and improve our cloud-first technology environment. Work Arrangement:...Work at officeRemote work
$155k - $180k
...Job Description Job Description Senior Cloud Security Engineer Company Overview A global firm based in Los Angeles, California is seeking a Senior Cloud Security Engineer to strengthen its cybersecurity program across cloud, data, endpoint, identity, and enterprise...Remote work- ...Job Description Job Description Duration: Contract 3 Months Roles and Responsibilities: The member will support the Security Services Department by conducting physical security assessments across utility facilities and critical infrastructure sites ,will have...Contract workLocal area
$10k
...3 days/week. About the role Match Group runs one unified security program across Tinder, Hinge, Match, Meetic, OkCupid, Plenty of... ...posture. Eliminate manual toil and accelerate delivery by engineering automated solutions—using scripting, no-code tools, or AI—to solve...Work experience placementWorldwide3 days per week$209k - $313k
...in addition to Bitmoji, Saturn, and other digital services.Snap Security teams protect the trust and safety of our global community by... ...execute with privacy at the forefront.We’re looking for a Security Engineer to join our Offensive Security Team! What you’ll do:Design,...Full timeLive inWork at officeLocal area- ...Job Description Job Description Exciting Splunk SIEM Security Engineer/Architect contract opportunity. Requirements Requirements ~3 plus years of experience in Spunk (SIEM) Security Enterprise: architecting, configuring, deploying, and customizing the tool,...Contract work
- Senior Cloud Security Engineer Spacecraft represent the most pressing unmet need across the entire aerospace industry. As more launch vehicles come online and the cost to orbit decreases, more companies launching payloads to space continue to emerge. For the first time...Full timeWork at office
- Affirm is seeking a Security Risk Manager to evaluate and refine solutions for third-party risk within the Security Third Party Program... ...scalable workflows. You will partner with Procurement, Legal, Engineering, IT, Compliance, and Privacy to drive risk-informed decisions...
- ...on the forefront of utilizing innovative solutions, with great minds from all backgrounds, to help solve the nation’s most complex security challenges. We strive for an inclusive, collaborative team environment that approaches differences as opportunities for innovation...Full timeWork experience placementLocal areaImmediate startRemote workFlexible hours
$126k - $189k
...Job Description Summary: We are seeking a Development, Security, and Operations "DevSecOps" Engineer to support and scale the organization’s citizen development initiatives. This role works closely with non-traditional developers — analysts, business users, and rapid...Full timeTemporary workWork at officeRemote workFlexible hours- ...Job Description Job Description Exciting Security Analyst / Engineer - Threat & Cortex XSIAM (Hybrid) Requirements ~3 plus years of experience in cyber security or related discipline. ~ SIEM, Cortex XSIAM, correlation, and threat monitoring ~ Understands the...
- ...range is subject to change. Please confirm the starting salary with the hiring department before accepting a job offer . A Cyber Security Analyst plans, coordinates, and guides cybersecurity activities in prevention, governance, risk, and compliance (GRC) as well as audit...
$130k - $195k
...is actively developing the technologies to make this possible, with the ultimate goal of enabling human life on Mars. AI SECURITY SOFTWARE ENGINEER (STARSHIELD) Starshield leverages SpaceX’s Starlink technology and launch capability to support national security...Permanent employmentFull timeTemporary workImmediate startFlexible hoursWeekend work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer. Be the first to apply!
- application security engineer Los Angeles, CA
- aws cloud security engineer Los Angeles, CA
- sr security engineer Los Angeles, CA
- endpoint security engineer Los Angeles, CA
- sr information security engineer Los Angeles, CA
- security engineer Los Angeles, CA
- physical security engineer Los Angeles, CA
- senior security operations engineer Los Angeles, CA
- IT security engineer Los Angeles, CA
- information technology security engineer Los Angeles, CA



