Назад
Company hidden
5 часов назад

Security Engineer - Federal (FieldOps) (AI)

134 000 - 167 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Engineer - Federal (FieldOps) (AI): Building and maintaining release-gate evidence and Continuous Monitoring automation for Federal AI deployments with an accent on FedRAMP compliance, vulnerability management, and hardened container registries. Focus on automating SBOM and POA&M workflows, implementing SCAP/STIG controls, and resolving security requirements across defense and intelligence deployments.

Location: Tysons, Virginia, United States

Salary: $134,000–$167,000 USD

Company

Enterprise AI application software company delivering the C3 Agentic AI Platform, industry-specific SaaS AI applications, and generative AI solutions.

What you will do

  • Own release-gate evidence covering image CVE disposition, allowlists, SCAP/STIG, FIPS validation, and Federal BOM requirements.
  • Build and maintain Continuous Monitoring automation, including SBOM generation, POA&M classification, and live security metrics feeds.
  • Act as the engineering interface for FedRAMP boundary-register items, including image provenance, patch uplift, and SCAP scope.
  • Address Federal customer security requirements while preserving the standard solution security posture.
  • Manage hardened container registries such as Iron Bank and Chainguard for Federal deployments.
  • Triage and remediate vulnerabilities in Federal systems and applications in collaboration with Information Security, Product, Engineering, Operations, and Compliance.

Requirements

  • Bachelor’s degree in Computer Science, Information Security, or a related field.
  • At least 5 years of experience in information security, DevSecOps, or a related field.
  • Experience with vulnerability management, CVEs, IOCs, Linux, and scripting with JavaScript, Shell, or Python.
  • Hands-on experience with SCAP/OpenSCAP tooling and automated STIG scanning and remediation.
  • Active DoD 8570 IAT II or higher certification, such as CISSP or Security+, or the ability to obtain it.
  • Must be authorized to work in the United States without current or future company sponsorship; US citizenship or permanent residence is required. Active Secret or higher security clearance is preferred.

Nice to have

  • Cloud security and experience securing cloud-based applications.
  • Knowledge of NIST 800-53, CMMC, and FedRAMP requirements.
  • Experience with security automation and orchestration tools.
  • Experience with hardened container registries, FIPS 140-2/3 validation, and SBOM generation and traceability tooling.

Culture & Benefits

  • Competitive compensation package.
  • Generous equity plan.
  • Employee benefits package.
  • Work supporting high-visibility defense and intelligence projects with stringent security requirements.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →