Назад
Company hidden
10 дней назад

Lead Security Engineer (AI)

Формат работы
onsite
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Lead Security Engineer (AI): Designing and leading cybersecurity engineering for a secure, on-premises Federal data, analytics, and AI platform with an accent on FISMA Moderate, NIST SP 800-53, RMF, and DevSecOps controls. Focus on implementing identity, encryption, logging, vulnerability, and continuous-monitoring safeguards while securing Kubernetes-based infrastructure, APIs, CI/CD pipelines, and AI/ML workloads.

Location: Bethesda, MD, United States. The role supports a secure, on-premises Federal platform within a Government-approved security boundary.

Company

hirify.global is a public-sector consulting and information technology solutions provider supporting health, civilian, and national security missions.

What you will do

  • Design, implement, and lead cybersecurity engineering across platform architecture, infrastructure, applications, data, APIs, DevSecOps pipelines, and AI services.
  • Translate FISMA Moderate and NIST SP 800-53 Rev. 5 requirements into technical controls, implementation evidence, and assessment-ready documentation.
  • Engineer access control, authentication, authorization, encryption, certificates, secrets, key management, audit logging, and data-protection safeguards.
  • Integrate security scanning, compliance checks, vulnerability management, and remediation into CI/CD pipelines.
  • Support incident response, continuous monitoring, threat modeling, security assessments, audits, POA&Ms, and vulnerability assessments.
  • Coordinate with security, CIO/CISO, platform, infrastructure, application, data, AI/ML, DevOps, and Government stakeholders.

Requirements

  • 8+ years of experience in cybersecurity engineering, security architecture, information assurance, or a related field.
  • Experience designing and implementing security controls for Federal information systems, preferably in FISMA/RMF environments.
  • Strong knowledge of FISMA, NIST SP 800-53 Rev. 5, RMF, secure software development, and DevSecOps.
  • Hands-on experience with Linux, Docker, Kubernetes and/or Rancher, enterprise infrastructure, applications, databases, APIs, networks, and on-premises or hybrid platforms.
  • Experience with IAM, RBAC, privileged access, vulnerability management, SAST/SCA/DAST, container security, secure API design, logging, monitoring, and incident response.
  • U.S. citizenship and ability to obtain and maintain Top Secret eligibility are required; an active Top Secret clearance is highly preferred.

Nice to have

  • Experience with Federal financial management, grants management, payment systems, award oversight, or financial reporting.
  • Experience securing AI/ML or open-source LLM workloads in on-premises, restricted, or disconnected environments.
  • Experience with SIEM, SOAR, EDR, security automation, infrastructure-as-code security, or FedRAMP-authorized environments.
  • Security certifications such as CISSP, Security+, SecurityX/CASP+, CCSP, CISM, or GIAC.

Culture & Benefits

  • Work with multidisciplinary professionals supporting Federal health, civilian, and national security missions.
  • Employer-paid health care.
  • Training and development funds.
  • 401(k) match and opportunities for bonuses.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →