Назад
Company hidden
5 дней назад

Sr Systems Security Engineer

143 487 - 197 294$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Sr Systems Security Engineer (Cybersecurity/RMF): Leading end-to-end cybersecurity posture, compliance governance, and system accreditation for classified defense information systems with an accent on vulnerability management, Splunk monitoring, DISA STIG hardening, and RMF/ATO ownership. Focus on developing security authorization packages, briefing government stakeholders, managing ISSO teams, and maintaining compliance with DCSA, DoD, and Intelligence Community requirements.

Location: Lone Tree, Colorado, United States; office or hybrid environment

Estimated starting salary: $143,487.14–$197,294.82 per year

Company

hirify.global develops aerospace, aviation, ISR, and national security systems, including C4ISR solutions and related integration, testing, certification, training, and logistics support.

What you will do

  • Own the cybersecurity posture, compliance governance, and system accreditation of information systems in a complex defense program.
  • Execute vulnerability scanning, SIEM operations, STIG hardening, configuration management, system monitoring, and incident response.
  • Lead the RMF and ATO lifecycle, including SSPs, SARs, POA&Ms, assessment evidence, and authorization decisions.
  • Develop security policies and procedures and manage compliance with NIST, DCSA, DoD, IC, CMMC, and PPSM requirements.
  • Train and mentor ISSOs and ISSEs and coordinate with government stakeholders, DCSA representatives, and Authorizing Officials.
  • Brief program security posture at government security reviews, authorization review boards, and Authorizing Official-level meetings.

Requirements

  • Bachelor’s degree in systems security, network engineering, information technology, or a related engineering discipline, or equivalent experience.
  • At least 8 years of IT security experience, including at least 8 years in a formal ISSM role with ATO ownership and government Authorizing Official interface responsibility.
  • Hands-on experience with Tenable/Nessus, Splunk SIEM, DISA STIGs and SRGs, ELK Stack, RHEL/Linux, VMware, Bash, PKI, and certificate management.
  • Deep working knowledge of NIST 800-53 Rev. 5, RMF/ATO processes, DCSA DAAPM, CMMC Level 2/3, TEMPEST requirements, and PPSM documentation.
  • Current, active Top Secret U.S. security clearance with SCI eligibility is required.
  • U.S. citizenship is required for employment. The role includes extended computer work, on-call incident response, occasional lifting up to 25 pounds, and occasional travel.

Nice to have

  • CISSP, CISM, CASP+, IAM Level III/IAT Level III, GitLab or GitHub, or RHCSA certification.
  • Experience with enterprise Tenable Security Center, cross-domain solutions, data transfer guards, Zero Trust architecture, and classified multi-domain environments.
  • Experience managing multidisciplinary RMF teams and conducting assessments under DoDI 8510.01, NIST SP 800-53A, and CNSSI 1253.
  • Knowledge of PMI/PMP practices and JIRA-based Earned Value task tracking.

Culture & Benefits

  • Hybrid and office-based work environment with an on-call incident response rotation.
  • Medical, dental, and vision insurance.
  • 401(k) with a 150% match up to 6%.
  • Life insurance, three weeks of paid time off, and tuition reimbursement.
  • Annual performance-based incentive pay.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →