Staff Security Engineer - Vulnerability Management US Public Sector (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Staff Security Engineer (Cybersecurity): Designing and operating asset and vulnerability management infrastructure for the US Public Sector with an accent on cloud-based deployments in AWS and regulatory compliance. Focus on reducing threats to infrastructure, automating scanning and reporting tasks, and ensuring adherence to NIST and FedRAMP standards.
Location: Washington, DC. Must be a U.S. Person (U.S. Citizen, National, Lawful Permanent Resident, Refugee, or Asylee) to access federal environments.
Salary: $161,000 — $270,000 USD
Company
is a leading Identity-as-a-Service provider securing digital identities across AI and human interfaces.
What you will do
- Own the full lifecycle operations of Asset and Vulnerability Management scanning and reporting infrastructure.
- Design new cloud-based and on-prem deployments and assess new scan technologies for business value.
- Monitor and respond to security incidents, communicating real vulnerability impact within the infrastructure context.
- Define and execute internal processes for accelerated remediation of critical vulnerabilities and zero-days.
- Support audit and compliance teams in reporting for PCI, ISO 27001, NIST SP 800-53, and SOC 2.
- Manage POAMs (Plan of Action & Milestones) and Continuous Monitoring processes for the Public Sector.
Requirements
- U.S. Person status is strictly required upon hire.
- 5+ years of multifaceted cybersecurity experience in a technology-centric company.
- 5+ years of experience building vulnerability scanning solutions in highly regulated environments such as FedRAMP.
- Proficiency in AWS core services (S3, DynamoDB, API Gateway) and serverless computing (Lambda).
- Strong scripting and automation skills using Python and Shell.
- Bachelor's degree in Computer Science, Computer Engineering, or equivalent experience.
Nice to have
- Experience with Qualys, TenableSC, Prisma Cloud, Wiz, Orca, Lacework, Jira, or ServiceNow.
- Familiarity with industry frameworks including CVE, CVSS, EPSS, OWASP, and CISA KEV catalog.
Culture & Benefits
- Comprehensive health, dental, and vision insurance.
- 401(k) and flexible spending accounts.
- Paid time off, including PTO and parental leave.
- Immersive in-person onboarding experience to accelerate impact and team connection.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →