Jobs and Careers
VA

Security Compliance Engineer

Valiant Solutions
Remote / Telework, United States, United StatesRemotefull_timeVerifiedPosted 4 Jan 2025
💰 $164,000/yr($150,000/yr$164,000/yr)

About the role

Position Description

Valiant Solutions is seeking a Security Compliance Engineer to join our rapidly growing and innovative cybersecurity team!

 

Valiant Solutions is looking for a self-motivated Security Compliance Engineer to join our Security Engineering division.  The selected candidate will play a key role providing guidance to our client for multiple FISMA systems. This role involves the use of a mixture of technical and compliance skills, supporting system security from design inception through to system decommission. You’ll have the opportunity to provide security guidance on system architectures, review and improve documentation, and identify risk and develop remediation plans. Your role will directly support business efficiency by working to make security as seamless as possible.

 

The selected candidate must have current knowledge and skills in the most current cloud security technologies including but not limited to AWS, GCP, and Azure.  Have expert knowledge of security best practices and engineering principles such as virtualization security, web application security, network architecture, container technology, CICD pipeline, logging tools, hardening best practices, encryption, FIPS validation, vulnerability management,configuration management, and multi-factor authentication.

 

The selected candidate must stay abreast of threats, vulnerabilities, and emerging issues that stand to impact Federal information systems.  In addition, the candidate must understand the governing laws, regulations, methodologies and/or policies to provide authoritative technical guidance on all issues related to the assigned program.

 

Named one of the Best Places to Work in the Washington DC area for TEN consecutive years!  If you are interested in learning more about Valiant and this opportunity, we invite you to apply now! 

 

This position allows for 100% remote work. Remote work necessitates a high-level trust in our employees and we strictly adhere to the details found below in our Remote Work Policy. 

 

Required Experience

  • 5+ years of experience in the IT security field
  • Bachelor's degree in Computer Science, Information Systems, Mathematics, Engineering, or related degree or an additional three (3) years of relevant experience
  • 4+ years experience supporting A&A (NIST 800-53) and compliance activities
  • 4+  years of hands-on technical experience as a System Architect or Security Engineer
  • Direct experience with NIST 171 is preferred
  • Experience in reviewing 3rd party security assessment reports
  • Experience in cloud security technologies including but not limited to AWS, GCP, and Azure
  • Have detailed knowledge and experience with  NIST Policies, Governance, Security Planning and Architecture, FISMA Compliance, RMF, Incident Analysis, and General Security Best Practices
  • Possess strong written and oral communication skills to support customers, internal stakeholders, peers, and public audiences
  • Ability to communicate, both written and orally, to both technical and non-technical stakeholders                  
  • Technical expertise with Nessus Tenable Security and NetSparker reports
  • Strong communication skills to interact with senior managers, junior staff, and business unit (non-technical) customers
  • Certifications: Security+, CISSP, CISM, CISA, or equivalent Security certifications are strongly preferred

 

Responsibilities:

  • Provide security guidance for systems during the design and development of systems so the system achieves an ATO
  • Develop and improve security compliance and privacy documentation in support of system ATOs and their maintenance during on-going authorization
  • Collaborate with multiple security and infrastructure teams on the integration of security tooling and mechanisms
  • Perform detailed architecture and technical design reviews on the full stack for vendor solutions (example of some areas requiring detailed analysis):
  • Assess and document encryption standards for encryption at rest and in transit (what cipher sets are used? What type of encryption? etc)
  • Assess and document authentication mechanisms for all points in the system (Is MFA implemented at all authentication points? Is the MFA solution approved and compliant with NIST and agency standards?)
  • Assess and document session management and control for all layers of the system
  • Schedule and lead screen sharing sessions with the vendors to gain full understanding of the technology stack, document all security relevant information required for the architecture review, and create a full report for present

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Valiant Solutions

View company profile →