Senior Information Security Engineer

🔥 3 minutes ago

⚔️ Virginia – Remote

infoinfo

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 10%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of ASRC Federal

ASRC Federal

5001 - 10000 employees

Founded 2003

🎖️ Defense

🚀 Aerospace

🏛️ Government

Defense • Aerospace • Government

ASRC Federal is a wholly-owned subsidiary of Arctic Slope Regional Corporation that provides federal government contracting services across space, civilian, defense & intelligence, national security, and health markets. It delivers engineering solutions, digital operations and IT modernization, software, applications & analytics, supply chain management & logistics, infrastructure operations, and professional services to support missions such as NASA space programs, FAA aviation safety/operations, Air Force industrial support, cyber defense, and base/resiliency operations. The company operates a family of businesses whose earnings support ASRC’s more than 14,000 Iñupiaq shareholders and employs roughly 9,000 people.

📋 Description

• Serve as the primary cybersecurity and privacy advisor to System Owners for assigned systems • Lead RMF activities, including development and maintenance of System Security and Privacy Plans (SSPPs), authorization packages, risk documentation, and supporting artifacts • Ensure systems maintain Authorization to Operate (ATO) through assessment support, continuous monitoring, and compliance with NIST RMF, FISMA, and federal security requirements • Assess security risks, validate security controls, and coordinate remediation of vulnerabilities and Plans of Action and Milestones (POA&Ms) • Maintain system inventories, security documentation, contingency plans, configuration management plans, and privacy documentation • Collaborate with ISSMs, System Owners, Security Control Assessors, and technical teams to integrate security throughout the system lifecycle • Monitor system security posture, review vulnerability and compliance scan results, and support continuous authorization initiatives • Provide cybersecurity guidance, develop security policies and procedures, and deliver security awareness training • Support security engineering, certification and accreditation activities, and implementation of security controls across systems • Recommend process improvements and automation opportunities to enhance RMF and cybersecurity operations

🎯 Requirements

• Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, Information Technology, or a related field • Minimum 5–7 years of experience supporting information assurance, cybersecurity, RMF, or information system security, or an equivalent combination of education and experience • Experience supporting federal cybersecurity programs and the NIST Risk Management Framework (RMF) • Experience developing and maintaining RMF documentation, authorization packages, and Governance, Risk and Compliance (GRC) tools • Strong knowledge of NIST SP 800-37, NIST SP 800-53, FISMA, FIPS 199, and federal privacy requirements • Experience supporting Authorization to Operate (ATO), Continuous ATO (cATO), or Continuous Authorization efforts • Strong analytical, communication, documentation, and stakeholder engagement skills • Certified Information Systems Security Professional (CISSP) • Certified in Governance, Risk and Compliance (CGRC) or Certified Cloud Security Professional (CCSP) • Experience supporting U.S. federal civilian agencies, preferably the USPTO • Experience with continuous monitoring, vulnerability management, and security automation • Familiarity with cloud security, DevSecOps, and continuous authorization initiatives • Knowledge of privacy compliance activities, including Privacy Threshold Assessments (PTAs), Privacy Impact Assessments (PIAs), and System of Records Notices (SORNs)

🏖️ Benefits

• Remote work arrangement

Apply Now

Similar Jobs

🔥 4 hours ago

Stripe

1001 - 5000

💳 Fintech

🛍️ eCommerce

🤝 B2B

Security Engineer designing rapid technical controls and automated defenses for Stripe’s financial infrastructure platform. Balancing abuse mitigation with user conversion across payment and identity systems.

🔥 6 hours ago

LinkedIn

10,000+ employees

💼 Consulting

📣 Marketing

📦 Logistics

Senior Incident Response Engineer protecting LinkedIn’s professional network and member data. Leading investigations, threat hunting, incident remediation, and security response improvements.

🔥 6 hours ago

Guild Mortgage

1001 - 5000

🏗️ Construction

💸 Finance

🏠 Real Estate

Third-Party Security Manager strengthening Guild Mortgage’s vendor risk program. Leading assessments, monitoring, remediation, governance, and executive reporting for mortgage operations.

🔥 10 hours ago

Icmarc

-

💼 Consulting

🏥 Healthcare

🛡️ Insurance

Application and AI security engineer securing MissionSquare’s retirement-services software and AI applications. Automating testing, threat modeling, and secure development across multidisciplinary teams.

🔥 10 hours ago

Baylor Genetics

501 - 1000

🏥 Healthcare

💼 Consulting

🍽️ Food & Beverage

Senior Information Security Engineer protecting Baylor Genetics’ clinical genomic and health data. Leading SIEM, vulnerability management, identity security, Zero Trust, and incident response.