Core One
Security Engineer
McLean, VA · Staff+
No sponsorship$53k-$800kDetected 49 days ago
TypeScriptAWSAzureCloud PlatformsCI/CDCybersecuritySOC OperationsIncident ResponseZero TrustMentoringCompTIA
About the role
- Core One is a team-oriented, dynamic, and growing company that values exceptional performance!
- The Senior Security Engineer serves as the primary cybersecurity technical authority supporting system engineering, cloud architecture, DevSecOps pipelines, compliance initiatives, and operational security monitoring.
Responsibilities
- Lead and support FedRAMP Moderate/High and IC ATO authorization efforts, ensuring compliance with NIST RMF, NIST 800-53, NIST 800-37, FedRAMP, and ICD 503 requirements.
- Manage the full Risk Management Framework (RMF) lifecycle, including system categorization, control selection, implementation, assessment, authorization, and continuous monitoring.
- Develop and maintain security documentation such as SSPs, SARs, POA&Ms, and control traceability artifacts, while tracking remediation activities.
- Lead vulnerability management activities using tools such as Nessus, ACAS, SCAP, and STIG Viewer, validating remediation and coordinating risk mitigation efforts.
- Support Security Operations and Incident Response, including threat monitoring, alert analysis, incident investigations, root cause analysis, and coordination with SOCs and government stakeholders.
- Design and assess security controls for AWS GovCloud, Azure Government, and other government cloud environments, implementing IAM, encryption, logging, and least-privilege access controls.
- Support audits and assessments, including 3PAO reviews, FedRAMP assessments, agency ATO reviews, and IG audits, while preparing evidence and coordinating with auditors and assessors.
- Collaborate with developers, engineers, cloud architects, ISSOs/ISSMs, compliance teams, and government stakeholders to provide cybersecurity guidance throughout system development and operations.
Requirements
- Bachelor's degree or higher in Cybersecurity, IT, or related field and 5+ years' experience in Cybersecurity in federal or IC environments
- OR Masters and 3+ years of experience in Cybersecurity in federal or IC environments
- Strong Knowledge of NIST RMF (800-37), NIST 800-53 controls, and FedRAMP requirements
- Experience in the following tools: NIST 800-53, RMF, FedRAMP, ICD 503, ServiceNow GRC, Splunk, AWS GovCloud, Azure
Skills
- Experience with cloud-native security tools
- Knowledge of Zero Trust Architecture
- Experience with cross-domain solutions
- Familiarity with DevSecOps pipelines in regulated environments
- CISM or CISA, CompTIA Security+ (baseline), Certified Authorization Professional (CAP), CCSP (cloud security)
Compensation
- We offer a competitive total compensation package that sets us apart from our competition.
Apply directly at Core One →Create a free account for alerts like thisView Core One immigration profile
This listing is sourced directly from Core One's careers page and normalized into a canonical job model.