Core One

Core One

Security Engineer

McLean, VA · Staff+

No sponsorship$53k-$800kDetected 49 days ago
TypeScriptAWSAzureCloud PlatformsCI/CDCybersecuritySOC OperationsIncident ResponseZero TrustMentoringCompTIA

About the role

  • Core One is a team-oriented, dynamic, and growing company that values exceptional performance!
  • The Senior Security Engineer serves as the primary cybersecurity technical authority supporting system engineering, cloud architecture, DevSecOps pipelines, compliance initiatives, and operational security monitoring.

Responsibilities

  • Lead and support FedRAMP Moderate/High and IC ATO authorization efforts, ensuring compliance with NIST RMF, NIST 800-53, NIST 800-37, FedRAMP, and ICD 503 requirements.
  • Manage the full Risk Management Framework (RMF) lifecycle, including system categorization, control selection, implementation, assessment, authorization, and continuous monitoring.
  • Develop and maintain security documentation such as SSPs, SARs, POA&Ms, and control traceability artifacts, while tracking remediation activities.
  • Lead vulnerability management activities using tools such as Nessus, ACAS, SCAP, and STIG Viewer, validating remediation and coordinating risk mitigation efforts.
  • Support Security Operations and Incident Response, including threat monitoring, alert analysis, incident investigations, root cause analysis, and coordination with SOCs and government stakeholders.
  • Design and assess security controls for AWS GovCloud, Azure Government, and other government cloud environments, implementing IAM, encryption, logging, and least-privilege access controls.
  • Support audits and assessments, including 3PAO reviews, FedRAMP assessments, agency ATO reviews, and IG audits, while preparing evidence and coordinating with auditors and assessors.
  • Collaborate with developers, engineers, cloud architects, ISSOs/ISSMs, compliance teams, and government stakeholders to provide cybersecurity guidance throughout system development and operations.

Requirements

  • Bachelor's degree or higher in Cybersecurity, IT, or related field and 5+ years' experience in Cybersecurity in federal or IC environments
  • OR Masters and 3+ years of experience in Cybersecurity in federal or IC environments
  • Strong Knowledge of NIST RMF (800-37), NIST 800-53 controls, and FedRAMP requirements
  • Experience in the following tools: NIST 800-53, RMF, FedRAMP, ICD 503, ServiceNow GRC, Splunk, AWS GovCloud, Azure

Skills

  • Experience with cloud-native security tools
  • Knowledge of Zero Trust Architecture
  • Experience with cross-domain solutions
  • Familiarity with DevSecOps pipelines in regulated environments
  • CISM or CISA, CompTIA Security+ (baseline), Certified Authorization Professional (CAP), CCSP (cloud security)

Compensation

  • We offer a competitive total compensation package that sets us apart from our competition.

This listing is sourced directly from Core One's careers page and normalized into a canonical job model.