安全工程师 需IRS MBI许可
Security Engineer with IRS MBI Clearance
这是一个远程职位
职位名称:安全工程师
地点:远程
工作时间:全职
所需权限:IRS MBI 权限
职位概述:
我们正在寻找一位具备 NIST 800-53 安全控制经验,并在风险和漏洞管理方面有扎实技术背景的安全工程师。理想候选人将在实施安全控制、评估漏洞以及确保符合联邦网络安全框架(如 FISMA、FedRAMP 和 RMF)方面发挥关键作用。
主要职责:
- 开发、评估并记录系统安全计划(SSP)、行动计划与里程碑(POA&Ms)和基于风险的决策(RBD)。
- 与开发人员和技术人员合作,指导每种安全控制族的正确实施。
- 收集、整理并提交安全控制评估(SCA)的证据。
- 具备安全技术方面的专业知识,例如加密方法、身份和访问管理(IAM)概念,以及 SAML、OIDC、SSO 和 MFA 等技术。
- 熟悉 SIEM 技术(如 Splunk)和其他监控工具。
- 通过风险和漏洞管理识别并修复漏洞。
- 跨团队与外部客户合作,制定安全策略、设计解决方案,并在部署过程中提供指导。
所需资格:
- 至少 8 年信息技术领域的工作经验,且责任逐步增加。
- 至少 5 年的信息安全解决方案经验。
- 相关安全认证(如 CISSP、CCSP、CEH)。
- 深入理解 NIST 800-53、RMF、FedRAMP、FISMA 和其他联邦安全标准。
- 了解系统安全漏洞及有效的修复技术。
- 熟悉网络概念,包括子网划分、路由、VPC/VNet、安全组、负载均衡等。
- 具有微服务架构经验,并能为多租户应用设计安全解决方案,使用 Docker 和 Kubernetes 等容器化和编排工具(优先考虑)。
- 具备支持 AWS 云平台安全的实际经验(优先考虑)。
- 候选人必须是美国公民或合法永久居民(绿卡持有者)至少 3 年,并且符合联邦税务规定。
最初发布于 Himalayas
查看英文原文
This is a remote position.
Job Title: Security Engineer
Location: Remote
Duration: Full-Time
Clearance Required: IRS MBI ClearancePosition Overview:
We are offering an exciting opportunity for a Security Engineer with expertise in NIST 800-53 security controls and a strong technical background in risk and vulnerability management. The ideal candidate will play a crucial role in implementing security controls, assessing vulnerabilities, and ensuring compliance with federal cybersecurity frameworks such as FISMA, FedRAMP, and RMF.
Key Responsibilities:
- Develop, assess, and document System Security Plans (SSPs), Plan of Action and Milestones (POA&Ms), and Risk-Based Decisions (RBDs).
- Collaborate with developers and technical staff to guide the proper implementation of each security control family.
- Collect, organize, and submit evidence for Security Control Assessments (SCAs).
- Possess technical expertise in security technologies such as encryption methods, IAM concepts, and technologies like SAML, OIDC, SSO, and MFA.
- Experience with SIEM technologies (e.g., Splunk) and other monitoring tools.
- Identify and remediate vulnerabilities through risk and vulnerability management.
- Work across teams and with external customers to develop security strategies, design solutions, and provide guidance during deployment.
Required Qualifications:
- At least 8 years of experience in the Information Technology field with increasing responsibility.
- A minimum of 5 years of experience in Information Security solutions.
- Relevant security certifications (e.g., CISSP, CCSP, CEH).
- Deep understanding of NIST 800-53, RMF, FedRAMP, FISMA, and other federal security standards.
- Knowledge of system security vulnerabilities and effective remediation techniques.
- Familiarity with networking concepts, including subnetting, routing, VPC / VNet, security groups, load balancing, etc.
- Experience with microservices-based architectures and designing security solutions for multi-tenant applications, using containerization and orchestration tools like Docker and Kubernetes (highly desirable).
- Hands-on experience supporting security for AWS cloud platforms (highly desirable).
- Candidates must be U.S. Citizens or Legal Permanent Residents (Green Card holders) for at least 3 years and be Federal Tax compliant.
Originally posted on Himalayas