
Information Assurance and Security Engineer
Posted Sep 10

Posted Sep 10
This is a fully remote position, open to applicants in United States.
• Act as the Information System Security Officer (ISSO) for a cloud-hosted system based on Azure.
• Deliver technical and programmatic information assurance support to both internal and external clients regarding network and information security systems.
• Create, develop, and implement security requirements across enterprise-level and program-level business processes.
• Generate documentation and security artifacts based on client input and industry-standard guidelines, including NIST RMF and DHS 4300A.
• Lead the certification and accreditation processes for the program.
• Develop and sustain security test and evaluation plans, as well as contingency plans.
• Conduct risk and vulnerability assessments and prepare formal reports along with recommendations.
• Assess policies and procedures for compliance with federal laws, regulations, and standards; suggest remediation strategies.
• Propose system enhancements to rectify deficiencies and strengthen the security posture.
• Design, test, and integrate tools for computer and network security.
• Secure system configurations and ensure compliant deployments.
• Conduct system scans, interpret results, and assist system administrators in addressing findings.
• Perform internal security program audits and formulate mitigation strategies.
• Provide technical expertise for secure architecture design that supports evolving mission requirements.
• Assist in security incident investigations, root-cause analysis, and response actions.
• Carry out vulnerability assessments and develop, document, and monitor corrective action plans.
• Bachelor's degree with 8 years of experience, or a Master's degree with 6 years of experience, or an Associate's degree with 10 years of experience, or a High School diploma/equivalent with 12 years of experience.
• Must be a U.S. Citizen.
• Ability to obtain and maintain a DHS Public Trust clearance.
• Proven experience performing ISSO duties in a federal or regulated environment.
• Experience in creating and maintaining RMF documentation, SSPs, POA&Ms, security test plans, and continuous monitoring artifacts.
• Experience in supporting software development teams that deliver Azure-based cloud solutions.
• Familiarity with Azure AD, App Services, Key Vault, App Gateway/WAF, and cloud-native security controls.
• Practical experience in identifying, tracking, and managing security vulnerabilities.
• Experience interpreting scan results from tools like Tenable/Nessus and Microsoft Defender.
• Experience collaborating with engineering teams on mitigation strategies.
• Strong understanding of NIST 800-53, 800-30, 800-37, and 800-171 frameworks.
• Active CISSP certification, or the ability to obtain it within 6 months of hire.
• Excellent communication skills, including the ability to develop briefing materials, present technical concepts to non-technical stakeholders, and support customer engagements.
• Preferred: Working knowledge of DHS security policies, controls, and compliance requirements, including DHS 4300A/B, the DHS 4300A Sensitive System Handbook, and associated RMF processes.
• Preferred: Familiarity with Azure security architecture patterns such as Zero Trust, RBAC, network segmentation, PIM/PIM, and least-privilege design.
• Preferred: Strong understanding of Agile methodologies and collaboration within cross-functional Agile teams.
• Preferred: Experience with security automation and DevSecOps workflows, including GitHub Actions, Azure DevOps pipelines, and IaC security scanning.
• Preferred: Experience implementing Continuous Monitoring plans, dashboards, and automated control reporting.
• Preferred: Additional security certifications such as ISC2 CAP, ISC2 CCSP, CompTIA Security+, or Azure Security Engineer Associate (AZ-500).
• Employees may qualify for overtime pay.
• Employees may qualify for shift differentials.
• Employees may be eligible for discretionary bonuses.
• Equal opportunity employer, including individuals with disabilities and protected veterans, or other characteristics protected by law.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.