
Principal Security Engineer
Posted Sep 18

Posted Sep 18
This is a fully remote position, open to applicants in United States.
• Offer technical guidance on the implementation of security controls and establish information security protocols for systems and applications.
• Conduct pre-assessment tasks, which involve a thorough evaluation of technology stacks that include vendor solutions.
• Evaluate vendor systems for technical adherence to NIST, FedRAMP, and agency requirements.
• Execute in-depth architecture and technical design assessments across the complete stack for vendor solutions.
• Carry out architecture evaluations of CSP authorization packages to confirm secure design, alignment with FedRAMP and agency standards, identify deficiencies, and provide insights on risk posture and compliance.
• Facilitate and engage in architecture interviews with Cloud Service Providers (CSPs).
• Create architecture briefing documents for the Government FedRAMP program manager and Chief Information Security Officer (CISO).
• Review and provide feedback on CSP FedRAMP documentation, including system security plans, policies, procedures, agency directives, alternative implementations, and risk acceptance documents.
• Collaborate with CSPs to address documentation and technology discrepancies.
• Analyze CSP assessments and package submissions post-3PAO audits and prepare package briefings.
• Review vendor security assessment plans, security assessment reports, vulnerability scans, and penetration testing results.
• Deliver security engineering services in collaboration with the agency FedRAMP Lead.
• Assist in Continuous Monitoring efforts, including annual package submissions, significant change proposals, and risk acceptance documents.
• Interpret FedRAMP and agency mandates and offer guidance to vendors.
• Stay updated on revised FedRAMP directives, industry best practices, emerging technologies, and Government cybersecurity regulations.
• Provide insights on the implications of updated directives and technologies.
• Conduct security evaluations of technologies proposed for use within CSP authorization boundaries.
• Manage relationships related to assigned contractor-owned or contractor-operated systems and ensure adherence to agency security and privacy standards.
• Support stakeholders with IT security tasks to meet project timelines.
• Guarantee that systems are operated, maintained, and disposed of in alignment with established security policies and procedures, including Assessment & Authorization (A&A).
• Investigate assigned IT security systems and offer architecture and security recommendations.
• A minimum of five (5) years of experience in the IT Security domain.
• A Bachelor’s degree in Computer Science, Information Systems, Mathematics, Engineering, or a related discipline, OR an additional three years of IT experience is required.
• Proven experience as a Security Engineer or System Architect conducting analysis on FedRAMP Cloud Service Providers (CSP) architectures and control implementations.
• Four (4) years of practical technical experience as a System Architect or Security Engineer.
• Four (4) years of experience in supporting FedRAMP as an Engineer or Architect.
• Possession of Security+, CISSP, CISM, CISA, or equivalent Security certification.
• Strong confidence and depth of understanding to lead discussions with potential Vendors.
• Current experience in evaluating third-party security assessment reports.
• Comprehensive knowledge and experience with NIST Policies, Governance, Security Planning and Architecture, FISMA Compliance, RMF, Incident Analysis, and General Security Best Practices.
• Excellent written and verbal communication skills.
• Ability to effectively communicate with both technical and non-technical stakeholders.
• Strong interpersonal skills to engage with senior management, junior staff, and business unit customers.
• Must maintain a quiet and distraction-free workspace with sufficient internet connectivity.
• Should dedicate full attention and availability to job responsibilities during working hours.
• Must follow a schedule during core business hours that aligns with coworkers and clients.
• Required to disclose any current or future outside employment engagements and obtain written approval.
• Should not solicit or engage in outside business during Valiant/client core business hours.
• Valiant covers 99% of the Medical, Dental, and Vision Insurance for Full-time Employees.
• Valiant contributes 25% towards Health Coverage for Families and Dependents.
• 100% Paid Short-Term Disability and Life Insurance Policy for Full-time Employees.
• 100% Paid Certifications.
• 401K Matching up to 4%.
• Paid Time Off.
• Paid Federal Holidays.
• Access to Valiant University – Online Education and Training Portal.
• Wellness & Fitness Program.
• FSA programs for: Medical Costs, Dependent Care, Transit, and Parking.
• Referral Bonuses.
• Emphasis on work-life balance.
• Opportunities for career development.
• Support for a quiet and distraction-free workspace for remote work.
• Flexible remote work arrangements.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.