An engineering firm that delivers high-quality Healthcare IT, Cybersecurity, and Telecommunication solutions.
Information Security Officer
Location
United States
Posted
81 days ago
Salary
$112.8K - $140K / year
Job Description
Job Requirements
- Minimum of 8+ years of progressive experience in information security, cybersecurity engineering, or system security roles, with demonstrated technical depth and increasing responsibility.
- A bachelor's degree in computer science, Information Systems, Engineering, Business, or other related scientific or technical discipline.
- Significant hands-on experience supporting large Federal Government security programs, including operation within FISMA-regulated environments and direct alignment with CMS ARS 5.0+ requirements.
- Proven experience owning and maintaining an Authorization to Operate (ATO), including authoring, updating, and defending security artifacts such as System Security Plans (SSPs), Plans of Action & Milestones (POA&Ms), Incident Response Plans, Configuration Management Plans, Privacy Impact Assessments, contingency plans, and related documentation.
- Strong practical knowledge of NIST Risk Management Framework (RMF) and NIST 800-53 Rev. 5, with the ability to translate control requirements into actionable technical and operational security implementations.
- Demonstrated hands-on experience managing vulnerability and compliance scanning programs, including configuration, operation, interpretation of results, and remediation tracking using tools such as Tenable, AWS Security Hub, and Snyk.
- Ability to assess security findings, determine risk severity, prioritize remediation, and drive closure in close collaboration with engineering, infrastructure, and DevSecOps teams.
- Strong hands-on experience securing cloud-based environments, with a focus on AWS (IAM, GuardDuty, CloudTrail, Security Hub) and SaaS platforms.
- Demonstrated ability to embed security into DevSecOps and CI/CD pipelines, including defining security decision gates and integrating automated security testing and continuous monitoring.
- Experience performing Security Impact Analyses (SIAs), access reviews, and least-privilege enforcement across cloud, application, and CI/CD environments.
- Proven ability to configure, operate, and tune security tools, respond to alerts, and maintain dashboards and reporting for visibility into vulnerability, compliance, and overall security posture.
- Experience operating within Agile / SAFe delivery models, participating in sprint planning, PI planning, backlog refinement, and cross-team coordination to ensure security is embedded in delivery.
- Strong written and verbal communication skills, with the ability to clearly articulate security risks, requirements, and remediation strategies to technical teams, leadership, and government stakeholders.
- Ability to work independently and as part of a cross-functional team, managing multiple priorities in a fast-paced, highly regulated environment.
- Ability to obtain and maintain a Public Trust clearance and have resided in the United States for at least 3 of the last 5 years.
Benefits
- Highly competitive salary
- Full healthcare benefits
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Information Security Engineer – IAM Lead
Model NModel N enables our life sciences and high-tech customers deliver life-changing products to the world.
Information Security Engineer leading IAM program at Model N
Senior Security Engineer, Detection and Response
1PasswordProductive businesses use 1Password to secure employees at scale.
Senior Security Engineer enhancing 1Password's security posture through proactive detection and response
Electronic Security Field Manager
CennoxCennox support the world's leading businesses for all things facilities, security, and technology.
Field Manager overseeing Electronic Security technician operations across regions
Cybersecurity Engineer – SOAR
Phoenix CyberSubject Matter Expert Services for Enterprise and Government. Specializing in Security Engineering & Operations.
Cybersecurity Engineer developing solutions within Phoenix Cyber’s delivery team