Senior /Principal Federal Security Engineer
Saviynt
The Senior/Principal Federal Security Engineer reports into Federal Information Security leadership, and will specialize in detection, response, and vulnerability triage. They will also serve as a high-level technical authority responsible for the end-to-end lifecycle of threat management. This hands-on engineering role will own the systems that identify and mitigate organizational risk as they relate primarily to the FedRAMP Program (FedRAMP Moderate and FedRAMP High).
The candidate should be familiar with policy and compliance requirements, including policy documentation and system requirements to successfully respond to potential audits as well as prior experience operating in Federally regulated environments.
CORE RESPONSIBILITIES
- Design and maintain high-fidelity detection rules and analytics across the security stack (SIEM, EDR, CNAPP/CSPM) and cloud environments (AWS, GCP, Azure).
- Ability to run vulnerability scans, triage results, establish exploitability of reported vulnerabilities, recommend risk mitigation controls, and deploy controls where needed
- Develop and refine automated response playbooks for Incident Response (IR) and orchestration (SOAR).
- Lead the evaluation and integration of security technologies, ensuring scalability, resilience, and compliance. as it pertains to FedRAMP environments
WHAT YOU WILL BE DOING
WHAT YOU BRING
- U.S. Citizenship: Applicants must be United States citizens.
- Bachelor's degree or equivalent experience with a minimum of 10 years of experience in Security Engineering, Security Architecture, Federal Security or similar
- Knowledge of U.S. Federal Government security compliance, risk management processes and requirements, including NIST RMF and NIST SP 800-53 Rev 5 controls
- Experience with vulnerability scanning, remediation, and continuous monitoring (ConMon)
- Requires sufficient technical background to be able to interpret audit and compliance requirements, and be able to support basic evidence gathering needs in support of audits
- Ability to provide excellent written and oral communications by email, presentations, and mobile communication platforms (including: experience facilitating discussions, briefing senior managers, and conducting project meetings).
- Experience with continuous monitoring and Plans of Actions and Milestones (POA&Ms) is a plus
- Knowledge of local legal and regulatory security requirements including HIPAA, FedRAMP, and GDPR/privacy
- Flexible and collaborative approach to enabling and supporting the business
- Meet US persons on US soil requirements
- Undergo full background investigation/screening
- Undergo IAL3 requirements (Identity proofing to include I-9 document verification, biometric collection, and mailing address confirmation)
100000 - 160000 USD a year