Security Engineer II
Listed on 2026-05-10
-
IT/Tech
Cybersecurity
Paragon is recruiting for a Security Engineer II to work on the PEO-T contract for USTRANSCOM.
Security Engineer II provides technical support in the areas of vulnerability and risk assessment, network security, product evaluation, and security implementation. Understands Information Security Continuous Monitoring (ISCM) concepts, security automation, and risk dashboarding tools. Must adhere to USTRANSCOM processes and procedures to identify and respond to risk while supporting efficient, accurate Assessment & Authorization (A&A) reporting to facilitate ongoing authorizations, secure release deployments, modernizations, migrations, and overall security enhancements.
A high-level of autonomy is required for this role. Capable of defining solution recommendations and working with management to improve efficiency in processes and procedures. Capable of communicating technical details effectively within their assigned Program Management Offices (PMOs), translating complex security risks into operational or business impact for leadership and non-technical stakeholders. Effective communication skills and willingness to collaborate with peers and management are critical to success.
May be asked to provide supplementary support to additional PMOs within the contract purview.
include, but are not limited to, the following:
- Reviews evolving NIST requirements to support risk assessment activities associated with the affiliated system requirements and specifications (execution, mapping, and compliance tracking).
- Prepares detailed specifications from which cybersecurity deficiencies identified during risk assessment will be mitigated/remediated and conducts follow-up risk assessment to ensure proper secure coding practices and STIG/SRG implementation are being built-in/enforced to the greatest extent possible.
- Collaborates closely with government customers to develop appropriate POA&Ms and support risk acceptance activities as needed to support risk management processes. Reviews evolving National Institute of Standards and Technology (NIST) requirements to support risk assessment activities associated with the affiliated system requirements and specifications (execution, mapping, and compliance tracking).
- Prepares detailed specifications from which cybersecurity deficiencies identified during risk assessment will be mitigated/remediated and conducts follow-up risk assessment to ensure proper secure coding practices and Security Technical Implementation Guide(STIG)/Security Requirements Guide (SRG) implementation are being built-in/enforced to the greatest extent possible.
- Collaborate closely with government customers to develop appropriate Plan of Action and Milestones (POA&Ms) and support risk acceptance activities as needed to support risk management processes.
- Responsible for designing and implementing solutions for protecting confidentiality, integrity, and availability of sensitive information.
- Provides technical evaluations of IT systems and assists with making security improvements.
- Participates in design of information system contingency plans that maintain appropriate levels of protection and meet time requirements for minimizing operations impact to customer organization.
- Conducts security product evaluations, and recommends products, technologies and upgrades to improve the organization’s security posture.
- Conduct testing and audit log reviews to evaluate the effectiveness of current security measures.
- Participates in team initiatives including the drafting of deliverables and peer reviews of others’ products.
- Experience developing/reviewing system authorization documentation (family plans and supplementary artifacts) in accordance with Department of War (DoW) implementation of the Risk Management Framework (RMF)
- Experience participating in Technical Interchange Meetings (TIMs) on a wide range of Program Management Office (PMO) security engineering topics
- Experience participating in acquisition program engineering milestone reviews
- Experience coordinating and collaborating with Development contract personnel in Security, System Administration, System Engineering, and other supporting…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).