Senior Security Engineer/Secret or -Secret Clearance
Listed on 2026-09-01
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Title:
Senior Security Engineer
Location:
Washington, D.C.
Clearance Required:
Active Secret or Top-Secret (TS) Clearance
Salary: $150k-$170K Based on Years of Experience
Final date to receive applications:
September 30, 2026
IBSS is seeking a Senior Security Engineer to support a Federal customer. This position develops, enhances, and maintains Security Operations Center (SOC) processes and standard operating procedures, performs vulnerability analysis and hands‑on security testing, and leads the engineering and implementation of secure cloud solutions, primarily in Microsoft Azure, in alignment with the customer's cybersecurity strategy and federal compliance mandates (NIST, FISMA, FedRAMP).
The Senior Security Architect works alongside the Cyber Security SME, ISSOs/Security Assessors, and customer leadership to sustain a strong security posture.
- Develop, enhance, and maintain Security Operations Center (SOC) standard operating procedures (SOPs) and assessment operations processes.
- Ensure accountability, integrity, confidentiality, and protection of operational security processes and data.
- Perform vulnerability analysis, review program‑level documentation (system requirements, architectures, design documents, test plans, security plans), and provide technical recommendations.
- Develop and document security evaluation plans, test procedures, and assessment methodologies.
- Conduct hands‑on security testing, analyze results, identify risk, and recommend countermeasures.
- Assess and calculate risk based on identified threats, vulnerabilities, and security control weaknesses.
- Identify and document mitigation strategies for threats, vulnerabilities, and deficiencies.
- Support the design, development, and implementation of security‑related systems, tools, and assessment capabilities.
- Participate in and/or lead technical exchange meetings, document action items and outcomes, and brief leadership on security engineering status and results.
- Support SOC alert analysis, triage, escalation, containment actions, and continuous improvement of detection and response use cases.
- Lead the engineering and implementation of secure cloud solutions — primarily in Microsoft Azure — in alignment with the customer's cybersecurity strategy and federal compliance mandates (NIST, FISMA, FedRAMP).
- Integrate Zero Trust security principles across Azure cloud environments, including identity hardening, micro‑segmentation, conditional access, and continuous monitoring.
- Configure and operationalize Azure cloud platform services, including:
- Azure Kubernetes Service (AKS) secure cluster configuration, governance, and node‑pool hardening
- Azure Policy creation and enforcement
- Secure Landing Zones following Azure enterprise‑scale frameworks
- Role‑Based Access Control (RBAC) and least‑privilege access models
- Resource tagging, naming standards, and governance implementation
- Bachelor's degree
- Minimum of eight (8) years of cybersecurity experience.
- CISSP or similar (CISM, CASP+, GSLC, etc.) recognized cybersecurity certification.
- Cloud Architecture/Engineer or similar certification, preferably one (or more) of the following:
- AZ-305 (Azure Solutions Architect Expert)
- SC-100 (Cybersecurity Architect Expert)
- AZ-400 (Dev Ops Engineer Expert)
- AZ-104 (Azure Administrator Associate)
- Demonstrated experience implementing and securing Azure cloud services, including AKS, Azure Policy, Azure AD/Entra, Conditional Access, RBAC, and Zero Trust controls.
- Ability to evaluate security documentation and develop security test plans, evaluation methodologies, and technical recommendations.
- Ability to coordinate across cybersecurity teams and communicate technical information to leadership.
- Secret Clearance or higher required.
- Experience supporting the Department of Commerce or another Federal Civilian Executive Branch (FCEB) agency’s cybersecurity or cloud security program.
- Experience supporting Security Operations Center (SOC) alert triage, escalation, and incident containment activities.
- Experience developing ATO/A&A documentation (SSPs, SARs, POA&Ms) within a NIST Risk Management…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).