Senior Security Engineer developing and implementing security controls for cloud-based SaaS applications. Leading compliance efforts for Federal customers while collaborating with engineering and DevOps teams.
Responsibilities
Lead the development, documentation, and implementation of security controls aligned with NIST 800-171 and NIST 800-53 frameworks
Own and maintain compliance artifacts including System Security Plans (SSP), Plans of Action and Milestones (POA&M), and supporting documentation
Drive Assessment and Authorization (ATO) efforts, including preparation of authorization packages and coordination with assessors
Collaborate with engineering and DevOps teams to integrate security controls into cloud infrastructure, CI/CD pipelines, and application architectures
Conduct risk assessments, maintain risk registers, and lead remediation efforts for identified security gaps
Develop and enforce security policies, procedures, and standards aligned with Federal and customer requirements
Evaluate and document security controls across AWS environments, containerized systems, and operational processes
Support SOC 2 Type 2 readiness, including audit preparation, evidence collection, and control validation
Monitor changes in regulatory requirements and proactively update security controls and documentation
Contribute to incident response planning, documentation, and post-incident analysis
Requirements
5+ years of experience in security engineering, compliance, or information assurance roles
Deep expertise in NIST 800-171 and NIST 800-53 security frameworks
Proven experience developing and maintaining SSPs, POA&Ms, and audit-ready compliance documentation
Hands-on experience supporting ATO/ATT processes in Federal or defense environments
Strong experience with AWS cloud security, including IAM, VPC architecture, encryption, and logging
Experience implementing security controls in containerized environments (Docker, Kubernetes, ECS)
Solid understanding of identity and access management, secrets management, and network security principles
Excellent written communication skills with the ability to produce clear, thorough, and audit-ready documentation
Strong organizational skills and the ability to manage multiple concurrent compliance initiatives
Content Developer creating engaging and effective learning materials for coding education online. Collaborating with a team to develop tailored resources for K - 12 learners in Egypt.
Campus Security Officer ensuring safety at Bright Horizons early childcare centers in Seattle. Responsible for access control, surveillance, and emergency response.
Sounding and Security Watch responsible for Navy asset security at NSF Diego Garcia. Conducting checks and ensuring safety during designated watch hours with strong situational awareness.
Sales Enablement Manager creating technical content for Upwind Security. Collaborating across teams to translate cloud security concepts into clear narratives for engineers and security leaders.
Security Engineer designing and implementing security measures to protect Snap Inc.'s infrastructure. Collaborating across teams while focusing on threat detection and response strategies.
IT Security & Compliance Head at Lonza leading security strategy and managing global risk. Collaboration with senior leadership to enhance information security across Capsules & Health Ingredients business.
Senior Security Manager leading security for Sanofi meetings and events across North America. Ensuring compliance with global meeting policies and managing event security operations in high - stake environments.
Security Officer maintaining safety protocols at Aloft New Orleans. Responsible for patrolling, monitoring security systems, and assisting guests with safety - related concerns.
Security Detection Specialist responsible for detecting cybersecurity incidents using advanced security technologies. Analyzing data feeds and leveraging security tools for incident detection and reporting.
Senior Incident Response Engineer at Walmart focusing on security threat campaigns to enhance detection and response capabilities. Collaborating with SOC and engineering teams to improve security posture.