Talent.com
Compliance and Security Engineer
Compliance and Security EngineerExecutivePlacements.com • Washington, DC, United States
Compliance and Security Engineer

Compliance and Security Engineer

ExecutivePlacements.com • Washington, DC, United States
1 day ago
Job type
  • Full-time
Job description

At TCG, we aim to prove that businesses can be good to their employees and responsible to their community while being profitable. We're an award-winning IT solutions provider to the Federal government seeking a Compliance and Security Engineer to join our project team at a major Federal agency.

The Compliance and Security Engineer will collaborate with operational teams and the Chief Information Officer (CIO) to uphold the security posture and ensure the implementation and maintenance of security controls in compliance with security plans and regulations. This role offers the unique opportunity to develop both Information Security Officer and Systems Engineering skills, eventually transitioning into a mid-level engineering position with a focus on technical work.

US Citizenship is required for this role. In addition, the selected applicant must submit to a government background investigation and be favorably adjudicated before their first day.

While primarily remote, this position may require occasional on-site meetings. The selected candidate must live within commuting distance of Washington, D.C.

Responsibilities

  • Conduct scheduled vulnerability scans with Nessus, Tenable, and Qualys across Windows, Linux, and container platforms; analyze results, document findings, and create POA&M entries to drive remediation planning.
  • Operate enterprise SIEM solutions (Splunk, ArcSight, QRadar, etc.), correlating alerts, performing root-cause investigations, and executing incident containment and closure in accordance with NIST800-61.
  • Draft, maintain, and update System Security Plans (SSPs), Risk Assessment Reports, POA&M logs, and System Requirements Traceability Matrices (SRTMs) to ensure alignment with NIST800-53 Rev5 and FISMA mandates.
  • Generate compliance dashboards and report status to leadership.
  • Assist in the design, implementation, and testing of NIST800-53 controls (e.g., Access Control, System & Communications Protection, Identification & Authentication).
  • Participate in periodic control assessments, including pre-penetration test reviews, to validate the security posture.
  • Administer and optimize monitoring stacks; fine-tune alert thresholds, develop custom probes, and deliver concise "quick-look" reports to stakeholders.
  • Harden operating systems (Windows, RHEL / CentOS, Ubuntu) and container images, applying CIS Benchmarks and conducting baseline compliance scans.
  • Review source code snippets (Python, Ruby, Java) for OWASP and CIS guideline violations; recommend secure coding practices.
  • Automate repetitive security tasks using lightweight scripts (Python, Bash) to increase efficiency and reduce human error.
  • Collaborate with DevSecOps teams to embed security controls throughout CI / CD pipelines (Jenkins, GitLab, Azure DevOps), ensuring secure deployment of applications.
  • Provide expert guidance to developers on secure coding, threat modeling, and testing methodologies.
  • Mentor junior analysts on monitoring, logging, and documentation best practices.
  • Author internal knowledge-base articles, develop training materials, and conduct short workshops to elevate team capability.

Required Skills & Experience

  • Minimum of 4 years of experience in IT security, including 2 years in a federal or ISSO-equivalent role such as System Security Officer or Security Analyst.
  • Demonstrated mastery of NIST800-53 Rev5, NIST800-61, and related NIST 800-series publications, applying these frameworks to security planning and operations.
  • Proficient with enterprise SIEM platforms (Splunk, QRadar, ArcSight) for event correlation, threat detection, and incident response.
  • Experienced in deploying and interpreting vulnerability scans using tools like Tenable, Qualys, Nexpose, etc., and translating findings into actionable remediation plans.
  • Skilled in monitoring infrastructure, including the design of dashboards, threshold tuning, and alert management.
  • Adept at configuring and maintaining security appliances to enforce perimeter security and web application protection.
  • Comfortable scripting in Python (or PowerShell, Bash) for automation, data extraction, and basic code-review tasks.
  • Solid understanding of networking fundamentals-TCP / IP, DNS, HTTP / HTTPS, and SSL / TLS-including packet analysis and troubleshooting.
  • Proficient in Microsoft Office (Word, Excel) and Atlassian suites (Jira, Confluence) for creating SOPs, generating reports, and maintaining dashboards.
  • Strong analytical and problem-solving abilities, capable of exercising independent judgement in complex security scenarios.
  • Excellent verbal and written communication skills, with the capacity to craft concise, audience-appropriate security briefs for both technical and non-technical stakeholders.
  • Preferred Skills & Experience

  • Tenable SC / IO, Nessus Advanced, Qualys, or other enterprise vulnerability platforms.
  • Experience running Blue / Red-team exercises or tabletop simulations.
  • Knowledge of container security (Docker, Kubernetes), CI / CD automation, and IaC (Terraform, CloudFormation).
  • FedRAMP knowledge, understanding of RMF implementation.
  • Education

  • Bachelor's degree preferred, preferably in Computer Science, Information Technology, or a related field. Experience may be substituted in the absence of a degree.
  • TCG does not discriminate based on race, sex, color, religion, national origin, age, disability, caste, or veteran status.

    Our B Corp mission is reflected in our benefits, including offerings like health care, 401K, parental leave, adoption assistance, financial planning services, student loan repayment assistance, and training budget. There's more; see for yourself.

    Internal title / grade : System Engineer, E2

    Salary Range : $95,000 - $120,000

    All individuals being hired to work for TCG must submit to, and successfully pass, a pre-employment background investigation prior to reporting for their first day of work. The pre-employment background investigation will include verification of employment and education, as well as a criminal and DMV check.

    Additional documentation and background checks will also be required for positions that require clearance from the Federal government.

    #J-18808-Ljbffr

    Create a job alert for this search

    Security Engineer • Washington, DC, United States

    Related jobs
    Compliance and Security Engineer

    Compliance and Security Engineer

    TCG • Washington, DC, United States
    Full-time
    You've stumbled upon the rare B Corp government contractor! At TCG, we aim to prove that businesses can be good to their employees and responsible to their community while being profitable.We're an...Show more
    Last updated: 6 days ago • Promoted
    Security Engineer

    Security Engineer

    Nutanix • Washington, DC, United States
    Full-time
    Hungry, Humble, Honest, with Heart.Are you a forward-thinking security professional with a passion for implementing cutting-edge technology and a strong understanding of Zero Trust principles? If s...Show more
    Last updated: 9 hours ago • Promoted • New!
    Security Engineer SME

    Security Engineer SME

    GovCIO • Fairfax, VA, United States
    Full-time
    GovCIO is currently hiring for a Security Engineer SME with an active Secret clearance in support of our DEA Bluestone program. Build culture of security-first development and IT infrastructure.Deli...Show more
    Last updated: 2 days ago • Promoted
    Security Engineer

    Security Engineer

    Verotis • Washington, DC, United States
    Full-time
    Verotis is seeking an experienced Security Engineer to support security operations, strategy, planning, architecture, vulnerability assessments and remediation, and coordination with various govern...Show more
    Last updated: 2 days ago • Promoted
    Security Engineer

    Security Engineer

    Electrosoft • Gaithersburg, MD, United States
    Full-time
    While cybersecurity is our specialty, we also focus on ICAM, enterprise IT modernization, and software solutions.We always seek to delight our customers, so we retain highly qualified employees and...Show more
    Last updated: 2 days ago • Promoted
    IA & SS or Security Engineer

    IA & SS or Security Engineer

    AHU Technologies, Inc. • Washington, DC, United States
    Permanent
    Role : IA & SS Master (Security Engineer).The Security Engineer role will focus on designing and developing security architecture patterns that meet regulatory obligations and data protection requi...Show more
    Last updated: 30+ days ago • Promoted
    Security Engineer SME

    Security Engineer SME

    Govcio LLC • Fairfax, VA, United States
    Full-time
    GovCIO is currently hiring for a Security Engineer SME with an active Secret clearance in support of our DEA Bluestone program. Build culture of security-first development and IT infrastructure.Deli...Show more
    Last updated: 2 days ago • Promoted
    FIPS 140 Security Engineer

    FIPS 140 Security Engineer

    ALTA IT Services • Columbia, MD, US
    Temporary
    Job Title : FIPS 140 Security Engineer Location : Columbia, MD Compensation : $60.HR Duration : 6 month contract with possibility of extension In joining the team, you will get an exciting opportunity ...Show more
    Last updated: 30+ days ago • Promoted
    Security Engineer

    Security Engineer

    AnaVation LLC • Washington, DC, United States
    Full-time
    Be Challenged and Make a Difference.In a world of technology, people make the difference.We believe if we invest in great people, then great things will happen. At AnaVation, we provide unmatched va...Show more
    Last updated: 2 days ago • Promoted
    Security Engineer

    Security Engineer

    ABBTECH Professional Resources • Reston, VA, United States
    Full-time
    Security Engineer - Subject Matter Expert.The above salary range represents the range expected for the position; however, final salary offers are based on a number of factors such as the position's...Show more
    Last updated: 2 days ago • Promoted
    Security Engineer

    Security Engineer

    AnaVation, LLC • Washington, DC, United States
    Full-time
    Be Challenged and Make a Difference.In a world of technology, people make the difference.We believe if we invest in great people, then great things will happen. At AnaVation, we provide unmatched va...Show more
    Last updated: 30+ days ago • Promoted
    Security Engineer

    Security Engineer

    iQuasar • Herndon, VA, United States
    Full-time
    Security Engineer for our customer in Herndon, VA.We believe that experienced teams, insightful solutions, proper resources and committed management will generate results that fit our clients' need...Show more
    Last updated: 2 days ago • Promoted
    Security Engineer

    Security Engineer

    HireCapital • Washington, DC, United States
    Full-time +1
    Direct message the job poster from HireCapital.Technical Recruiter placing talent at innovative and mission-driven organizations. Our client is a rapidly growing technology firm operating at the int...Show more
    Last updated: 30+ days ago • Promoted
    Security Engineer

    Security Engineer

    Tammina • Washington, DC, United States
    Full-time
    The security engineering position provides support to a Security Operation Center of a federal agency.Ideal candidate will have comprehensive knowledge of Windows and UNIX-based system administrati...Show more
    Last updated: 2 days ago • Promoted
    Network Security Engineer

    Network Security Engineer

    Office of The Chief Financial Officer • Northern Virginia, VA, United States
    Full-time
    Government of the District of Columbia.Office of the Chief Financial Officer (OCFO).Network Security Engineer (INFOSEC).This position is located in the Office of the Chief Financial Officer (OCFO),...Show more
    Last updated: 30+ days ago • Promoted
    Security Engineer

    Security Engineer

    Berkeley Research Group • Washington, DC, United States
    Full-time
    Second Sight Solutions, a subsidiary of Berkeley Research Group (BRG), is a health technology company, and our innovative technology reimagines how drug discount data is exchanged, establishing new...Show more
    Last updated: 2 days ago • Promoted
    Security Engineer - Networks

    Security Engineer - Networks

    ERT • Silver Spring, MD, United States
    Full-time +1
    ERT is seeking a Security Engineer to work directly with Agile development and operations teams supporting the modernization of AWIPS (Advanced Weather Interactive Processing System) into a cloud-n...Show more
    Last updated: 1 day ago • Promoted
    Security Infrastructure Engineer

    Security Infrastructure Engineer

    Leidos Inc • Alexandria, VA, United States
    Full-time
    As a Security Engineer on our team, you will operate and maintain network security infrastructure utilized by a team of cybersecurity analysts in support of 24x7x365 mission-critical operations.Thi...Show more
    Last updated: 11 days ago • Promoted