DataLock Consulting Group logo
DataLock Consulting GroupPosted 6 months ago

Senior GRC Engineer

RemoteUnited States

Part TimeSenior LevelSmall

Job Summary

Maintain and strengthen the cybersecurity posture of assigned federal programs, systems, or enclaves by guiding system owners, ISSOs, and engineering teams through the system lifecycle. Lead Risk Management Framework activities including categorization, control selection, implementation, assessment, authorization, and continuous monitoring while producing high-quality, actionable security artifacts. Support achievement and maintenance of Authorities to Operate and manage Plans of Action and Milestones through briefings to senior leadership on risk posture and remediation strategies. Apply DevSecOps principles to integrate security into CI/CD pipelines and support Zero Trust architecture, supply chain risk management, and modernization initiatives across IT and operational technology environments. Utilize SAST, DAST, SCA, secrets management, and GitHub workflows alongside Infrastructure as Code, virtualization, and containerization to assess vulnerabilities using CVE, CWE, and CVSS methodologies. Implement authentication, authorization, and identity federation mechanisms including SAML, OAuth, and OIDC while leveraging endpoint protection, integrity monitoring, and SIEM tooling. Develop and maintain cybersecurity policies aligned with organizational objectives and assess controls using NIST SP 800-53, the Cybersecurity Framework, and CIS Critical Security Controls. Introduce automation and engineering practices to improve continuous monitoring maturity and ensure compliance with FedRAMP standards.

Required Qualifications

  • Bachelor's degree in Computer Science, Information Systems, or a related field, or an additional three years of relevant experience
  • Seven or more years of relevant cybersecurity experience
  • Three or more years of experience serving as an ISSO for a Federal agency
  • Prior experience serving as an ISSO for a portfolio of Federal systems
  • Experience achieving ATOs, managing POA&Ms, and briefing senior leadership
  • Deep functional and technical knowledge of NIST RMF and NIST CSF processes and documentation
  • Expertise in FedRAMP standards and processes
  • Strong understanding of IaaS, PaaS, and SaaS cloud service models, including Azure, Microsoft 365, Salesforce, ServiceNow, Appian, and MuleSoft
  • Strong foundational and operational knowledge of DevSecOps, CI/CD pipelines, Zero Trust, supply chain risk management, artificial intelligence, and operational technology
  • Familiarity with SAST, DAST, Software Composition Analysis, secrets management, and GitHub
  • Operational knowledge of Infrastructure as Code, virtualization, and containerization
  • Proficiency with endpoint protection, integrity monitoring, and SIEM tools
  • Expertise in authentication, authorization, and identity federation technologies
  • Familiarity with PKI, encryption technologies, and FIPS requirements
  • Foundational understanding of network architectures and security mechanisms
  • Familiarity with OSCAL and machine-readable security documentation
  • Ability to analyze software vulnerabilities using CVE, CWE, and CVSS
  • Experience in technical writing and producing clear, well-organized security documentation
  • Experience evaluating supplier and product trustworthiness
  • Ability to obtain a Public Trust clearance

Desired Qualifications

  • One or more certifications such as CASP, GPEN, GMON, GISP, GSEC, GSLC, CISM, CISA, CAP, CCSP, SSCP, CISSP, or CISSP-ISSMP
  • Experience implementing policy as code to automate control enforcement, compliance validation, and evidence collection
  • Demonstrated ability to introduce automation and engineering practices into GRC programs to enhance efficiency and continuous monitoring

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce