Senior GRC Engineer
RemoteUnited States
Job Summary
Maintain and strengthen the cybersecurity posture of assigned federal programs, systems, or enclaves by guiding system owners, ISSOs, and engineering teams through the system lifecycle. Lead Risk Management Framework activities including categorization, control selection, implementation, assessment, authorization, and continuous monitoring while producing high-quality, actionable security artifacts. Support achievement and maintenance of Authorities to Operate and manage Plans of Action and Milestones through briefings to senior leadership on risk posture and remediation strategies. Apply DevSecOps principles to integrate security into CI/CD pipelines and support Zero Trust architecture, supply chain risk management, and modernization initiatives across IT and operational technology environments. Utilize SAST, DAST, SCA, secrets management, and GitHub workflows alongside Infrastructure as Code, virtualization, and containerization to assess vulnerabilities using CVE, CWE, and CVSS methodologies. Implement authentication, authorization, and identity federation mechanisms including SAML, OAuth, and OIDC while leveraging endpoint protection, integrity monitoring, and SIEM tooling. Develop and maintain cybersecurity policies aligned with organizational objectives and assess controls using NIST SP 800-53, the Cybersecurity Framework, and CIS Critical Security Controls. Introduce automation and engineering practices to improve continuous monitoring maturity and ensure compliance with FedRAMP standards.
Required Qualifications
- Bachelor's degree in Computer Science, Information Systems, or a related field, or an additional three years of relevant experience
- Seven or more years of relevant cybersecurity experience
- Three or more years of experience serving as an ISSO for a Federal agency
- Prior experience serving as an ISSO for a portfolio of Federal systems
- Experience achieving ATOs, managing POA&Ms, and briefing senior leadership
- Deep functional and technical knowledge of NIST RMF and NIST CSF processes and documentation
- Expertise in FedRAMP standards and processes
- Strong understanding of IaaS, PaaS, and SaaS cloud service models, including Azure, Microsoft 365, Salesforce, ServiceNow, Appian, and MuleSoft
- Strong foundational and operational knowledge of DevSecOps, CI/CD pipelines, Zero Trust, supply chain risk management, artificial intelligence, and operational technology
- Familiarity with SAST, DAST, Software Composition Analysis, secrets management, and GitHub
- Operational knowledge of Infrastructure as Code, virtualization, and containerization
- Proficiency with endpoint protection, integrity monitoring, and SIEM tools
- Expertise in authentication, authorization, and identity federation technologies
- Familiarity with PKI, encryption technologies, and FIPS requirements
- Foundational understanding of network architectures and security mechanisms
- Familiarity with OSCAL and machine-readable security documentation
- Ability to analyze software vulnerabilities using CVE, CWE, and CVSS
- Experience in technical writing and producing clear, well-organized security documentation
- Experience evaluating supplier and product trustworthiness
- Ability to obtain a Public Trust clearance
Desired Qualifications
- One or more certifications such as CASP, GPEN, GMON, GISP, GSEC, GSLC, CISM, CISA, CAP, CCSP, SSCP, CISSP, or CISSP-ISSMP
- Experience implementing policy as code to automate control enforcement, compliance validation, and evidence collection
- Demonstrated ability to introduce automation and engineering practices into GRC programs to enhance efficiency and continuous monitoring
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.