Subject Matter Expert III - Information Systems Security Engineer
On-siteArlington, Virginia, United States
Job Summary
Lead Information Systems Security Engineer, developing and integrating cybersecurity designs for systems and networks. Design, build, and maintain the layered automation architecture in AWS infrastructure, including provisioning, configuration management, policy-as-code compliance validation, and orchestration. Develop and manage the Compliance-as-Code framework while integrating AWS-native security services for continuous monitoring. Provide technical support for dashboard and API development, including Power BI dashboards and RESTful APIs that expose standardized compliance metrics. Serve as the lead technical authority for translating DoW regulatory requirements into functional, automated, operational code. Requires active Secret clearance, U.S. citizenship, and 12 years of systems engineering and cybersecurity experience.
Required Qualifications
- Bachelor's degree from an accredited institution in Information Technology, Computer Science, Engineering, or a related technical discipline
- One of the following certifications: AWS Certified DevOps Engineer – Professional; AWS Certified Solutions Architect – Professional; AWS Certified Security – Specialty; or (ISC)2 CISSP, preferably with an engineering or architecture concentration (ISSEP/ISSAP)
- Twelve (12) years of demonstrated experience in systems engineering and cybersecurity, with at least seven (7) of those years focused on security automation, cloud engineering, and architecture
- Five (5) years of demonstrated experience serving as a lead technical authority on enterprise-level projects, responsible for designing and implementing security solutions, not just assessing them
- Five (5) years of demonstrated experience translating complex regulatory requirements (RMF, NIST, DISA STIGs) and architectural diagrams into functional, automated, and operational code
- Active Secret clearance
- U.S. citizenship
- Expert-level AWS engineering skill, including AWS-native security services and Systems Manager
- Infrastructure-as-Code and secure baseline template development for repeatable, compliant provisioning
- Policy-as-Code and Compliance-as-Code development, translating DoW control requirements into automated checks
- Security orchestration and workflow automation across multi-step, multi-system processes
- Dashboard and API engineering (e.g., Microsoft Power BI, RESTful APIs) to expose standardized, reusable compliance metrics
- Deep working knowledge of RMF, NIST standards, and DISA STIGs in a DevSecOps delivery model
- Ability to act as lead technical authority and to communicate architectural decisions to government stakeholders
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.