Job Closed

This listing is no longer active.

Abile Headquarters logo
Abile Headquarters

Abile Group, Inc. was formed in July 2004 to partner with the Intelligence Community and their Contractors in the areas of Enterprise Analytics & Performance Management, IT & Systems Engineering and Program & Project Management. We have significant experience with the Federal Government and are an EDWOSB dedicated to our employees and clients. Hiring Statement Abile is committed to hiring the most qualified and best fit person for the job - always has, always will. Anyone requiring reasonable accommodations should email careers@abilegroup.com with requested details. A member of the HR team will respond to your request within 2 business days. Please review our current job openings and apply for the positions you believe may be a fit. If you are not an immediate fit, we will also keep your resume in our database for future opportunities.

FedRAMP Engineer

Location

United States

Posted

90 days ago

Salary

0

Seniority

Mid Level

No structured requirement data.

Job Description

FedRAMP Engineer

Abile Headquarters

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description Abile Group is seeking a FedRAMP Engineer to join our rapidly growing and innovative cybersecurity team! The candidate will provide technical expertise on Security control implementations and development of Information Security procedures for systems and applications. The selected candidate will play a key role in a fast-paced FedRAMP team to provide comprehensive program, analytical, technical, and advisory skills to the client and supported Cloud Service Providers (CSPs). Candidates will be required to perform pre-assessment activities, including a detailed analysis of the technology stacks that comprise the vendor solutions. This position requires an advanced understanding of engineering secure, compliant, and resilient architectures and solutions. You will be part of a team working to assess vendor systems for technical compliance with NIST, FedRAMP and agency standards. Responsibilities - Performs detailed architecture and technical design reviews on the full stack for vendor solutions. - Conducts architecture reviews of Cloud Service Providers (CSPs) authorization packages to validate the secure design, alignment to FedRAMP and agency requirements, identify gaps, and advise the FedRAMP Government Lead on overall risk posture and compliance. - Leads and conducts architecture interviews with CSPs to ensure all critical control areas throughout the architecture are designed to meet program requirements. - Develops architecture briefing documents to inform the Government FedRAMP program manager and CISO of CSP compliance with FedRAMP program requirements, technical capabilities, and any concerns noted from the material review. - Completes comprehensive review and comments on documents of CSPs FedRAMP documentation, including but not limited to system security plans, policies and procedures, supplemental agency guidance documents, alternative implementation and risk acceptance documents, etc. - Completes a comprehensive review of CSPs' assessments and package submissions after 3PAO audits and prepares a package briefing for the Government FedRAMP program manager and agency CISO. - Works alongside the agency FedRAMP Lead and provides security engineering services. - Provides support for Continuous Monitoring activities including but not limited to items such as reviewing annual package submissions, reviewing and scoping significant change proposals, reviewing risk acceptance documents, etc. - Interprets FedRAMP and other agency requirements and provides vendors with guidance regarding expectations, technical requirements, and processes. - Stays informed of updated FedRAMP guidance, industry best practices, emerging technologies, and Government cybersecurity directives, and provides recommendations to FedRAMP Government lead regarding impacts. - Conducts security reviews of technologies for use-based consideration within CSPs authorization boundary. - Oversees and manages relationships for assigned systems that may be contractor-owned or contractor-operated, ensuring vendors comply with agency security and privacy requirements. - Assists stakeholders with IT security-related activities to ensure project deadlines are met. - Ensures all systems are operated, maintained, and disposed of IAW documented security policies and procedures, including but not limited to Assessment & Authorization (A&A). - Researches assigned IT security systems to provide insight into IT security architectures and IT security recommendations for assigned systems. Qualifications - Bachelor’s degree in Computer Science, Information Systems, Mathematics, Engineering or a related field, or an additional three years of IT experience. - Five (5) years of experience in the IT Security field. - Four (4) years of hands-on technical experience as a System Architect or Security Engineer. - Four (4) years of experience supporting FedRAMP. Desired Certifications - Security+, CISSP, CISM, CISA, or equivalent Security certification strongly preferred. Required Skills - Direct experience performing analysis on FedRAMP CSP architectures and control implementations (ie. 3PAO, FedRAMP program at another agency, etc) as an Engineer or Architect. - Confidence and depth of understanding to lead meetings with potential Vendors. - Current experience in reviewing 3rd party security assessment reports. - Have detailed knowledge and experience with NIST Policies, Governance, Security Planning and Architecture, FISMA Compliance, RMF, Incident Analysis, and General Security Best Practices. - Possess strong written and oral communication skills to support customers, internal stakeholders, peers, and public audiences. - Ability to communicate, both written and oral, to both technical and non-technical stakeholders. - Strong communication skills to interact with senior managers, junior staff, and business unit (non-technical) customers. Benefits - This position allows for 100% remote work. Remote Work Policy Remote work necessitates a high level of trust in our employees. To ensure that employee performance does not suffer in a remote work environment, all employees who telecommute are expected to have a quiet and distraction-free workspace with adequate internet, dedicate their full attention and availability to their job duties during working hours, and maintain a schedule during core business hours that align with those of their coworkers and clients. In alignment with our inclusive and engaging environment, cameras are encouraged and can be required to be on during virtual video conferences. Additionally, in alignment with the Office of the Inspector General’s effort to eliminate conflicting employment, all employees are required to disclose any current or future outside employment engagements. During onboarding and throughout employment, employees must disclose any current activities or intent to engage in outside employment or other professional activities and obtain written approval. Employees may not solicit or conduct any outside business during core business hours for the company and our clients. Hiring Statement Abile is committed to hiring the most qualified and best fit person for the job - always has, always will. Anyone requiring reasonable accommodations should email careers@abilegroup.com with requested details. A member of the HR team will respond to your request within 2 business days. Please review our current job openings and apply for the positions you believe may be a fit. If you are not an immediate fit, we will also keep your resume in our database for future opportunities.

Job Requirements

  • Bachelor’s degree in Computer Science, Information Systems, Mathematics, Engineering or a related field, or an additional three years of IT experience.
  • Five (5) years of experience in the IT Security field.
  • Four (4) years of hands-on technical experience as a System Architect or Security Engineer.
  • Four (4) years of experience supporting FedRAMP.
  • Desired Certifications
  • Security+, CISSP, CISM, CISA, or equivalent Security certification strongly preferred.
  • Required Skills
  • Direct experience performing analysis on FedRAMP CSP architectures and control implementations (ie. 3PAO, FedRAMP program at another agency, etc) as an Engineer or Architect.
  • Confidence and depth of understanding to lead meetings with potential Vendors.
  • Current experience in reviewing 3rd party security assessment reports.
  • Have detailed knowledge and experience with NIST Policies, Governance, Security Planning and Architecture, FISMA Compliance, RMF, Incident Analysis, and General Security Best Practices.
  • Possess strong written and oral communication skills to support customers, internal stakeholders, peers, and public audiences.
  • Ability to communicate, both written and oral, to both technical and non-technical stakeholders.
  • Strong communication skills to interact with senior managers, junior staff, and business unit (non-technical) customers.

Benefits

  • This position allows for 100% remote work.
  • Remote Work Policy
  • Remote work necessitates a high level of trust in our employees. To ensure that employee performance does not suffer in a remote work environment, all employees who telecommute are expected to have a quiet and distraction-free workspace with adequate internet, dedicate their full attention and availability to their job duties during working hours, and maintain a schedule during core business hours that align with those of their coworkers and clients. In alignment with our inclusive and engaging environment, cameras are encouraged and can be required to be on during virtual video conferences. Additionally, in alignment with the Office of the Inspector General’s effort to eliminate conflicting employment, all employees are required to disclose any current or future outside employment engagements. During onboarding and throughout employment, employees must disclose any current activities or intent to engage in outside employment or other professional activities and obtain written approval. Employees may not solicit or conduct any outside business during core business hours for the company and our clients.
  • Hiring Statement
  • Abile is committed to hiring the most qualified and best fit person for the job - always has, always will. Anyone requiring reasonable accommodations should email careers@abilegroup.com with requested details. A member of the HR team will respond to your request within 2 business days. Please review our current job openings and apply for the positions you believe may be a fit. If you are not an immediate fit, we will also keep your resume in our database for future opportunities.

Related Categories

Related Job Pages

More Security Engineer Jobs

Horizon Industries logo

Cybersecurity Engineer

Horizon Industries

Horizon Industries Limited was founded in 1996 and is based in Vienna, Virginia. Horizon is a dynamic, SBA-certified Small Disadvantaged Business (SDB) with professional and talented strategists, technologists, and consultants across diverse domains. Expertise in IT, analysis and evaluation, data analytics, business process management Acquisition and financial management, cost and risk assessments Independent Verification & Validation, program management, systems engineering and design Database management, logistical warehouse services, and administrative support Capabilities in financial, operational, and technology consulting Risk management services, strategic planning, leadership effectiveness Anti-fraud waste and abuse programs, financial and operational assessments Regulatory compliance, workflow automation, and audit readiness services Equal Employment Opportunity Horizon is an Equal Employment Opportunity employer. It is our policy to consider all applicants for employment without regard to sex, race, color, creed, religion, national origin, sexual orientation, marital status, age, disability, veteran status, alienage, ancestry, citizenship status, or any other factor prohibited by law. Horizon will not discharge or discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant, consistent with applicable law.

OtherRemoteTeam 201-500

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description The Cybersecurity Assessment and Authorization (A&A) Subject Matter Expert (SME) serves as a senior cybersecurity authority responsible for supporting the authorization of information systems and ensuring compliance with Department of Defense (DoD) cybersecurity policies and procedures. The SME performs and supports the DoD cybersecurity authorization process, either as the system authorizing expert or as a subject matter expert for systems undergoing authorization. This role requires a strong understanding of how security controls defined in NIST SP 800-53 are applied during the assessment and authorization process across large and complex enterprise environments such as those supporting the Defense Logistics Agency (DLA). These environments may include multiple enclaves, Automated Information Systems (AIS), enterprise applications, and outsourced IT services. - The SME evaluates vulnerabilities and determines the appropriate severity value for identified security control deficiencies. - Assesses potential impacts on system authorization status and provides recommendations for remediation. - Briefs senior leadership on the progress, risks, and outcomes of systems undergoing the Risk Management Framework (RMF) authorization process. Qualifications - Minimum five (5) years of experience supporting Risk Management Framework (RMF) and NIST Assessment and Authorization (A&A) processes. - Demonstrated DoD cybersecurity experience. - Experience assessing security controls and conducting authorization reviews for large, complex organizations. - Strong understanding of DoD cybersecurity authorization policies, procedures, and implementation processes. - Experience supporting the DoD RMF authorization lifecycle. - Knowledge of cybersecurity considerations related to emerging technologies, including: - Cloud environments - Industrial Control Systems (ICS) - Warehouse Execution Systems - Operational Technology (OT) infrastructures. Requirements - Must possess an active DoD Secret Clearance. - Must hold IT-II Non-Critical Sensitive security clearance or Tier 3 (T3) at the time of proposal submission. Benefits - Medical, dental, vision, and disability insurance. - 401(k) retirement plan with 100% vesting from day one and employer matching after 90 days. - Educational Assistance Program. - Student Loan Repayment Program. - Gym Reimbursement Program. Company Description Founded in 1996, Horizon Industries Limited (Horizon) has grown into a team of highly qualified professionals providing full-cycle IT consulting and management support to both public and private sector clients. Horizon fosters a culture that promotes work-life balance. Horizon Industries Limited is an Equal Employment Opportunity (EEO) employer. All qualified applicants will receive consideration for employment without regard to sex, race, color, creed, religion, national origin, sexual orientation, marital status, age, disability, veteran status, alienage, ancestry, citizenship status, or any other factor protected by law.

United States
Jobgether logo

Senior IT Security Engineer

Jobgether

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1 We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

OtherRemoteH1B No Sponsor

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description As a Senior IT Security Engineer, you will play a critical role in safeguarding enterprise environments by designing, implementing, and maintaining advanced security solutions. You will serve as a technical leader, guiding security strategy, responding to incidents, and ensuring compliance with industry standards and regulations. This position offers the opportunity to influence security frameworks, mentor team members, and contribute to the evolution of security practices across the organization. You will work in a collaborative, fast-paced environment where your expertise directly impacts operational resilience and business continuity. Success in this role requires a blend of hands-on technical proficiency, strategic thinking, and the ability to communicate complex concepts effectively to stakeholders at all levels. - Design, deploy, and maintain enterprise information security solutions to protect critical infrastructure. - Serve as a Tier‑3 escalation point for monitoring and responding to security incidents. - Develop and enforce internal and customer-facing security standards, policies, and procedures. - Execute incident response activities and lead investigations in alignment with security protocols. - Evaluate, test, and deploy security application upgrades, patches, and controls. - Provide consultative expertise on emerging threats, vulnerabilities, and risk mitigation strategies. - Mentor and guide team members while contributing to the development of security product roadmaps. - Partner with product owners and cross-functional teams to ensure security alignment across solutions and offerings. Qualifications - 5–10 years of experience in information security roles, preferably in enterprise or cloud environments. - Hands-on experience with Azure Cloud security deployments and Security-as-a-Service (SaaS) solutions. - Strong knowledge of digital forensics, penetration testing methodologies, and file integrity monitoring. - Proficiency with vulnerability scanning tools, password vaulting technologies, and SIEM platforms. - Experience implementing and maintaining security frameworks such as PCI-DSS, SSAE SOC1/SOC2, GDPR, HIPAA, IRS Pub 1075, NIST, and ISO 27001. - Expertise in anti-malware technologies, security auditing, and forensic analysis. - Security certifications such as CISSP, CISA, CISM, CEH, or SANS GIAC. - Bachelor’s degree in Information Security or equivalent professional experience. - Excellent communication and collaboration skills, with the ability to advise stakeholders across multiple levels. - Familiarity with tools such as MS Sentinel, Splunk, Microsoft Defender, Trend Micro, Trellix, Carbon Black, Tenable, Rapid7, Varonis, and Microsoft Purview is preferred. Benefits - 💰 Competitive base salary: $112,000–$130,000 USD annually, with eligibility for bonus and equity programs. - 🏥 Medical, dental, and vision insurance options. - 💼 401(k) with company match. - 🌴 Unlimited paid time off and paid holidays. - 👶 Paid parental leave and family-forming benefits including fertility, adoption, and surrogacy coverage. - 🏠 Flexible work schedule and remote work options. - 📚 Education reimbursement, student loan assistance, or 529 college funding. - 🧘 Wellness programs and sabbatical leave options. Company Description

United States
Job Closed

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description Our client is seeking an IoT Security Researcher to conduct advanced vulnerability research on embedded systems and connected devices. The role focuses on identifying and analyzing security weaknesses in firmware, device operating systems, and IoT communication protocols. This position is suited for researchers who enjoy low-level analysis, firmware reverse engineering, and vulnerability discovery across embedded platforms. You will work with a team of experienced security researchers performing hands-on analysis of real-world devices, developing proof-of-concept exploits, and advancing internal research capabilities. Responsibilities - Conduct vulnerability research on IoT and embedded systems across multiple platforms and device types. - Perform firmware extraction, unpacking, and reverse engineering. - Analyze device firmware using static and dynamic analysis techniques. - Identify vulnerabilities in device operating systems, network services, and communication protocols. - Develop proof-of-concept exploits to demonstrate impact. - Interact with device hardware using debugging and extraction interfaces such as UART, JTAG, SPI, or SWD. - Analyze IoT network protocols and device communications. - Document research findings and communicate technical discoveries to internal teams. - Develop tools and automation to support ongoing research activities. Qualifications - Experience in vulnerability research or reverse engineering. - Experience analyzing embedded systems, firmware, or IoT devices. - Proficiency with reverse engineering tools such as Ghidra, IDA Pro, or Binary Ninja. - Experience with Linux-based embedded environments. - Scripting ability with Python or similar languages. - Understanding of network protocols and embedded device architectures. - Strong analytical and problem-solving skills. Requirements - Experience with hardware debugging or chip-level interfaces. - Familiarity with IoT protocols such as MQTT, BLE, Zigbee, or proprietary device protocols. - Experience with exploit development. - Public vulnerability research, CVEs, or conference presentations. - Participation in CTFs, bug bounty programs, or security research communities.

United States + 171 moreAll locations: United States | Canada | Brazil | Colombia | Argentina | Chile | Venezuela | Bolivia | Ecuador | French Guiana | Guyana | Paraguay | Peru | Suriname | Uruguay | Mexico | Costa Rica | El Salvador | Guatemala | Honduras | Nicaragua | Panama | Dominican Republic | Puerto Rico | Bahamas | Guadeloupe | Haiti | Jamaica | Martinique | Montserrat | United Kingdom | Germany | France | Estonia | Portugal | Hungary | Poland | Ukraine | Romania | Bulgaria | Czechia | Slovakia | Belarus | Moldova | Sweden | Greece | Belgium | Italy | Ireland | Switzerland | Netherlands | Finland | Malta | Denmark | Lithuania | Croatia | Spain | Austria | Bosnia And Herzegovina | Iceland | Luxembourg | North Macedonia | Montenegro | Norway | Serbia | Slovenia | Albania | Cyprus | Latvia | Monaco | South Africa | Egypt | Algeria | Angola | Benin | Botswana | Burkina Faso | Burundi | Cameroon | Cabo Verde | Central African Republic | Chad | Congo | Côte D'ivoire | Democratic Republic of the Congo | Equatorial Guinea | Eritrea | Ethiopia | Gabon | Gambia | Ghana | Guinea | Guinea-bissau | Kenya | Lesotho | Liberia | Libya | Madagascar | Malawi | Mali | Mauritania | Mauritius | Mayotte | Morocco | Mozambique | Namibia | Niger | Nigeria | Réunion | Rwanda | Senegal | Seychelles | Sierra Leone | Somalia | Sudan | Eswatini | Tanzania | Togo | Tunisia | Uganda | Zambia | Zimbabwe | Georgia | Turkey | Israel | United Arab Emirates | Armenia | Azerbaijan | Bahrain | Iraq | Jordan | Kuwait | Lebanon | Oman | Qatar | Saudi Arabia | Palestine | Yemen | India | Japan | Philippines | Pakistan | Thailand | Singapore | Vietnam | Taiwan | Indonesia | Cambodia | Laos | Malaysia | Myanmar | South Korea | China | Afghanistan | Bangladesh | Bhutan | Kazakhstan | Kyrgyzstan | Maldives | Mongolia | Nepal | Sri Lanka | Tajikistan | Turkmenistan | Uzbekistan | Australia | Papua New Guinea | Kiribati | Palau | French Polynesia | Tuvalu | New Zealand
Job Closed
Jobgether logo

Senior Cloud & Identity Engineer

Jobgether

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1 We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

OtherRemoteH1B No Sponsor

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description This role is designed for a hands-on engineer who will lead and support secure, scalable cloud and identity solutions across enterprise platforms. You will work closely with architecture, security, and operations teams to design, deploy, and maintain identity systems, API integrations, and cloud infrastructure. The position emphasizes implementing Zero Trust principles, managing enterprise IdPs, and automating processes to improve efficiency and security. The ideal candidate is experienced in production deployments, enjoys solving complex technical challenges, and thrives in a collaborative environment that values innovation and continuous improvement. This role combines strategic planning with practical implementation, providing the opportunity to influence core infrastructure and identity architecture. You will also contribute to governance, monitoring, and performance optimization across cloud and integration systems. - Design, implement, and maintain enterprise identity and access management (IAM) solutions, including SSO, SCIM, RBAC, and authentication protocols (OAuth2, OIDC, SAML). - Build and support REST API integrations and middleware platforms, ensuring secure authentication flows, logging, monitoring, and troubleshooting. - Manage cloud infrastructure in AWS and/or Azure, including IAM roles, secure networking, and Infrastructure as Code (Terraform, ARM, CloudFormation). - Troubleshoot integration, authentication, and cloud infrastructure issues while maintaining clear documentation and environment standards. - Collaborate with architecture and security teams to ensure system reliability, compliance, and scalability. - Contribute to greenfield initiatives, CI/CD pipeline implementations, and enterprise-scale governance frameworks where applicable. Qualifications - 3+ years implementing enterprise IAM or Zero Trust solutions in production environments. - Proven experience in cloud infrastructure deployments and API integrations. - Strong scripting and automation skills to manage systems and integrations. - Hands-on experience with identity providers such as Okta, Entra ID, or Ping. - Familiarity with authentication protocols and standards (OAuth2, OIDC, SAML, JWT). - Experience with cloud platforms (AWS, Azure) and Infrastructure as Code tools (Terraform, ARM, CloudFormation). - Excellent problem-solving and documentation skills. - Nice to have: experience in event-driven architecture, leading greenfield projects, or implementing enterprise-scale governance frameworks. Benefits - 💻 Flexible Work – Remote or hybrid options available. - 💰 Competitive Compensation – $130,000–$140,000 USD annual range, with performance-based bonuses. - 🏥 Health Coverage – Medical, dental, and vision plans, including fully company-paid HDHP options. - 🌴 Paid Time Off – Flexible time off, paid holidays, and parental leave programs. - 📈 Professional Growth – Continuous learning, leadership programs, and development funds. - ⚡ Wellness Support – Mental health resources, wellness stipends, and personalized coaching. - 🤝 Engagement – Team-building events, recognition programs, and volunteer opportunities. Company Description

United States
Job Closed