Booz Allen Hamilton is an award-winning provider of strategic innovation, management consulting, technology, and engineering services. Founded in 1914, the comp
Cybersecurity and Risk Management Framework Engineer, Lead
Location
Texas + 1 moreAll locations: Texas | Virginia
Posted
84 days ago
Salary
$112.8K - $257K / year
Seniority
Lead
Job Description
Cybersecurity and Risk Management Framework Engineer, Lead
Booz Allen Hamilton
Risk Management Framework Locations Arlington, VA San Antonio, TX Full time job requisition id R0238707 Job Description: Cybersecurity and RMF Engineer, Lead The Opportunity: Are you looking for an opportunity to share your experience in cyber security and systems engineering that will support the US Air Force? As a systems security and network security engineer, you can identify the tools needed to assess vulnerabilities and recommend the best solution and security strategy. We need your experience to oversee the development and implementation of security solutions that will protect our military. On our team, you'll supervise a team as they troubleshoot and analyze complex challenges for customers using your knowledge of network and security devices, applications, and identifying tools. You'll manage the research of technology and market trends to further develop security solutions. Using your expertise in Low Code/No Code systems and security protocols, you'll assess security threats and implement infrastructure controls. In this role, you'll directly impact Air Force human capital management by helping to secure our nation's human capital systems. With mentoring, challenging hands-on problem-solving, and opportunities to learn new tools and skills, we focus on growing as a team to make the best solutions for our customers. Work with us as we secure and protect the Air Force for the better. What You'll Work On: - Develop relationships quickly and easily with other teams, communicating the complexities of security with a wide variety of audiences, including senior management. - Manage infrastructure and cyber security controls, including enhanced detection and vulnerability capabilities and improved event correlation in large enterprises. - Lead risk and vulnerability assessments in network, system, and application areas; leverage big data analytics and traditional security event types to identify advanced threats or indicators of compromise. Join us. The world can't wait. You Have: - 8+ years of experience with RMF, NIST 800-53, Zero Trust, STIGs, vulnerability management, ATO packages, POA&Ms, continuous monitoring, or secure cloud - 5+ years of experience as an Information Systems Security Officer (ISSO), Information Systems Security Engineer (ISSE), or Information Systems Security Manager (ISSM) - 2+ years of experience setting-up or working with DevSecOps pipeline security tools, scanning, and reporting - 2+ years of experience with supporting and helping configure in a DevOps team - Experience in cybersecurity engineering and RMF alignment for the solution, supporting secure architecture, controls implementation, scanning, evidence generation, POA&M tracking, and continuous monitoring in IL5-ready environments with scalability to higher controls - Ability to work with development teams to select the most suitable controls - Secret clearance - HS diploma or GED Nice If You Have: - Experience with developing SSP or ATO packages for systems deployed in a Microsoft Azure, AWS, or DoD Cloud environment - Bachelor's degree - Amazon Web Service (AWS), Microsoft Azure, or Google Cloud Service Provider Certification - DoD 8570 IAM II or higher Certification, such as SecurityX, CISM, or CISSP Certification - DoD Directive 8570.01-M for IASAE Level III Certification, such as CISSP-ISSAP, CISSP-ISSEP, or CCSP Certification Clearance: Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; Secret clearance is required. Compensation At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen's benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page. Salary at Booz Allen is determined by various factors, including but not limited to location, the individual's particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $112,800.00 to $257,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen's total compensation package for employees. This posting will close within 90 days from the Posting Date. Identity Statement As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud. Candidate AI Usage Policy AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided. Work Model Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings. - Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility. - Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility. - Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role. Commitment to Non-Discrimination All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Principal Network Security Engineer
Huntington National BankSine 1866, Huntington National Bank has served midwestern communities with banking and financial services for consumers and businesses of all sizes. The regiona
Title: Principal Network Security Engineer - Location: 999 Peachtree Street NE Atlanta, GA 222 North LaSalle St Chicago, IL 8214 Westchester Dr Dallas, TX 7 Easton Oval Columbus, OH 7906 North Sam Houston Parkway West Houston, TX 2025 Woodward Ave Detroit, MI 101 South Tryon Street Charlotte, NC - Reference Number:R0071244 Job Description: This position is onsite and available to be filled at any Huntington Corporate office location (see location options on posting) Summary: The Principal Network Security Engineer provides technical and engineering expertise for the Network Security Department. Will demonstrate their expertise on provisioning, supporting, and ongoing maintenance of Network Security operating platforms, applications and services. Is responsible for providing and implementing the technological solutions and configurations that are in alignment with the overall enterprise Network Security strategy and objectives. Provide management, design, and support for Internet proxy systems and enterprise web browser systems. Duties & Responsibilities: - Conduct security engineering necessary to maintain the confidentiality, availability, and integrity of enterprise data and information systems. - Provide excellent customer service for internal and external customers in support of security initiatives, incident response, and support. - Evaluate, design, and implement security related solutions, adhering to established change control processes. - Lead the design, implementation, and delivery of Network Security applications and appliances, including NGFWs, IDS/IPS, Anti-virus, Web Application Firewalls, etc. - Lead the Security Architecture and/or senior level enterprise engineering programs and committees. - Maintain a high level of technical expertise on Network Security defense-in-depth technology and best practices by performing ongoing research and engagement to maintain awareness of industry trends, best practices. - Other duties as assigned. Basic Qualifications: - 8+ years of production support and design of Network Security technologies. - 8+ years of operational experience with security technologies. - 8+ years of implementing or utilizing technology lifecycles and best practices. - Associate's Degree or 4+ additional years of equivalent experience. Preferred Qualifications: - 5+ years of experience with web URL filtering, browser security, and/or remote browser isolation. (iBoss, Zscaler, or Netskope, etc) - 2+ years of professional experience with secure enterprise internet browsers - Expert level knowledge of core networking protocols including BGP, DNS, HTTP/S, DNS, etc... - Expert level knowledge of operating systems, e.g. Windows, Linux, & Unix - Expert level network troubleshooting skills utilizing packet capture/analysis packages such as Wireshark, TCPdump, etc… - Excellent customer facing communication skills (both written and verbal) - Experience writing professional level documentation covering topics related to networking or application Network Security technologies. These include design and implementation documents, process documents, SLAs, etc. Exempt Status: (Yes = not eligible for overtime pay) (No = eligible for overtime pay) Yes Workplace Type: Office Our Approach to Office Workplace Type Certain positions outside our branch network may be eligible for a flexible work arrangement. We're combining the best of both worlds: in-office and work from home. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. Remote roles will also have the opportunity to come together in our offices for moments that matter. Specific work arrangements will be provided by the hiring team. Compensation Range: $93,000 - $189,000 Annual Salary The compensation range represents the anticipated low and high end of the base compensation range for this position. Actual compensation will vary based on various factors including but not limited to location, experience, and education. Colleagues in this position are also eligible to participate in an applicable incentive compensation plan. In addition, Huntington provides a variety of benefits to colleagues, including health insurance coverage, wellness program, life and disability insurance, retirement savings plan, paid leave programs, paid holidays and paid time off (PTO). Huntington is an Equal Opportunity Employer. Tobacco-Free Hiring Practice: Visit Huntington's Career Web Site for more details. Note to Agency Recruiters: Huntington will not pay a fee for any placement resulting from the receipt of an unsolicited resume. All unsolicited resumes sent to any Huntington colleagues, directly or indirectly, will be considered Huntington property. Recruiting agencies must have a valid, written and fully executed Master Service Agreement and Statement of Work for consideration.
Cybersecurity Lead
LeidosLeidos is an innovation company rapidly addressing the world’s most vexing challenges in national security and health.
• Delivering timely and accurate development of cyber artifacts needed for the program • Lead cybersecurity efforts for specific software development and engineering projects • Develop the cybersecurity requirements to be included in and allocated to the product baseline(s) • Assess, document, and report on the cybersecurity posture of various systems. • Develop and implement cyber mitigation strategies in response to identified vulnerabilities • Managing the cybersecurity policies, best practices, controls, and technologies used to secure applications, data, and infrastructure in cloud environments • Creating a framework for integrating security measures and controls into the design and implementation of a software solution • Identifying and prioritizing potential threats to a system, application, or organization • Accurately monitor, track, and report on cybersecurity project status to internal and external stakeholders • Coordinates with Leidos PMO and customer stakeholders to prioritize cybersecurity tasks
Security Engineer – Cybersecurity Posture, Hygiene & AI Enablement
AbbVieA biopharmaceutical company based in Chicago, Illinois, AbbVie makes and markets advanced therapies and medicines to treat serious illnesses and medical conditi
• design, develop, and implement security controls and solutions that enhance AbbVie’s security hygiene • ensure that security measures are effectively integrated into IT systems and applications • collaborate with IT, network, and other relevant departments to align security measures with organizational goals and compliance requirements • partner with platform and application teams to establish clear security baseline requirements, following the Center for Internet Security Critical Security Controls (CIS 18) • utilize existing enterprise tools dedicated to vulnerability management, asset inventory, and cyber hygiene to ensure that all assets meet established security baseline requirements • develop custom integrations using APIs or other scripting tools for high-risk applications to enable proactive monitoring of critical security controls • demonstrate a foundational understanding of how artificial intelligence (AI) and machine learning technologies work, including their strengths, limitations, and common enterprise use cases, particularly as they relate to cybersecurity • leverage AI-enabled tools and capabilities to improve security posture and hygiene outcomes, such as enhancing visibility, identifying configuration drift, prioritizing risk, or accelerating analysis and decision-making • lead posture and hygiene efforts to effectively drive and complete initiatives successfully. This includes coordinating stakeholders, setting clear objectives, and maintaining sustained focus on improving the organization’s security posture • manage documentation such as baselines, Standard Operating Procedures (SOPs), policies, and work instructions in accordance with AbbVie requirements, ensuring accuracy, currency, and alignment with organizational standards
• Deliver high-impact security engineering solutions across detection and platform engineering service streams • Design and implement detection capabilities, automate security workflows, and enhance security platform infrastructure • Lead incident response coordination and act as escalation point for security incidents across Canva's cloud-native infrastructure, including participation in on-call rotation • Investigate and triage security alerts, coordinating containment, eradication, and recovery activities across a range of security events • Lead and contribute to post-incident reviews, translating incident learnings into improved detections, playbooks, and response processes • Build and maintain automation workflows and response playbooks that streamline investigation, triage, and response, reducing analyst toil and improving mean-time-to-respond • Partner with CTI, Application Security, and Red Team to turn threat intelligence and emerging risks into practical detection and response outcomes • Develop and improve security response tooling and capabilities across areas including case management, automation, SOAR, SIEM, and forensics




