General Dynamics logo
General Dynamics

General Dynamics is a global aerospace and defense company offering products designed to provide safety and security to people around the world. In the past, General Dynamics has p

Senior Information Security Advisor - AWS

Location

Virginia

Posted

14 days ago

Salary

$140.3K - $189.8K / year

Seniority

Senior

Job Description

Senior Information Security Advisor - AWS

General Dynamics

Title: Sr Information Security Advisor /AWS (Secret Cleared) Location: USA VA Fairfax - 2677 Prosperity Ave (VAC779) Work Type: Hybrid, Full Time Job ID: RQ213364 Job Description: Type of Requisition: Regular Clearance Level Must Currently Possess: Secret Clearance Level Must Be Able to Obtain: Secret Public Trust/Other Required: None Job Family: Cyber and IT Risk Management Job Qualifications: Skills: Data Security, Information Assurance, Information Security, System Security Certifications: AWS Certified Security - Specialty | Amazon Web Services (AWS) - Amazon Web Services (AWS), Certified Cloud Security Professional (CCSP) | International Information System Security Certification Consortium (ISC2) - International Information System Security Certification Consortium (ISC2), Certified Ethical Hacker (CEH) | EC-Council - EC-Council, Certified Information Systems Security Professional (CISSP) | International Information System Security Certification Consortium (ISC2) - International Information System Security Certification Consortium (ISC2) Experience: 8 + years of related experience US Citizenship Required: Yes Job Description: Information Security Analyst Sr Advisor Transform technology into opportunity as an Information Security Analyst Sr Advisor with GDIT. A career in enterprise IT means connecting and enhancing the systems that matter most. At GDIT you’ll be at the forefront of innovation and play a meaningful part in improving how agencies operate. At GDIT, people are our differentiator. As an Information Security Analyst Sr Advisor you will help ensure today is safe and tomorrow is smarter. Our work depends on Information Security Analyst Sr Advisor joining our team to protect and defend critical law enforcement information systems and data. The successful candidate will be responsible for designing, implementing, and managing security measures across on-premises and cloud-based environments in compliance with policy and other applicable security standards. This role requires deep cybersecurity expertise and experience securing sensitive law enforcement data in highly regulated environments. HOW AN INFORMATION SECURITY ANALYST SR ADVISOR WILL MAKE AN IMPACT ● Performs all procedures necessary to ensure the safety of information threat detection /prevention systems assets and to protect systems from intentional or inadvertent access or destruction - Integrate and correlate logs from firewalls, intrusion detection/prevention systems (IDS/IPS), and endpoint security tools for holistic situational awareness. ● Mentor the IT services team to achieve leadership in our cybersecurity posture ●Monitor, analyze systems and identify security issues for remediation, for example Splunk Enterprise Security ● Provide information assurance project management, technical security staff oversight, and development of mission critical technical documents ● The customer mission of national law enforcement requires cybersecurity compliance ● Ensure compliance with FISMA, NIST SP 800-53, and state/federal agency standards. - Conduct internal audits using tools such as Nessus to identify vulnerabilities and validate compliance. - Design and implement security controls in AWS GovCloud and secure on-prem environments. - Maintain secure Identity and Access Management (IAM) policies; manage roles and policies using AWS IAM or Okta. - Enforce secure data handling practices and monitor access to sensitive or classified data repositories. ● Education: Technical Training, Certification(s) or Degree: Bachelors degree ● Required Experience: Minimum of 5 years of experience in information security, with at least 2 years in a government or law enforcement environment. WHAT YOU’LL NEED TO SUCCEED: ● Required Technical Skills: Comprehensive knowledge of data security administration principles, methods, and techniques including both on-premises and cloud - Requires familiarity with domain structures, user authentication, and digital signatures - Requires understanding of firewall theory and configuration - Knowledge of NIST, FISMA, and FedRAMP compliance standards. Preferred Skills: One or more security related certifications like ISACA CISA, (ISC)2 CISSP, and/or CEH, CCSP, AWS Certified Security – Specialty ● Location: Hybrid ● U.S. Citizenship with the ability to pass a comprehensive background check and obtain/maintain agency fitness eligibility or other applicable security clearances. Clearance: Secret GDIT IS YOUR PLACE: ● Full-flex work week to own your priorities at work and at home ● 401K with company match ● Comprehensive health and wellness packages ● Internal mobility team dedicated to helping you own your career ● Professional growth opportunities including paid education and certifications ● Cutting-edge technology you can learn from ● Rest and recharge with paid vacation and holidays The likely salary range for this position is $140,250 - $189,750. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range. Scheduled Weekly Hours: 40 Travel Required: None Additional Work Locations: Total Rewards at GDIT: Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

Related Categories

Related Job Pages

More Security Engineer Jobs

GoMining logo

Security Operations Engineer

GoMining

We make Bitcoin mining simple, accessible and fun.

Full TimeRemoteTeam 201-500Since 2017H1B No Sponsor

Role Description We are looking for a hands-on Security Operations Engineer to own and evolve our security posture across infrastructure, endpoints, and internal systems. You will be the primary driver of day-to-day security operations — from managing protective tooling to responding to incidents and coordinating audits. This is a high-ownership role with direct impact on how the company detects, responds to, and prevents security threats. - Security Systems Management: - Own the configuration, maintenance, and continuous improvement of security tooling across the organization — including DLP, MDM, SIEM, and endpoint protection platforms. - Ensure policies are enforced, coverage is complete, and tooling stays current with evolving threats and business needs. - Incident Management: - Act as the first responder for security incidents: triage alerts, investigate root causes, coordinate containment and remediation, and produce clear post-mortem reports. - Build and refine runbooks and playbooks to reduce response time and improve team readiness over time. - Infrastructure Security: - Partner with DevOps and Engineering teams to embed security across cloud infrastructure, Kubernetes workloads, CI/CD pipelines, and network layers. - Conduct regular reviews of IAM policies, secrets management, network segmentation, and access controls to identify and close gaps before they become incidents. - Audit & Penetration Testing: - Coordinate internal and external security audits, manage relationships with pentest vendors, and track remediation of findings through to closure. - Conduct ongoing vulnerability assessments and support compliance activities (SOC 2, ISO 27001, PCI DSS, or equivalent) by maintaining evidence and responding to auditor requests. Qualifications - Hands-on experience administering DLP platforms (Forcepoint, Symantec DLP, Teramind, Nightfall, or similar) — policy authoring, tuning, and alert management. - MDM administration experience: Jamf, Kandji, Microsoft Intune, or equivalent — device enrollment, compliance policies, remote wipe, certificate management. - Familiarity with PAM solutions (CyberArk, HashiCorp Vault, BeyondTrust) and secrets lifecycle management. - Email security tooling: DMARC/DKIM/SPF configuration, anti-phishing platforms (Proofpoint, Mimecast). - Network security fundamentals: firewall rule management, IDS/IPS configuration, zero-trust access models, VPN and ZTNA (Cloudflare Access, Tailscale, Zscaler). - Infrastructure-as-Code security scanning: Checkov, tfsec, KICS for Terraform/Helm/Kubernetes manifests. - Structured incident response methodology: NIST SP 800-61, PICERL, or equivalent framework. - Digital forensics basics: memory and disk image acquisition, log preservation and chain of custody, timeline reconstruction. - Threat intelligence platforms and feeds: MISP, OpenCTI, VirusTotal, Shodan — IOC enrichment and threat correlation. - Practical knowledge of MITRE ATT&CK framework for detection mapping and adversary emulation. - Vulnerability scanning and management: Nessus, Qualys, Wiz, Orca Security — prioritization, SLA tracking, and remediation coordination. - Pentest coordination: scoping, managing NDA/RoE, validating findings, tracking remediation through to closure. - Web application security fundamentals: OWASP Top 10, common API vulnerabilities, ability to validate findings from external researchers. Requirements - Experience in fintech, crypto, or another regulated industry. - Relevant certifications: OSCP, CEH, GCIA, GCIH, GWAPT, Security+, CISSP, AWS Security Specialty, or CKS (Certified Kubernetes Security Specialist). - Compliance frameworks: SOC 2 Type II, ISO 27001, PCI DSS — evidence collection, control mapping, auditor interaction. - Exposure to blockchain-specific security considerations: smart contract audit basics, wallet security, on-chain threat monitoring. - Experience operating or hardening Web3-facing infrastructure. - SIEM deployment and tuning: Splunk, Elastic SIEM, Microsoft Sentinel, or similar — writing detection rules, building dashboards, reducing false positive rates. - Bug bounty program management: HackerOne, Bugcrowd, or equivalent — triage, researcher communication, severity classification. Benefits - Learning support - courses, English classes, and conferences (up to 100% reimbursement). - Unique loyalty program - receive corporate digital miners and earn passive income with no investment. - Team culture: retreats in international locations (for example, company apartments in Cyprus). - Memorable events with wow prizes - we celebrate big occasions in a big way. - “Employee of the Month” award - we recognize and reward our top performers. - Paid leave: up to 28 vacation days + 8 company holidays + 5 personal days per year. - New career tracks - real opportunities to grow into expert or top management roles. - Work-life fit - flexible hours and remote work. You don’t need to chase balance - here, work is a part of life, not the opposite. We aim to make work inspiring, not exhausting. For us, results matter most.

Serbia
MAINSOFT logo

Subgerente de Ciberseguridad y Protección Digital

MAINSOFT

Llevamos la inteligencia artificial a tu negocio, con talento especializado y soluciones de software innovadoras.

Full TimeRemoteTeam 201-500Since 1993H1B No Sponsor

• Definir y liderar la estrategia integral de ciberseguridad y protección digital • Garantizar la protección de activos digitales y información sensible • Integrar seguridad desde el diseño (Security by Design) en desarrollos tecnológicos • Supervisar la seguridad en aplicaciones y acceso a sistemas • Establecer controles de seguridad en arquitecturas modernas

Colombia
Job Closed
Flywire logo

Senior Security Engineer, Application Security

Flywire

Delivering the most important & complex payments.

Full TimeRemoteTeam 1,001-5,000Since 2011H1B Sponsor

• Design, prompt-engineer, and deploy automated security review workflows, using for example Claude or other LLM APIs to perform real-time code analysis and architectural reviews within our CI/CD environment. • Lead secure design reviews and advanced threat modeling for our complex payment systems and AI integrated applications. • Act as a technical bridge between Security and Engineering teams. • Collaborate frequently with different engineering teams to identify and address security issues. • Oversee deep-dive technical reviews, moving beyond basic scans to perform source code audits and live application testing on high-risk features. • Contribute and take ownership for the automated security controls we are building and take an active part in every aspect of the secure software development lifecycle (S-SDLC). • Provide hands-on remediation guidance and mentor junior security or software engineers, also members of Product teams, on both traditional exploits and emerging AI-specific vulnerabilities.

India
Flywire logo

Senior Security Engineer I, Application Security

Flywire

Delivering the most important & complex payments.

Full TimeRemoteTeam 1,001-5,000Since 2011H1B Sponsor

• Act as a technical visionary, bridging the gap between robust defense and rapid innovation • Design, prompt-engineer, and deploy automated security review workflows • Lead secure design reviews and advanced threat modeling for complex payment systems and AI integrated applications • Collaborate frequently with different engineering teams to identify and address security issues • Oversee deep-dive technical reviews, moving beyond basic scans to perform source code audits and live application testing on high-risk features • Contribute and take ownership for the automated security controls we are building • Provide hands-on remediation guidance and mentor junior security or software engineers

India