Job Closed

This listing is no longer active.

eSimplicity logo
eSimplicity

An engineering firm that delivers high-quality Healthcare IT, Cybersecurity, and Telecommunication solutions.

Senior Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 51-200Since 2016H1B No SponsorCompany SiteLinkedIn

Location

Maryland

Posted

4 days ago

Salary

0

Seniority

Senior

Bachelor Degree8 yrs expEnglishAWSCloudJenkinsPythonSplunkTerraform

Job Description

Senior Security Engineer

eSimplicity

• Designing, implementing, and maintaining security controls across the Salesforce-based MESH platform and AWS cloud environment in accordance with CMS Acceptable Risk Safeguards (ARS) 5.1, FedRAMP Moderate, and NIST SP 800-53 Rev 5 • Embedding security into the DevSecOps CI/CD pipeline by integrating SAST, DAST, IAST, and software composition analysis tools (e.g., Snyk, AppOmni, Tenable, AWS Security Hub) into GitHub Actions and Copado workflows • Operating the end-to-end vulnerability management lifecycle including detection, triage, prioritization, remediation tracking, and reporting; ensuring critical and high findings are remediated within CMS/HHS-defined timeframes • Performing and documenting Security Impact Analyses (SIAs) for proposed changes to the MESH platform and integrations such as T-MSIS, MBES/MacFin, Microsoft 365, and CMS DataConnect • Authoring, maintaining, and updating Authority to Operate (ATO) artifacts in CFACTS, including System Security Plans (SSPs), POA&Ms, Privacy Impact Assessments, Contingency Plans, and Incident Response Plans • Hardening Salesforce GovCloud configurations by enforcing role-based access, permission sets, OAuth/MFA, and Salesforce Shield controls; reviewing third-party AppExchange packages for security risk prior to installation • Configuring and tuning continuous monitoring and detection tooling (Splunk, AWS GuardDuty, CloudTrail, Security Hub) and leading incident response from detection through post-mortem review • Leading least-privilege access reviews and identity lifecycle workflows across CMS IDM/Okta, EUA, AWS IAM, Salesforce, and CI/CD pipelines; automating recurring access reviews and onboarding/offboarding tasks • Building dashboards and reports in Splunk, Power BI, or Jira that give CMS leadership and product teams visibility into vulnerabilities, compliance posture, access reviews, and audit readiness • Translating CMS, HHS, and federal AI governance requirements into actionable secure design patterns for AI/ML capabilities embedded in MESH (e.g., AI-assisted submission analysis, NLP search, predictive analytics) • Participating in Agile ceremonies as a security subject matter expert, ensuring user stories include clear security acceptance criteria and that security enablers are represented in the team Definition of Done • Mentoring developers, QA, and DevOps engineers on secure coding practices (OWASP ASVS), threat modeling, and continuous compliance • Cooperating with CMS-directed audits, penetration tests, and 3PAO assessments; coordinating responses to agency security data calls within required timeframes

Job Requirements

  • All candidates must pass public trust clearance through the U.S. Federal Government.
  • Bachelor’s degree in Computer Science, Information Systems, Engineering, or other related scientific or technical discipline
  • 8+ years of hands-on security engineering experience supporting cloud-hosted federal information systems
  • Demonstrated experience implementing and maintaining ATOs under CMS or HHS, including authoring SSPs, POA&Ms, and continuous monitoring artifacts in CFACTS or equivalent GRC tooling
  • Strong working knowledge of NIST RMF, NIST SP 800-53 Rev 5, FedRAMP Moderate baseline, and CMS ARS 5.1 controls
  • Hands-on experience with AWS security services (IAM, GuardDuty, CloudTrail, Security Hub, KMS, Config) and Salesforce security best practices (profiles, permission sets, Salesforce Shield, OAuth/MFA, AppOmni)
  • Experience integrating security gates into CI/CD pipelines using GitHub Actions, Copado, Jenkins, Terraform, or equivalent
  • Hands-on configuration and tuning of vulnerability and security testing tools such as Snyk, Tenable Nessus, Invicti, OWASP ZAP, AppOmni, and Splunk
  • Hands-on scripting and automation skills (Python, Bash, PowerShell, REST APIs)
  • Working knowledge of FIPS 140 validated encryption, HIPAA, the Privacy Act of 1974, and Section 508 considerations as they apply to federal information systems
  • Experience with Atlassian Jira and Confluence and CMS-style agile delivery environments

Benefits

  • medical, dental, and vision coverage
  • 401(k) retirement benefits
  • paid time off
  • paid holidays
  • life and disability insurance
  • additional wellness and employee support programs

Related Categories

Related Job Pages

More Security Engineer Jobs

365id logo

Principal Product Security Engineer

365id

Global ID Verification | Verify your customer’s identity | Transfer data to your CMS | Avoid Fraud

Full TimeRemoteTeam 11-50Since 2015H1B No Sponsor

• Own and mature the product security program, including security review processes, secure development standards, risk prioritization, vulnerability remediation practices, and engineering enablement. • Lead security architecture reviews and secure design initiatives across backend services, web applications, mobile applications, APIs, and remote devices. • Review source code and application architecture to identify security vulnerabilities, insecure patterns, and operational risks. • Partner closely with Engineering, DevOps, QA, Infrastructure, and Product teams to integrate security into the software development lifecycle. • Establish and enforce secure coding standards, development guidelines, and security best practices. • Mentor and guide software engineers on secure development practices and remediation strategies. • Perform threat modeling and risk assessments for new and existing products and infrastructure. • Assist in incident response investigations, root cause analysis, and remediation planning. • Evaluate third-party libraries, frameworks, and dependencies for security and operational risks. • Collaborate with DevOps and Infrastructure teams on cloud security, CI/CD security, secrets management, and system hardening. • Drive vulnerability management efforts, including prioritization, remediation guidance, and validation. • Help define and implement logging, monitoring, and security alerting strategies. • Partner with external security consultants and vendors on penetration testing and security assessments. • Promote a security-first engineering culture across the organization.

United States
Map Ssg logo

Founding Security Engineer

Map Ssg

A venture-backed startup building a modern data platform for the real estate industry, enabling automation, analytics, and AI-powered workflows for real estate operators. The team includes engineers and leaders from companies such as major fintech, cloud, and consumer technology platforms, and is focused on solving complex infrastructure and data challenges in a large, underserved industry.

Role Description This is the company’s first dedicated security hire. You will define and build the company’s security program from scratch, working directly with a security-minded co-founder. This role spans product security, application security, corporate security, compliance, incident response, and detection. Over time, this person may build and lead the security function. - Own the company’s security posture across product, infrastructure, and internal systems - Lead security reviews, threat modeling, and secure design work - Build foundational security systems such as secrets management, audit logging, vulnerability management, and certificate infrastructure - Drive compliance programs such as SOC 2, ISO 27001, GDPR, and CCPA - Define incident response processes and detection capabilities - Partner closely with engineering to embed security into product development - Help shape security culture across a small, high-caliber team Qualifications - 5+ years of security engineering experience - Strong application security background - Experience with secure SDLC, threat modeling, vulnerability management, and security architecture - Experience contributing to or running security programs - Compliance experience, ideally SOC 2, ISO 27001, GDPR, or similar - Backend or systems engineering fluency; Go experience is a plus - Ability to operate with high ownership in an early-stage environment - Low-ego, collaborative mindset and willingness to wear multiple hats Nice to Have - First or second security hire experience at a startup - Detection engineering experience - Identity, access management, enterprise IT, or security software background - Kubernetes, GCP, cloud security, or infrastructure security experience - Published security research, talks, or open-source security work

United States
$180K - $230K / year
Job Closed
NIR-YU logo

Cloud Security Consultant – Access Controls

NIR-YU

Take Control of Your Business and Execute Your Vision with Ease - Hire Affordable and Qualified Nearshore Staff

ContractRemoteTeam 201-500H1B No Sponsor

• Gestionar el acceso de usuarios, roles y aprovisionamiento utilizando controles de acceso basados en roles

Mexico
Full TimeRemoteTeam 5,001-10,000H1B Sponsor

• Designing and implementing runtime security controls that protect inference execution environments against adversarial inputs, model extraction, and unauthorized access • Conducting threat modeling and security assessments of inference serving frameworks, model loading pipelines, and GPU execution environments • Hardening model serving infrastructure including container isolation, runtime sandboxing, and supply chain integrity for model artifacts and dependencies • Developing automated security testing and monitoring for inference workloads to detect anomalous behavior, data exfiltration, and prompt-based attacks • Collaborating with platform and model intelligence teams to establish security standards across the full inference lifecycle from model ingestion to production serving

Poland