Design Your Dream Team
Security Consultant – Staff
Location
Maryland + 1 moreAll locations: Maryland | Virginia
Posted
3 days ago
Salary
0
Seniority
Lead
Job Description
Security Consultant – Staff
HIKINEX
• We are seeking a Security Consultant (Staff) to provide security leadership and guidance across application modernization and database migration workstreams. • This role will establish security, logging, observability, and compliance standards while ensuring the modernized environment aligns with public sector and healthcare data protection requirements. • As the primary security resource supporting multiple workstreams, the consultant will focus on defining patterns, governance, and best practices rather than implementing every security control directly. • Define and oversee security, logging, and observability standards throughout modernization and migration efforts • Establish secure architecture patterns for AWS-based target environments • Develop and promote IAM, secrets management, and least-privilege access strategies • Ensure proper handling and protection of PHI and PII data within healthcare and Medicaid-related systems • Advise teams on compliance requirements applicable to state government workloads • Review application security controls, authentication and authorization approaches, and secure coding practices • Assess converted database access patterns and connection security, including Aurora PostgreSQL endpoints • Provide guidance on encryption, monitoring, logging, and auditability requirements • Support risk identification, remediation planning, and security governance activities • Collaborate with technical teams to embed security best practices throughout the delivery lifecycle
Job Requirements
- Security & Application Modernization
- Strong experience performing secure code reviews and application security assessments
- Expertise with ASP.NET Core security best practices
- Experience migrating authentication and authorization frameworks, including: Forms Authentication System.Web.Security Membership ASP.NET Core Identity OIDC / OAuth 2.0 JWT-based authentication
- Knowledge of: CORS configuration Anti-forgery protections ASP.NET Core Data Protection APIs (MachineKey replacement)
- AWS Security
- Hands-on expertise with: IAM Roles and Policies AWS Secrets Manager AWS Systems Manager Parameter Store AWS Key Management Service (KMS) Security Groups AWS WAF Amazon GuardDuty AWS CloudTrail
- Experience securing cloud-native applications and database workloads
- Observability & Monitoring
- Experience implementing structured logging solutions using: Serilog Microsoft.Extensions.Logging
- Knowledge of: OpenTelemetry CloudWatch Logs CloudWatch Metrics Distributed tracing and correlation IDs across modernized application stacks
- Data Protection & Compliance
- Experience supporting environments containing PHI and PII
- Knowledge of: Encryption in transit (TLS) Encryption at rest Database and field-level protection strategies
- Familiarity with healthcare and government compliance requirements, including: HIPAA NIST 800-53 State government security frameworks StateRAMP and FedRAMP concepts
- Preferred Qualifications AWS Certified Security – Specialty certification
- Prior experience supporting Medicaid, healthcare, health-and-human-services, or other public sector programs
- Experience securing large-scale modernization or cloud migration initiatives
- Familiarity with AWS-based application modernization and database migration projects
Benefits
- Important Screening Requirements
- Due to client and clearance requirements
- Candidates must be U.S. Citizens or U.S. Permanent Residents (Green Card holders) and able to work in the United States without current or future visa sponsorship.
- Undergo fingerprinting as part of the onboarding process
- Successfully complete a government background investigation (CJIS-type clearance)
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Lead Cybersecurity Assessor / SCSEM Methodology Lead
eTelligent Group LLCOver the past 15 years, eTel has delivered essential solutions for the federal government by securing and managing data, providing scalable identity access, modernizing legacy systems, and building high-performance platforms. By integrating new technologies and ensuring reliable operations we help agencies stay prepared for future challenges. eTel offers integrated CMMI Level 3 processes, tools, and techniques with innovative, cost-efficient, and secure solutions to address complex challenges. eTel holds ISO 9001:2015, ISO/IEC 27001:2013, and ISO/IEC 20000-1:2018 certifications. Offers dedicated subject matter experts (SMEs) and thought leaders that possess a deep understanding of customers’ environments and challenges.
Role Description Senior hands-on technical lead for security assessment execution and for developing and validating the SCSEMs and automated evaluation files that drive every review. Distinct from the Computer & Information Systems Manager: this role is the deep technical author/assessor rather than the team manager. Key Responsibilities - Develop, update, and validate SCSEMs and automated evaluation files (Nessus audit / SCAP XCCDF), mapping to CIS Benchmarks, DISA STIGs, and applicable NIST controls. - Validate that automated checks accurately reflect required configurations and correctly evaluate both binary and non-binary conditions. - Lead hands-on system configuration checks and automated/manual compliance scanning during reviews. - Perform corrective actions and ad hoc fixes for identified issues, including logic errors in automated evaluation files. - Maintain configuration instructions and supporting documentation; ensure alignment between SCSEMs and automated files. Qualifications - Demonstrated experience identifying and applying information-security/cybersecurity requirements and ensuring they are addressed through development, implementation, and configuration. - Demonstrated experience implementing security controls, configuration changes, software/hardware updates, and vulnerability management within government organizations. - Hands-on experience securing configurations and authoring or tailoring SCSEM/STIG/CIS/Nessus content (preferred). Requirements - High School Diploma or higher. - Certifications / Licenses (minimum of ONE of the following): - CCNA Security - CySA+/CSA+ - GICSP - GSEC - Security+ CE - CND - SSCP - CASP+ CE - CCNP Security - CISA - CISSP (or Associate) - GCED - GCIH - CCSP - CAP - CISM - GSLC - CCISO - HCISPP - CEH - GSNA - CFR - PenTest+ - In lieu of a certification, graduation from a minimum 2-year IT/Cybersecurity program at an accredited college or university may be substituted. Preferred - Prior FTI/Safeguards review experience; demonstrated SCSEM/STIG/CIS/Nessus authoring. Commitment to Diversity eTelligent Group provides equal employment opportunities (EEO) to all applicants without regard to race, color, religion, gender, sexual orientation, gender identity, nations origin, age, disability, genetic information, marital status, amnesty, status as a covered veteran, and any other characteristic provided in accordance with applicable, federal, state and local laws.
Senior Security Engineer, Product AppSec
Veeam SoftwareYour Single Backup and Data Management Platform for Cloud, Virtual and Physical
• Evaluate, deploy, integrate, and optimize security tooling — including SAST, DAST, SCA, IAST, container scanning, SBOM generation, secrets detection, and API security testing — across CI/CD pipelines and developer workflows • Build automated workflows for vulnerability ingestion, prioritization, remediation tracking, and reporting, integrating with platforms such as GitHub Actions, Azure DevOps, Jenkins, Jira, and SIEM tools • Drive enterprise vulnerability management initiatives, including prioritization frameworks, SLA tracking, remediation velocity improvements, and security posture dashboards • Embed security-by-design principles into the SDLC, developing security guardrails and policy-as-code capabilities for cloud and application environments • Partner with DevOps and CI/CD teams to improve automated security validation, release governance, and software supply chain security • Serve as a senior technical advisor on application security, influencing engineering and product roadmaps to improve platform security and operational resilience • Mentor engineers and security practitioners on secure development and DevSecOps best practices
• Lead and execute the IT SOX program, including annual scoping, risk assessments, control design, testing strategy, and deficiency remediation • Own and continuously improve the IT General Controls (ITGC) framework (Access, Change Management, Operations, SDLC) ensuring alignment with SOX and COSO standards • Serve as the primary liaison to Internal and External Audit, driving efficient audit execution and high-quality outcomes • Partner closely with Finance and Internal Audit to co-develop control narratives, risk assessments, and audit committee materials • Drive the evolution of the Enterprise Risk Management (ERM) program for IT and Cybersecurity risks, including facilitating cross-functional risk workshops and maintaining the enterprise risk register • Translate technical risks into business-relevant insights and provide clear reporting to executive stakeholders, including the CIO and Audit Committee • Lead risk lifecycle activities including risk identification, assessment, mitigation planning, and ongoing monitoring • Establish and track key risk indicators (KRIs) and key performance indicators (KPIs) to measure program effectiveness and inform decision-making • Author and maintain IT and cybersecurity policies, standards, and procedures to ensure compliance with regulatory and industry frameworks • Evaluate and integrate GRC tools, automation, and analytics to enhance control monitoring and reporting capabilities • Review and assess third-party risk through SOC1/SOC2 and other service provider assurance reports • Lead and develop a small team (or provide functional leadership), fostering growth, accountability, and high performance • Drive cross-functional initiatives and special projects that strengthen governance, risk posture, and operational resilience
Security Engineer III, Product AppSec
Veeam SoftwareYour Single Backup and Data Management Platform for Cloud, Virtual and Physical
• Monitor, assess, and manage security risks related to open-source software dependencies, CVEs, and third-party components • Triage and validate vulnerabilities across applications, containers, infrastructure, and dependencies — prioritizing by exploitability, exposure, and business impact • Coordinate patch management initiatives and support automated patch deployment workflows with Release Engineering and DevOps teams • Support and expand the Security Champion program, partnering with developers to improve secure coding awareness and adoption • Integrate security controls into CI/CD pipelines and automate vulnerability scanning, dependency analysis, and security reporting • Develop playbooks, documentation, and educational materials that promote self-service security within engineering teams • Contribute to threat modeling, secure architecture discussions, and continuous improvement of secure SDLC processes


