SMX logo
SMX

Shared Vision. Outcome Assured.

Cyber Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteMid LevelTeam 1,001-5,000Since 1995H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

8 days ago

Salary

$103.1K - $1,718.2K / year

Seniority

Mid Level

Job Description

Cyber Security Engineer

SMX

Role Description The Cyber Security Engineer will provide security engineering, compliance, and risk management support for cloud-based systems aligned with NIST SP 800-53, FedRAMP, and DoD IL4–6 requirements. The role will advise partners and customers navigating government security requirements while supporting authorization, audit readiness, and continuous monitoring activities. A key focus will be improving compliance efficiency through GRC platforms, APIs, scripts, cloud-native services, and automation for evidence collection, control validation, documentation, reporting, and remediation tracking. This position is remote supporting a Herndon, VA based team. - Provide cybersecurity engineering and compliance support for FedRAMP and DoD-authorized cloud environments, including IL4–6. - Advise partners and customers on federal and DoD security requirements, authorization strategies, control implementation, and audit readiness. - Develop, review, and maintain authorization documentation, including SSPs, SAPs, SARs, POA&Ms, FedRAMP appendices, policies, and supporting evidence. - Support system authorization and reauthorization activities across FedRAMP/RMF, including gap assessments, control validation, evidence development, and remediation planning. - Leverage GRC platforms, APIs, scripts, and automation to streamline compliance workflows, evidence collection, documentation updates, control testing, and reporting. - Develop repeatable and auditable processes that reduce manual compliance effort and improve the accuracy and consistency of authorization artifacts. - Collaborate with cloud engineering and DevOps teams to design, implement, and validate security controls across AWS, Azure, and hybrid environments. - Review system changes and significant change requests to assess security impact, identify documentation updates, and maintain authorization boundaries. - Coordinate with system owners, engineers, 3PAOs, Authorizing Officials, and government stakeholders to address findings and support authorization outcomes. - Support continuous monitoring, vulnerability management, POA&M updates, remediation tracking, and recurring compliance deliverables. - Evaluate security tooling and data sources to identify opportunities for automated control validation and compliance reporting. - Track evolving federal cybersecurity requirements and translate them into practical technical and operational actions. Qualifications - Strong analytical, documentation, and problem-solving skills with a focus on secure and compliant outcomes. - Excellent communication and stakeholder-management skills, including the ability to advise partners, customers, engineers, and government stakeholders. - Ability to translate federal security requirements into practical technical controls and operational processes. - U.S. citizenship with the ability to obtain and maintain a Secret or higher security clearance. - Bachelor’s degree in Information Security, Cybersecurity, Computer Science, or a related field, or equivalent practical experience. - Five or more years of cybersecurity experience, including at least three years supporting federal cloud security engineering, information assurance, RMF, or ISSO functions. - Knowledge of NIST SP 800-53 Rev. 5, FedRAMP Moderate and High, DoD IL4–6 overlays, RMF, and related federal compliance frameworks. - Experience developing and maintaining SSPs, POA&Ms, SARs, policies, control evidence, and other authorization artifacts. - Experience supporting authorization planning, gap assessments, audit readiness, control implementation, and remediation activities. - Hands-on experience with AWS, Azure, or hybrid cloud environments, including IAM, encryption, logging, configuration management, and security monitoring. - Experience using GRC platforms, APIs, scripting, or automation to improve compliance and security workflows. - Familiarity with tools such as eMASS, Paramify, Nessus/Tenable, Splunk, Prisma Cloud, or comparable solutions. Requirements - Experience supporting FedRAMP, DoD, DISA, or federal agency ATO activities. - CISSP, CGRC/CAP, CISM, Security+, or similar cybersecurity certification. - Experience developing automation with Python, PowerShell, REST APIs, infrastructure-as-code, or cloud-native services. - Experience integrating vulnerability, configuration, and cloud-security data into GRC (Paramify) and POA&M workflows. - Familiarity with DevSecOps pipelines, automated security testing, policy-as-code, and continuous control validation. - Knowledge of FISMA, the Privacy Act, and agency-specific security requirements. Benefits - Health insurance. - Paid leave. - Retirement. Company Description At SMX®, we are a team of technical and domain experts dedicated to enabling your mission. From priority national security initiatives for the DoD to highly assured and compliant solutions for healthcare, we understand that digital transformation is key to your future success. We share your vision for the future and strive to accelerate your impact on the world. We bring both cutting edge technology and an expansive view of what’s possible to every engagement. Our delivery model and unique approaches harness our deep technical and domain knowledge, providing forward-looking insights and practical solutions to power secure mission acceleration. SMX is an Equal Opportunity employer including disabilities and veterans. Selected applicant may be subject to a background investigation and/or education verification. SMX does not sponsor a new applicant for employment authorization or immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, E-2, E-3, L-1 and O-1, or any EADs or other forms of work authorization that require immigration support from an employer).

Related Categories

Related Job Pages

More Security Engineer Jobs

Cosuno logo

Senior IT Security Manager

Cosuno

Manage your entire planning cycle with the Cosuno platform and benefit from our one-size-fits-all solution

Full TimeRemoteTeam 51-200H1B No Sponsor

• Take full ownership of information security, compliance, and IT governance at Cosuno. • Build and run our ISMS, lead us through ISO 27001 certification, and become the face of Cosuno's security posture toward enterprise customers and auditors. • Lead our ISO 27001 certification from gap analysis through audit, and run the ISMS afterwards. • Own responses to enterprise security questionnaires and RFIs, helping Sales close deals faster. • Own the operational side of GDPR: drafting and negotiating DPAs, managing our subprocessor list. • Own our identity and access management via JumpCloud, including joiner/mover/leaver processes.

Germany
€80K - €100K / year
accesa.eu logo

Security Engineer

accesa.eu

The place where creative problem-solvers that care for people, solutions, and their impact thrive

ContractRemoteTeam 1,001-5,000Since 2003H1B No Sponsor

• Administer and fine-tune Microsoft Sentinel (SIEM), including rule creation, use-case development, and incident triage • Manage and optimize Elastic Stack (Elasticsearch/ELK) for log ingestion, indexing, and security analytics • Configure, maintain, and troubleshoot enterprise firewalls (rule management, policy hardening, traffic analysis) • Operate and tune EDR (Endpoint Detection & Response) solutions for threat detection and incident response • Collaborate with SOC/IT teams to ensure compliance with banking regulatory and security standards

Romania
NIR-YU logo

Especialista de Seguridad, Certificado

NIR-YU

Take Control of Your Business and Execute Your Vision with Ease - Hire Affordable and Qualified Nearshore Staff

Full TimeRemoteTeam 201-500H1B No Sponsor

• Fortalecer y evaluar la postura de seguridad en la nube (CSPM) • Integrar controles dentro del ciclo de desarrollo de software (DevSecOps) • Trabajar con equipos de ingeniería en revisiones de arquitectura y auditorías de cumplimiento

Latvia

ML Security Engineer

Bright Vision Technologies

Bright Vision Technologies is a forward-thinking software development company dedicated to building innovative solutions that help businesses automate and optimize their operations. We leverage cutting-edge technologies to create scalable, secure, and user-friendly applications.

Role Description We are seeking an AI Security Engineer to lead the design and implementation of security controls, threat models, and incident response capabilities specifically tailored to AI and machine learning systems. The role addresses the unique security challenges posed by LLMs, model APIs, training data pipelines, and AI-powered applications, including prompt injection, model abuse, data exfiltration, and supply chain risks. The ideal candidate has strong security engineering fundamentals and a deep understanding of how modern AI systems work in practice, with hands-on experience designing defenses for both AI-powered applications and the AI infrastructure that supports them. Key Responsibilities - Define and implement security controls specifically targeting LLM and AI-powered application risks. - Build threat models for AI systems, including prompt injection, jailbreaks, data exfiltration, and abuse patterns. - Design and deploy guardrails, content filters, and policy enforcement layers around model endpoints. - Implement runtime detection and response capabilities for adversarial prompts and abusive behavior. - Secure training and fine-tuning pipelines, including data provenance, integrity, and access controls. - Design controls for sensitive data handling, retention, and redaction in LLM workflows. - Lead red-team exercises against AI systems and drive remediation of identified weaknesses. - Evaluate and harden third-party AI services and open-source AI components used internally. - Implement identity, authorization, and tenant-isolation patterns for multi-tenant AI services. - Drive supply chain security for ML artifacts including weights, datasets, and inference dependencies. - Collaborate with privacy, legal, and compliance teams to ensure AI systems meet regulatory obligations. - Develop monitoring, logging, and detection strategies tailored to AI workloads. - Lead incident response for AI-specific security events and drive durable improvements. - Stay current with adversarial ML, LLM security research, and emerging regulatory developments. Qualifications - Bachelor’s or Master’s degree in Computer Science, Cybersecurity, or a related discipline. - Six or more years of security engineering experience, including significant work on AI or ML systems. - Strong understanding of LLM internals, modern AI architectures, and common failure modes. - Hands-on experience designing security controls for AI-powered applications. - Deep knowledge of application security, identity, and cryptography fundamentals. - Experience with threat modeling and security architecture review processes. - Familiarity with adversarial ML, prompt injection, and model abuse research. - Proficiency in Python and at least one systems language. - Strong understanding of cloud security and modern infrastructure controls. - Excellent written and verbal communication skills. Preferred Qualifications - Publications, talks, or CTF participation in AI security topics. - Experience with red-teaming LLM-based products. - Familiarity with privacy-preserving ML techniques such as differential privacy. - Exposure to regulated industries with strict data handling requirements. - Open-source contributions to AI security tooling. How to Apply Would you like to know more about this opportunity? For immediate consideration, please send your resume to [email protected] or contact us at (908) 505-3544. Learn more about Bright Vision Technologies at www.bvteck.com . Equal Employment Opportunity (EEO) Statement Bright Vision Technologies (BV Teck) is committed to equal employment opportunity (EEO) for all employees and applicants without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, genetic information, disability, veteran status, or any other protected status as defined by applicable federal, state, or local laws. This commitment extends to all aspects of employment, including recruitment, hiring, training, compensation, promotion, transfer, leaves of absence, termination, layoffs, and recall. BV Teck expressly prohibits any form of workplace harassment or discrimination. Any improper interference with employees' ability to perform their job duties may result in disciplinary action up to and including termination of employment.

United States
$100K - $150K / year
Job Closed