Enter a job title or keyword

Security Engineer


Job Location:

Washington, DC - USA

Monthly Salary: Not provided by the employer
Posted: 1 September 2026 (4 hours ago)
Application Deadline: 29 November 2026
Vacancies: 1 Vacancy

Job Summary

Koniag Data Solutions a Koniag Government Services company is seeking an experiencedSecurity Engineerto support enterprise cybersecurity operations and IT administrative and operational support services for a federal government client. This position requires an active security clearance or the ability to obtain and maintain a government background investigation and all requisite IT access authorizations prior to performing work. Specific clearance requirements will be confirmed at time of offer. Primary work will be performed at the client site in Washington DC and approved remote/telework offer competitive compensation and an extraordinary benefits package including health dental and vision insurance 401K with company matching flexible spending accounts paid holidays three weeks paid time off and role serves as a critical technical function responsible for the design implementation administration and continuous improvement of enterprise security controls security architecture and cybersecurity capabilities across a complex geographically distributed federal IT environment spanning on-premises infrastructure cloud platforms and enterprise ideal candidate is a technically proficient and security-focused engineer with deep expertise in enterprise security architecture security control implementation vulnerability management identity and access management network security cloud security and Federal cybersecurity compliance frameworks. This individual must possess the technical depth analytical rigor and operational discipline required to design and sustain robust defensible security capabilities that protect Government data systems and mission operations in a highly regulated federal IT Security Engineer will serve as a key technical contributor responsible for the design implementation administration and continuous improvement of enterprise security controls security architectures and cybersecurity capabilities across the full program environment. This individual works closely with infrastructure engineers network engineers cloud operations teams application developers DevSecOps engineers cybersecurity leadership and Government stakeholders to ensure that security is embedded throughout all layers of the enterprise IT environmentfrom endpoint and network through application cloud and identityenabling the Government to maintain a strong measurable and continuously improving security posture in alignment with Federal cybersecurity frameworks and Zero Trust Architecture responsibilities will include but are not limited to:Security Architecture & EngineeringDesign implement and maintain enterprise security architectures and security control frameworks across on-premises cloud and hybrid IT environments ensuring alignment with NIST SP 800-53 NIST SP 800-207 Zero Trust Architecture applicable DISA STIGs CIS Benchmarks and client-specific security security architecture reviews for new and existing systems applications and infrastructure changes identifying security risks recommending compensating controls and ensuring security requirements are addressed prior to and maintain security architecture documentation including security architecture diagrams data flow diagrams network security diagrams and security control implementation narratives ensuring documentation is current and accurately reflects the operational the design and implementation of Zero Trust Architecture principles across the enterprise environment including micro-segmentation identity-based access controls continuous validation least-privilege enforcement and encrypted expert security engineering guidance to infrastructure engineers cloud operations teams application developers and DevSecOps engineers ensuring security requirements are accurately translated into technical implementations across all program emerging security technologies tools and capabilities providing recommendations to program leadership and Government stakeholders on opportunities to enhance the enterprise security Control Implementation & AdministrationImplement configure and maintain enterprise security controls across endpoint network application cloud and identity layers ensuring controls are properly configured continuously monitored and aligned with applicable security baselines and compliance and maintain enterprise security platforms and tools including Security Information and Event Management (SIEM) systems Endpoint Detection and Response (EDR) platforms Data Loss Prevention (DLP) tools Privileged Access Management (PAM) solutions Web Application Firewalls (WAF) and network security monitoring and maintain endpoint security controls including EDR configuration and tuning application whitelisting host-based intrusion detection and endpoint hardening in accordance with applicable DISA STIGs and CIS and maintain network security controls including firewall rule management intrusion detection and prevention system (IDS/IPS) configuration and tuning network segmentation and network access control (NAC) and maintain cloud security controls across AWS (commercial and GovCloud) and Microsoft Azure Government environments including identity and access management (IAM) network security groups encryption at rest and in transit security logging and monitoring and cloud security posture management (CSPM) and maintain identity and access management security controls including multi-factor authentication (MFA) privileged access management (PAM) role-based access control (RBAC) and identity federation configurations in coordination with the Microsoft infrastructure and cloud operations and maintain security baseline configurations and hardening standards for all major platform types including Windows Server Linux network devices cloud workloads and enterprise applications ensuring baselines are current and consistently applied across the ManagementOwn and manage the enterprise vulnerability management program ensuring vulnerabilities are continuously identified accurately assessed prioritized tracked and remediated in accordance with defined timelines and risk-based prioritization and oversee regular vulnerability scanning activities across all in-scope systems applications and cloud environments using industry-standard scanning platforms ensuring scan coverage is comprehensive and scan results are accurate and vulnerability scan results applying contextual risk assessment to prioritize remediation activities based on exploitability asset criticality exposure and potential business and maintain the vulnerability remediation tracking register ensuring all open vulnerabilities are assigned tracked to resolution and reported accurately in program status reports and compliance with infrastructure engineers cloud operations teams application developers and system administrators to ensure timely and effective vulnerability remediation providing technical guidance and remediation recommendations as and maintain vulnerability management reporting capabilities producing regular vulnerability status reports and trend analyses for program leadership and Government penetration testing activities including scoping coordination and remediation tracking for findings identified during authorized penetration tests and red team Monitoring & Incident Response SupportSupport the configuration tuning and maintenance of the enterprise SIEM platform developing and refining detection rules correlation queries dashboards and alerting configurations to improve threat detection coverage and reduce false positive security event feeds and SIEM alerts triaging security events and escalating confirmed or suspected security incidents to the incident response team in accordance with defined escalation procedures and SLA and maintain security monitoring use cases and detection logic aligned with the MITRE ATT&CK framework ensuring detection coverage is continuously improved as the threat landscape cybersecurity incident response activities providing security engineering expertise to containment eradication and recovery efforts and implementing security control improvements to prevent threat hunting activities proactively searching for indicators of compromise adversarial TTPs and undetected threats within the enterprise environment using available log sources endpoint telemetry and threat digital forensics activities as needed providing security engineering context and technical analysis to support forensic investigation ATO & Risk ManagementSupport Authority to Operate (ATO) activities including the implementation documentation and continuous monitoring of required NIST SP 800-53 security controls system security plan (SSP) development and maintenance security assessment support and plan of action and milestones (POA&M) and maintain security assessment and authorization documentation including system security plans security control implementation statements risk assessment reports and continuous monitoring the programs POA&M ensuring all identified security weaknesses are accurately documented assigned tracked and remediated in accordance with defined timelines and risk acceptance continuous monitoring activities including regular security control assessments configuration compliance scanning and security posture reporting ensuring the Government maintains current and accurate visibility into the security state of all in-scope compliance with applicable Federal cybersecurity frameworks and requirements including FISMA NIST SP 800-53 FedRAMP HSPD-12/FIPS 201 NIST SP 800-207 Zero Trust Architecture OMB M-22-09 applicable DISA STIGs and client-specific cybersecurity supply chain risk management (SCRM) activities ensuring third-party software components cloud services and vendor technologies are assessed for supply chain risk in accordance with applicable Federal all security engineering activities involving personally identifiable information (PII) CUI or other sensitive data categories are conducted in accordance with applicable privacy protection requirements and data handling Automation & ToolingDevelop and maintain security automation scripts playbooks and tooling to improve the efficiency consistency and effectiveness of security operations activities including vulnerability scanning compliance checking alert triage and incident security tools and capabilities with SIEM SOAR ITSM and DevSecOps pipeline platforms to enable automated detection alerting ticketing and response and maintain security metrics collection and reporting automation ensuring program leadership and Government stakeholders receive accurate timely and actionable security posture and recommend security automation opportunities identifying manual security processes that can be improved through scripting orchestration or tool Reporting & Knowledge SharingDevelop and maintain comprehensive security engineering documentation including security architecture diagrams security control implementation guides hardening standards operational runbooks and standard operating and present security status reports vulnerability trend analyses and security posture briefings for program leadership and Government stakeholders communicating complex security information clearly and security findings indicators of compromise and threat intelligence to the programs knowledge management repository supporting broader detection prevention and response technical guidance and mentorship to program personnel on security engineering practices tools and Federal compliance the development and delivery of security awareness training materials for program personnel and Government stakeholders as and Experience:Required:Bachelors degree in Cybersecurity Computer Science Information Technology Information Systems or a related field from an accredited college or university. Equivalent combination of education and directly relevant experience may be of 5 years of hands-on experience in security engineering cybersecurity operations or a closely related discipline within a federal government IT contracting or enterprise security hands-on experience implementing and administering enterprise security controls across endpoint network application and cloud supporting ATO activities including NIST SP 800-53 security control implementation SSP development POA&M management and continuous with enterprise vulnerability management including vulnerability scanning risk-based prioritization remediation tracking and security clearance or the ability to obtain and maintain a government background investigation and all requisite IT access authorizations. Specific clearance requirements will be confirmed at time of :Prior experience serving as a Security Engineer on a federal IT O&M program of comparable scale and supporting FedRAMP authorization activities and implementing cloud security controls within AWS GovCloud and/or Microsoft Azure Government with Zero Trust Architecture implementation within a federal enterprise IT Skills and Competencies:Exceptional technical problem-solving skills with demonstrated ability to design implement and maintain robust defensible security architectures and security controls across complex multi-platform federal IT knowledge of Federal cybersecurity frameworks and compliance requirements including NIST SP 800-53 FISMA FedRAMP HSPD-12/FIPS 201 NIST SP 800-207 Zero Trust Architecture OMB M-22-09 applicable DISA STIGs and CIS experience administering and tuning enterprise security platforms including SIEM EDR DLP PAM WAF IDS/IPS and network security monitoring proficiency in vulnerability management including enterprise vulnerability scanning platform administration risk-based vulnerability prioritization and remediation tracking and implementing and maintaining cloud security controls across AWS and/or Microsoft Azure Government environments including IAM network security encryption logging and cloud security posture of Zero Trust Architecture principles and demonstrated experience implementing Zero Trust controls including micro-segmentation identity-based access control least-privilege enforcement and continuous supporting ATO activities including NIST SP 800-53 security control implementation and documentation SSP development and maintenance POA&M management and continuous monitoring program with at least one scripting or programming language including Python PowerShell Bash or equivalent for security automation tool integration and operational developing and maintaining SIEM detection rules correlation queries and dashboards aligned with the MITRE ATT&CK understanding of identity and access management security principles including MFA PAM RBAC identity federation and enterprise directory services (Microsoft Entra ID / Active Directory).Excellent written and verbal communication skills with demonstrated ability to develop clear accurate security documentation and present complex security information to both technical and non-technical with supply chain risk management (SCRM) requirements and practices as applied to third-party software cloud services and vendor technologies in a federal IT Skills and Competencies:Certified Information Systems Security Professional (CISSP) or equivalent senior cybersecurity Security Essentials (GSEC) GIAC Certified Enterprise Defender (GCED) GIAC Certified Incident Handler (GCIH) or equivalent GIAC cybersecurity Security CompTIA CySA or CompTIA CASP Certified Security Specialty or Microsoft Certified: Azure Security Engineer Associate certification or equivalent cloud security Information Security Manager (CISM) or equivalent security management with Security Orchestration Automation and Response (SOAR) platform development and administration including playbook development and automated response workflow with penetration testing methodologies and tools including scoping execution coordination and remediation tracking for authorized penetration tests and red team with threat intelligence platforms and the practical application of threat intelligence to detection engineering threat hunting and security control improvement with deception technology platforms including honeypots and honeytokens as supplementary detection and early warning capabilities within enterprise security with privacy engineering principles and the practical application of privacy-by-design concepts to security architecture and control implementation developing and delivering security awareness training materials for program personnel and Government stakeholders in a federal IT of enterprise application security principles including OWASP Top 10 secure coding practices and web application security testing with Section 508 compliance requirements for security tools dashboards and reporting products delivered under federal with FedRAMP continuous monitoring program execution including automated evidence collection control assessment scheduling and monthly reporting ATT&CK Defender (MAD) certification or demonstrated equivalent expertise applying the MITRE ATT&CK framework to detection engineering threat hunting and security architecture Equal Employment Opportunity Policy:The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race color religion creed ethnicity sex sexual orientation gender or gender identity (except where gender is a bona fide occupational qualification) national origin or ancestry age disability citizenship military/veteran status marital status genetic information or any other characteristic protected by applicable federal state or local law. We are committed to equal employment opportunity in all decisions related to employment promotion wages benefits and all other privileges terms and conditions of company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or to apply to a position on our website please contact Heaven Wood via e-mail at or by calling to request accommodations. Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical professional and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers employees and native communities. For more information please visit Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352

Required Experience:

IC


About Company

Company Logo

What We Do Koniag Government Services (KGS) is an Alaska Native Corporation comprised of multiple wholly owned subsidiary companies that deliver Enterprise Solutions, Professional Services, and Operations Management to Federal Government agencies. With an agile employee and corporate ... View more

View Profile View Profile