Security Engineer-Senior
Wichita Tribal Enterprise United States
Holding Companies · 51-200 employees
About the role
The Security Engineer provides senior-level cybersecurity engineering and RMF support for federal information systems. They are responsible for conducting security assessments, developing authorization packages, and ensuring compliance with federal cybersecurity requirements.
What they look for
Requirements
Candidates must possess a degree or equivalent professional experience in information assurance or cybersecurity engineering. Proficiency in NIST RMF guidance, security assessment methodologies, and federal compliance standards is required.
Full description
This position is contingent upon contract award
Wichita Tribal Enterprises, a Quivera Enterprise company, is seeking an experienced Security Engineer – Senior to support the Department of the Interior (DOI), Indian Affairs (IA), Office of Information Technology (OIT). This position provides senior-level cybersecurity engineering and Risk Management Framework (RMF) support for enterprise information systems and continuous monitoring activities. The Security Engineer – Senior serves as a technical subject matter expert responsible for conducting comprehensive security assessments, developing system authorization packages, implementing NIST Risk Management Framework (RMF) processes, and supporting federal cybersecurity compliance initiatives.
Working closely with Information System Owners (ISOs), Information System Security Officers (ISSOs), developers, IT operations personnel, and federal stakeholders, this position develops security documentation, performs technical security assessments, evaluates security controls, and supports continuous monitoring efforts to ensure compliance with NIST guidance, FISMA, Departmental policy, and federal cybersecurity requirements. The successful candidate will possess extensive experience in information assurance, risk assessment, security engineering, and security authorization activities while supporting secure, compliant, and mission-focused federal IT systems.
Key Responsibilities
Risk Management Framework (RMF)
- Conduct security assessments of federal information systems in accordance with NIST SP 800-37 and NIST SP 800-53 guidance.
- Develop complete security authorization packages supporting Authority to Operate (ATO) and continuous authorization activities.
- Perform system security categorization in accordance with NIST SP 800-60 and FIPS 199 requirements.
- Document security control selection and tailoring in accordance with NIST SP 800-53 and NIST SP 800-18.
- Develop and maintain System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), Plans of Action and Milestones (POA&Ms), Contingency Plans (CPs), and supporting RMF documentation.
- Support implementation of RMF activities throughout the System Development Life Cycle (SDLC).
Security Engineering & Assessment
- Conduct technical security assessments of complex information systems, network infrastructures, cloud environments, and industrial control systems with minimal supervision.
- Evaluate management, operational, and technical security controls for effectiveness and compliance.
- Perform vulnerability analysis and identify security weaknesses affecting federal information systems.
- Apply NIST security engineering principles throughout system design, implementation, and operation.
- Develop remediation recommendations and mitigation strategies for identified vulnerabilities.
- Provide preliminary POA&M recommendations supporting corrective action planning.
- Conduct concurrent risk assessments and document findings within Security Assessment Reports.
Continuous Monitoring & Compliance
- Support Indian Affairs Risk Management Framework and Continuous Monitoring Programs.
- Monitor implementation of security controls to ensure ongoing compliance with federal cybersecurity requirements.
- Participate in continuous assessment of technical, operational, and management controls.
- Assist with ongoing authorization activities and security documentation updates.
- Support compliance with FISMA, Departmental policy, and organizational cybersecurity standards.
Security Documentation
- Develop initial and updated System Security Plans.
- Develop Contingency Plans aligned with NIST SP 800-34 guidance.
- Prepare Security Assessment Plans and execute assessment activities.
- Develop Security Assessment Reports documenting assessment findings.
- Prepare Risk Assessment Reports identifying organizational and system risks.
- Develop and maintain POA&M documentation identifying weaknesses, remediation activities, and risk priorities.
- Maintain documentation supporting system authorization and continuous monitoring.
Risk Assessment & Security Analysis
- Perform enterprise and system-level risk assessments.
- Analyze vulnerabilities, threats, likelihood, and impact to determine organizational risk.
- Provide risk mitigation recommendations aligned with NIST guidance and industry best practices.
- Evaluate configuration management processes supporting secure system operation.
- Support contingency planning and disaster recovery planning activities.
Collaboration & Technical Support
- Collaborate with Information System Owners, Information System Security Officers, developers, project teams, and IT operations personnel.
- Coordinate assessment activities with organizational stakeholders while working independently.
- Provide technical guidance regarding security engineering and RMF implementation.
- Support implementation of cybersecurity best practices across the enterprise.
- Assist organizational stakeholders in understanding security assessment findings and remediation priorities.
Program Support
- Provide multidisciplinary security support across:• Physical Security
- Computer Security
- Personnel Security
- Information Security
- Administrative Security
- Operational Security
- Communications Security
- Support strategic implementation of security controls across enterprise information systems.
- Participate in process improvement initiatives supporting cybersecurity maturity.
- Maintain awareness of emerging cybersecurity threats, technologies, and federal regulatory changes.
Required Qualifications
Education
One of the following combinations is required:
- Bachelor's degree and four (4) years of relevant professional experience; or
- Master's degree and three (3) years of relevant professional experience; or
- Six (6) years of directly related professional experience in lieu of a degree.
An industry-recognized technical certification may substitute for two (2) years of required experience where permitted by contract.
Required Experience
- Experience supporting Risk Management Framework (RMF) activities.
- Experience conducting technical security assessments.
- Experience developing complete security authorization packages.
- Experience with information assurance or cybersecurity engineering.
- Experience implementing NIST RMF guidance.
- Experience conducting security assessments of complex information systems with minimal supervision.
- Experience performing vulnerability assessments and risk analysis.
- Experience developing POA&Ms and remediation recommendations.
- Experience supporting continuous monitoring activities.
- Experience evaluating management, operational, and technical security controls.
Required Knowledge
- NIST SP 800-37 Risk Management Framework
- NIST SP 800-53 Security Controls
- NIST SP 800-18 System Security Plans
- NIST SP 800-34 Contingency Planning
- NIST SP 800-27 Security Engineering
- NIST SP 800-60 Information Categorization
- FIPS 199
- Risk Assessment & Management
- Vulnerability Analysis
- Configuration Management
- Disaster Recovery
- Contingency Planning
- Security Engineering
- Authorization & Assessment (A&A)
- Security Authorization Packages
- Continuous Monitoring
- Federal Information Security Modernization Act (FISMA)
Preferred Qualifications
- CISSP
- CAP (Certified Authorization Professional)
- Security+
- CASP+
- CISM
- CEH
- GSEC
- Experience supporting Department of the Interior or Bureau of Indian Affairs.
- Experience with eMASS, CSAM, Xacta, Archer, or similar GRC platforms.
- Experience supporting cloud security and FedRAMP initiatives.
- Experience with industrial control systems (ICS) or operational technology (OT) environments.
Physical Demands – IT Office/Technical Role
The physical demands described here are representative of those that must be met by an employee, with or without reasonable accommodation.
This role is primarily office-based and requires prolonged computer use, including sitting, typing, and operating standard office equipment. Occasional walking, standing, bending, and reaching may be required to support equipment setup and troubleshooting. The employee must be able to lift up to 15 pounds, with occasional heavier lifting.
The employee must be able to communicate effectively and maintain visual acuity (close, distance, color, and depth perception). Occasional travel and extended hours may be required to support operational needs and deadlines.
Equal Employment Opportunity
Quivera Enterprises LLC and its subsidiaries are 100% tribally owned and SBA-certified Small Disadvantaged Businesses. We are proud to be an Equal Opportunity Employer and are committed to creating an inclusive workplace where all qualified applicants receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veteran status, or any other status protected by applicable federal, state, or local law.
As a tribally owned organization, Quivera Enterprises and its subsidiaries may apply Indian Preference in accordance with applicable tribal, federal, and contractual requirements where authorized by law.
Dream. Grow. Thrive.
Similar roles
-
Senior Security Engineer- Hybrid
Akamai Tel-Aviv, Tel-Aviv District, Israel
-
Cybersecurity Engineer
ISPA Technology Panama City Beach, Florida, United States
-
Cybersecurity Specialist
Avion Solutions Huntsville, Alabama, United States
-
Systems Cybersecurity Journeyman
Applied Research Solutions Bedford, Massachusetts, United States · $140K–$160K/yr
-
Sr Systems Engineer/ Information Security Engineer
ELEVI Associates Annapolis Junction, Maryland, United States · $170K–$200K/yr
-
CRA Compliance and Product Security Engineer
Valce Talent Solutions Mexico