Q

Security Engineer

QualityWorks Consulting Group, LLC Los Angeles County, California, United States

Yesterday
security Mid (2-5 yrs) Contractor United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Security Engineer will configure and secure the AWS GovCloud environment and implement DoD PKI authentication based on provided runbooks. They are responsible for executing security controls, performing system hardening, and capturing compliance evidence for government acceptance.

What they look for

AWS GovCloud PKI Security Engineering Systems Administration Linux Windows Server Compliance Vulnerability Scanning STIGs IAM Encryption KMS Network Security Technical Documentation Troubleshooting

Requirements

Candidates must be U.S. Persons capable of passing a Public Trust background investigation and obtaining a Common Access Card. The role requires 3-6 years of experience in systems or security engineering and a DoD 8140/8570 IAT Level II certification.

Full description

QualityWorks Consulting Group 

Cybersecurity Engineer 

Job Description

Location  On-site, U.S. — specific site shared during screening

Type  Contract

Duration  3 months

Experience: Mid -level

Department : Technology

About the Role

We're deploying an autonomous software testing platform into a secure government environment spanning AWS GovCloud and on-premise infrastructure, and we need a security engineer inside the accredited boundary to make it real: configure and secure the GovCloud environment, install and configure DoD PKI, harden the stack, verify the security controls actually work, and produce the compliance evidence the government needs to accept it. This role is scoped for execution and verification rather than greenfield security architecture. The trust-model decisions, configuration procedures, and integration patterns are prepared in advance by our engineering team and handed to you as detailed runbooks, pre-validated in a sandbox before you ever open them. Your job is to run them correctly in the real environment, troubleshoot where the environment doesn't match the document, prove the controls hold, and escalate cleanly when something falls outside the documented path. If you're a careful systems or security engineer who executes precisely, documents well, and communicates clearly against a compliance deadline, you don't need a decade of PKI architecture experience to do this job well. We've deliberately built the role so you don't have to.

Security & Eligibility Requirements

These are hard conditions of the work, not preferences:

  • U.S. Person status. The work happens inside a government-accredited environment and cannot be performed by a non-U.S. Person or from outside the United States.
  • Ability to pass a Public Trust background investigation.
  • Willingness to complete DD Form 2875 system access paperwork immediately on offer acceptance.
  • Completion of the DoD Cyber Awareness Challenge and site-specific training before access.
  • Ability to obtain and maintain a Common Access Card (CAC).
  • DoD 8140/8570 IAT Level II certification (Security+ CE or equivalent) — held, or obtainable before access is granted.
  • On-site presence for the duration of the setup phase.

On timing: vetting and access provisioning run roughly 30 business days from submission. You won't have system access in your first few weeks — that time goes to paperwork, training, and working through the runbooks before you touch the environment. Candidates need to be  comfortable with that ramp.

What You'll Do

AWS and GovCloud environment security

  • Configure and secure the GovCloud environment following the provided setup runbook: account structure, IAM roles and policies, VPC and security group configuration
  • Implement encryption and key management (KMS), S3 access controls, and secrets handling to the provided specification
  • Stand up and validate logging and monitoring — CloudTrail, Config, GuardDuty or equivalent — and confirm the audit trail satisfies the control requirements
  • Work within GovCloud partition boundaries and credential separation, and identify where service parity differs from commercial regions

PKI and CAC Authentication

  • Install and configure DoD PKI certificates for the platform, following the provided configuration runbook
  • Configure CAC/PIV-based authentication and validate it end to end with live credentials
  • Verify certificate chains, trust stores, and revocation checking (OCSP/CRL) behave as specified
  • Handle certificate lifecycle work in the environment: requests, installation, renewal, replacement

Environment Setup and Hardening

  • Execute the provided on-premise and cloud setup procedures inside the accredited boundary
  • Apply specified hardening baselines and STIG configurations
  • Run compliance and vulnerability scans, interpret the results, remediate findings per the documented guidance

Control Verification and Evidence

  • Execute documented test steps demonstrating each required security control is implemented and working
  • Capture evidence to our evidence standard — scan output, configuration exports, logs, screenshots — recorded in the master test log
  • Package security artifacts in the form the government's compliance reviewers expect
  • Track open findings to closure and report status on a set cadence

Client Interface and Escalation

  • Act as on-site point of contact for the client's ISSM/ISSO on security configuration questions
  • Coordinate site access, change windows, and scan schedules with client stakeholders
  • Raise anything outside the documented procedures through our escalation channel, with enough diagnostic detail for remote analysis
  • Maintain a daily written handoff so work continues across time zones
  • Feed deviations back so the runbooks stay accurate

What This Role Doesn't Own

Stated plainly, because it's the point of the role. These arrive already built:

  • Designing the PKI architecture or certificate trust model — you implement the documented design
  • Designing the cloud landing zone, network architecture, or platform integration patterns
  • Authoring security control narratives or the RMF/ATO package from scratch — you produce the evidence that feeds them
  • Writing the configuration runbooks and test procedures
  • Platform development and test-automation framework design

You have a dedicated engineering team behind all of it, reachable through a defined escalation channel with agreed response times. You are the only one on-site; you are not the only one on the problem.

What We're Looking For

  • 3–6 years in systems engineering, security engineering, or systems administration with a security focus
  • Hands-on certificate work: installing, renewing, and troubleshooting X.509/TLS certificates, trust stores, and chain-of-trust problems. Comfort debugging at the openssl s_client level — not CA design
  • Direct experience working in AWS GovCloud, including its partition boundaries, credential separation, and service parity differences from commercial regions
  • Solid Linux and/or Windows Server administration
  • Demonstrated ability to follow a detailed technical procedure exactly, and to notice and document when the environment doesn't match it
  • Familiarity with hardening baselines (STIGs, CIS benchmarks, or equivalent) and running or interpreting compliance scans
  • Disciplined written communication — evidence capture, status reports, and escalation write-ups someone remote can act on
  • U.S. Person status and ability to meet every vetting requirement above

Nice to Have (not required)

  • Prior on-site work in a DoD or federal environment; prior CAC holder
  • Prior experience with DD-2875 access processes
  • AWS Certified Security – Specialty, or Solutions Architect Associate
  • Experience in another FedRAMP or IL-accredited environment
  • Exposure to AWS GovCloud or another FedRAMP/IL-accredited environment
  • Supporting (not owning) role on a previous RMF or ATO effort
  • Familiarity with CI/CD, source control, and test management tooling
  • Experience working with a distributed team across time zones

What We Offer

  • Competitive contract compensation for the 3-month engagement
  • Direct backing from a dedicated engineering team, reachable through a defined escalation channel with agreed response times
  • Pre-validated runbooks and configuration procedures, so you execute against a proven plan rather than starting from a blank page
  • A clearly scoped, well-defined engagement with a set start and end date
  • The opportunity to work inside an accredited government environment on a mission-relevant platform

Similar roles