Subject Matter Expert III - Information Systems Security Engineer
OneZero Solutions Arlington County, Virginia, United States
IT Services and IT Consulting · 201-500 employees
About the role
The lead Information Systems Security Engineer is responsible for designing, building, and maintaining layered security automation architecture within AWS. This includes developing Infrastructure-as-Code templates, implementing Policy-as-Code compliance, and managing orchestration workflows to support mission requirements.
What they look for
Requirements
Candidates must possess a Bachelor's degree and at least 12 years of experience in systems engineering and cybersecurity, with 7 years specifically in security automation and cloud architecture. An active Secret clearance and professional AWS or CISSP certification are required.
Benefits
Full description
We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. OneZero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance. Additional details are available on our website: https://www.onezerollc.com/careers/
Position Title: Subject Matter Expert III - Information Systems Security Engineer
Location: Arlington, VA or Mechanicsburg, PA
Clearance: Secret
Job Summary:
The Subject Matter Expert III is key personnel serving as the lead Information Systems Security Engineer (ISSE). The role is the lead technical authority for designing, building, and sustaining DSCA's layered security automation architecture in AWS infrastructure provisioning, configuration management, Policy-as-Code compliance validation, and orchestration and for translating DoW regulatory requirements into functional, automated, operational code.
Education and Experience:
- Bachelor's degree from an accredited institution in Information Technology, Computer Science, Engineering, or a related technical discipline.
- One of the following certifications: AWS Certified DevOps Engineer – Professional; AWS Certified Solutions Architect – Professional; AWS Certified Security – Specialty; or (ISC)2 CISSP, preferably with an engineering or architecture concentration (ISSEP/ISSAP).
- Twelve (12) years of demonstrated experience in systems engineering and cybersecurity, with at least seven (7) of those years focused on security automation, cloud engineering, and architecture.
- Five (5) years of demonstrated experience serving as a lead technical authority on enterprise-level projects, responsible for designing and implementing security solutions, not just assessing them.
- Five (5) years of demonstrated experience translating complex regulatory requirements (RMF, NIST, DISA STIGs) and architectural diagrams into functional, automated, and operational code.
- Active Secret clearance; U.S. citizenship required.
Essential Duties:
- Serving as the lead Information Systems Security Engineer, developing and integrating cybersecurity designs for systems and networks.
- Designing, building, and maintaining the layered automation architecture.
- Infrastructure Provisioning Layer: developing and maintaining a library of approved, secure Infrastructure-as-Code templates.
- Configuration Management Layer: implementing solutions such as AWS Systems Manager to sustain secure configurations.
- Compliance Validation Layer: implementing Policy-as-Code capabilities by translating DoW control requirements into automated checks.
- Orchestration and Workflow Layer: delivering orchestration to coordinate complex, multi-step security workflows.
- Developing and managing the Compliance-as-Code (CaC) framework.
- Integrating AWS-native security services for continuous monitoring.
- Providing technical support for dashboard and API development, including Power BI dashboards and RESTful APIs that expose standardized, reusable compliance metrics.
Knowledge, Skill and Abilities:
- Expert-level AWS engineering skill, including AWS-native security services and Systems Manager.
- Infrastructure-as-Code and secure baseline template development for repeatable, compliant provisioning.
- Policy-as-Code and Compliance-as-Code development, translating DoW control requirements into automated checks.
- Security orchestration and workflow automation across multi-step, multi-system processes.
- Dashboard and API engineering (e.g., Microsoft Power BI, RESTful APIs) to expose standardized, reusable compliance metrics.
- Deep working knowledge of RMF, NIST standards, and DISA STIGs in a DevSecOps delivery model.
Ability to act as lead technical authority and to communicate architectural decisions to government stakeholders
OneZero Solutions, LLC is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, status as a protected veteran, or any other protected category under applicable federal, state, and local laws.
To request an accommodation, please contact us at recruiting@onezerollc.com or call (202) 987-2580.
Similar roles
-
IT & Cybersecurity Manager
Jusczak Trucking LLC Forest Lake, Minnesota, United States
-
Senior Cloud Security Engineer
Zions Bancorporation Midvale, Utah, United States
-
Lead Cyber Security Engineer
Capital Bank Rockville, Maryland, United States · $115K–$125K/yr
-
Cyber Security Engineer I
TAMKO Coppell, Texas, United States
-
Cybersecurity Officer (Remote)
CloseKnit MSO Rockville, Maryland, United States · $175K–$205K/yr
-
Engineering, Cybersecurity, Application Security Engineer, Vice President
TPG Careers Page Fort Worth, Texas, United States