Security Engineer
The JAAW Group Davis County, Utah, United States
Defense and Space Manufacturing · 11-50 employees
About the role
The Security Engineer will architect, deploy, and maintain cybersecurity solutions while ensuring compliance with RMF and JSIG frameworks. They will also manage security tools, automate processes, and provide technical support for mission-critical systems in cloud and enterprise environments.
What they look for
Requirements
Candidates must possess an active Secret security clearance and at least 3 years of experience in a security engineering role. Proficiency in Splunk, cloud security, and automation tools like Ansible or Terraform is required, along with a DoD IASAE Level II certification.
Full description
Security Engineer
Location: Hill Air Force Base, UT. Clearance Required: Secret; Top Secret preferred. Employment Type: Full-Time.
About the Role
The JAAW Group LLC, a Service-Disabled Veteran-Owned Small Business (SDVOSB), is seeking a Security Engineer to support secure, mission-critical Department of Defense systems at Hill Air Force Base. This role is responsible for architecting, engineering, deploying, and maintaining cybersecurity solutions while supporting compliance with the Risk Management Framework (RMF), Joint Special Access Program Implementation Guide (JSIG), and related security requirements. The Security Engineer will work closely with ISSOs, DevOps, platform, and infrastructure teams to strengthen system security, deploy and maintain cybersecurity tooling, automate security processes, support vulnerability management and incident response, and ensure security requirements are incorporated into enterprise and cloud environments.
Responsibilities
- Support, administer, and maintain cybersecurity tools and platforms, including SIEM, vulnerability management, compliance, and endpoint security technologies.
- Administer and support Splunk Enterprise, including data onboarding, dashboards, alerts, correlation, and data normalization.
- Support vulnerability scanning and management using Nessus/ACAS and compliance assessment tools such as Evaluate-STIG and SCAP Compliance Checker.
- Develop and automate security processes using Ansible, Terraform, PowerShell, Bash, Python, or similar technologies.
- Develop and improve security detections, telemetry, alerting, and incident response capabilities.
- Architect and deploy solutions supporting vulnerability management, auditing, logging, patch management, and risk remediation.
- Engineer and implement security requirements for AWS and Azure cloud environments in accordance with RMF and JSIG.
- Improve system security through access controls, configuration baselines, system hardening, and endpoint security.
- Partner with ISSM and ISSO teams on RMF authorization activities, continuous monitoring, control implementation, and audit preparation.
- Develop and maintain technical documentation, including standard operating procedures, runbooks, and architectural designs.
- Provide security engineering recommendations to DevOps and platform teams supporting complex system architectures.
Required Qualifications
- Active Secret security clearance required prior to onboarding; Top Secret preferred.
- U.S. citizenship required.
- DoD IASAE Level II certification, such as CASP+ or CISSP, or ability to obtain within 3 months of hire.
- At least 3 years of experience in a security engineering role.
- Hands-on experience with Splunk Enterprise, including administration, data normalization, alerting, and correlation.
- Advanced working knowledge of Windows and Linux system administration, hardening, and security; RHEL experience preferred.
- Experience with AWS and/or Microsoft Azure environments, cloud security concepts, and hybrid deployments.
- Experience with cybersecurity engineering disciplines, including vulnerability assessment, patch and configuration management, monitoring, access control, and incident response.
- Experience with automation and configuration management technologies such as Ansible, Terraform, PowerShell, Bash, or Python.
- Familiarity with RMF and JSIG accreditation processes.
- Strong understanding of TCP/IP networking and network security.
- Ability to work effectively in an Agile, fast-paced, mission-focused environment.
Preferred Qualifications
- Active Top Secret security clearance.
- 5+ years of security engineering experience.
- AWS or Microsoft Azure technical certifications.
- Bachelor's or Master's degree in Computer Science, Software Engineering, Information Assurance, Cybersecurity, or a related field.
- Experience supporting security incident response teams, including NOC or SOC environments.
- Familiarity with container security technologies, including Docker, Kubernetes, ECS, EKS, or AKS.
- Experience supporting Department of Defense or other classified government environments.
Similar roles
-
Senior Cybersecurity Engineer
Votaw Precision Technologies LLC Santa Fe Springs, California, United States · $125K–$175K/yr
-
Sr. Application Security Engineer
SentinelOne United States · $132K–$160K/yr
-
Cloud Security Engineer - Public Sector, IT Operations
BDO USA, P.C. Mclean, Virginia, United States · $105K–$120K/yr
-
Senior Software Security Engineer
Valar Atomics Torrance, California, United States · $175K–$200K/yr
-
Staff Security Engineer, Product & Platform Security
Nscale San Francisco, California, United States · $190K–$240K/yr
-
Staff Cyber Security Engineer
NBCUniversal New York, New York, United States · $125K–$155K/yr