Principal Security Engineer
Posted 4hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Principal Security Engineer reviewing FedRAMP cloud architectures, authorization packages, and security controls. Advising government programs and Cloud Service Providers on NIST compliance and risk.
Responsibilities:
- Provide technical expertise on security control implementations and develop Information Security procedures for systems and applications
- Provide program, analytical, technical, and advisory skills to clients and supported Cloud Service Providers (CSPs)
- Perform pre-assessment activities, including detailed analysis of technology stacks comprising vendor solutions
- Engineer secure, compliant, and resilient architectures and solutions
- Assess vendor systems for technical compliance with NIST, FedRAMP, and agency standards
- Perform detailed architecture and technical design reviews across the full stack for vendor solutions
- Conduct architecture reviews of CSP authorization packages to validate secure design, alignment with FedRAMP and agency requirements, identify gaps, and advise on risk posture and compliance
- Lead and conduct architecture interviews with CSPs
- Develop architecture briefing documents for the Government FedRAMP program manager and CISO
- Review and comment on CSP FedRAMP documentation, including system security plans, policies, procedures, agency guidance, alternative implementations, and risk acceptance documents
- Work with CSPs to reconcile documentation and technology gaps
- Review CSP assessments and package submissions after 3PAO audits and prepare package briefings
- Review security assessment plans, security assessment reports, vulnerability scans, and penetration tests
- Provide security engineering services alongside the agency FedRAMP Lead
- Support Continuous Monitoring activities, including annual package submissions, significant change proposals, and risk acceptance documents
- Interpret FedRAMP and agency requirements and provide vendors with technical and process guidance
- Monitor updated FedRAMP guidance, industry best practices, emerging technologies, and Government cybersecurity directives
- Conduct security reviews of technologies for use within CSP authorization boundaries
- Manage relationships for assigned contractor-owned or contractor-operated systems and ensure vendor compliance with agency security and privacy requirements
- Assist stakeholders with IT security-related activities and project deadlines
- Ensure systems are operated, maintained, and disposed of according to documented security policies and procedures, including Assessment & Authorization (A&A)
- Research assigned IT security systems and provide architecture and security recommendations
Requirements:
- Five (5) years of experience in the IT Security field
- Bachelor’s degree in Computer Science, Information Systems, Mathematics, Engineering or a related field, OR an additional three years of IT experience required
- Direct experience as a Security Engineer or System Architect performing analysis on FedRAMP Cloud Service Providers (CSP) architectures and control implementations
- Four (4) years of hands-on technical experience as a System Architect or Security Engineer
- Four (4) years of experience supporting FedRAMP as an Engineer or Architect
- Security+, CISSP, CISM, CISA, or equivalent Security certification
- Confidence and depth of understanding to lead meetings with potential Vendors
- Current experience in reviewing 3rd party security assessment reports
- Detailed knowledge and experience with NIST Policies, Governance, Security Planning and Architecture, FISMA Compliance, RMF, Incident Analysis, and General Security Best Practices
- Strong written and oral communication skills
- Ability to communicate with technical and non-technical stakeholders
- Strong communication skills to interact with senior managers, junior staff, and business unit customers
- Ability to work during core business hours aligned with coworkers and Valiant's clients
- Quiet, distraction-free workspace with adequate internet for remote work
- Full attention and availability during working hours
- Disclosure of current or future outside employment engagements and written approval for outside employment or other professional activities
Benefits:
- Valiant pays 99% of the Medical, Dental, and Vision Coverage for Full-time Employees
- Valiant contributes 25% towards Health Coverage for Families and Dependents
- 100% Paid Short-Term Disability and Life Insurance Policy for Full-time Employees
- 100% Paid Certifications
- 401K Matching up to 4%
- Paid Time Off
- Paid Federal Holidays
- Valiant University – Online Education and Training Portal
- Wellness & Fitness Program
- FSA programs for: Medical Costs, Dependent Care, Transit, and Parking
- Referral Bonuses
- Work-life balance
- Career development opportunities














