RAPP · 3 months ago
Security Engineer
RAPP Chicago is a global precision marketing agency seeking a Security Engineer to join their Technology team. The role involves supporting enterprise-wide security and compliance initiatives within a highly secure government cloud environment, ensuring ongoing compliance and security through continuous monitoring, vulnerability management, and collaboration with technical teams.
AdvertisingMarket ResearchMarketing
Responsibilities
Conduct and analyze vulnerability assessments using automated tools (e.g. Evaluate-STIG), interpret scan results, and coordinate remediation
Update RMF required documentation (SSP, SAR, POA&Ms), ensuring it accurately reflects current system status, vulnerabilities, and remediation actions to support ATO renewals and audits
Participate in technical change management and secure development processes, reviewing new features for security compliance
Support threat modeling activities for system changes, documenting risks and mitigation approaches working with the Security Architect
Use compliance/risk management tools (e.g. eMass) to maintain security and risk assessment evidence, track findings, and support remediation activities
Collaborate with and support the Security Architect, technical owners, ISSOs, engineers, and program management stakeholders to gather evidence, resolve findings, and verify secure implementation of security related changes
Prepare and deliver clear, concise security reports and briefings to security and technical stakeholders
Remain current on evolving DoD cybersecurity requirements, NIST guidance, AWS GovCloud security practices, and emerging threats
Qualification
Required
Experience supporting RMF processes and maintaining compliance documentation (NIST 800-53, ATO lifecycle)
Hands-on experience with vulnerability assessment tools (e.g. Evaluate-STIG), and AWS services
Strong analytical, problem-solving, organizational, and technical writing skills
Familiarity with vulnerability management, continuous monitoring, and secure change management in cloud environments
Demonstrated ability to communicate and collaborate effectively with both technical and program management teams
Experience working in or with consulting organizations and/or public sector clients is highly valued
One of the following certifications is required to qualify for this role, in accordance with DoD 8140/8570 requirements for cybersecurity positions (IAT Level II/III, IAM Level I/II, or CSSP Analyst/Auditor, as appropriate to assignment): CompTIA Security+, CompTIA Cybersecurity Analyst (CySA+), CAP (Certified Authorization Professional), CISA (Certified Information Systems Auditor), GSLC (GIAC Security Leadership Certification), CISSP (Associate or full, preferred for some assignments), Other DoD 8140/8570-approved certifications appropriate to the position and level
Candidates must maintain active certification status throughout employment
Exceptional attention to detail and organizational skills
Strong written and verbal communication skills, with the ability to explain complex metadata systems to non-technical users
Ability to work collaboratively and cross-functionally with creative, marketing, and IT teams
Proactive problem-solver who can identify issues and suggest improvements
Time management skills with the ability to prioritize and manage multiple tasks in a fast-paced environment
Preferred
Certified Cloud Security Professional (CCSP) and/or Cloud AWS/Azure/GCP certifications
Experience in highly regulated industries (government, defense, healthcare, finance)
Experience with eMASS (DoD) / RMF tools and DISA STIGs, ACAS, Nessus compliance tools
Benefits
Health/vision/dental insurance
401(k)
Stock options
Healthcare & Dependent Flexible Spending Accounts
Vacation
Sick, and personal days
Positive activism days
Paid parental leave
Disability benefits
Company
RAPP
RAPP is a customer experience agency. It is a sub-organization of DAS Group.
Funding
Current Stage
Late StageRecent News
Campaign UK More Latest RSS Feed
2025-12-25
Campaign UK More Latest RSS Feed
2025-12-03
Company data provided by crunchbase