Marathon TS · 6 hours ago
Security Engineer
Marathon TS is seeking a Security Engineer to provide senior-level security engineering expertise for the DoD, focusing on Risk Management Framework (RMF) authorization and continuous monitoring. The role involves ensuring compliance with DoD cybersecurity policies in a cloud-based DevSecOps environment and managing various security-related activities.
Responsibilities
Develop, review, and maintain RMF artifacts and system authorization documentation supporting accreditation and sustainment
Manage eMASS entries, security control evidence, and Plans of Action and Milestones (POA&Ms)
Conduct vulnerability assessments, analyze findings, and recommend risk-based mitigations
Support integration of security controls and best practices within a DevSecOps delivery environment
Coordinate security activities with Government stakeholders, DISA, and contractor security teams
Qualification
Required
Bachelor's degree or equivalent relevant experience
Active SECRET clearance
Minimum of seven (7) years of cybersecurity or security engineering experience
One or more of the following certifications: CCISO, CISA, CISM, CISSP, CISSP-ISSEP, CySA+, GSLC, or GSNA
Demonstrated hands-on experience with RMF and eMASS
Experience with STIG implementation, vulnerability scanning, and POA&M management
Preferred
Experience with system integration, data migration, and master data management in ERP environments
Familiarity with RMF, cloud security, and FedRAMP considerations for SaaS solutions
Experience supporting Agile or SAFe governance for COTS/SaaS implementations
Cloud security experience in environments such as AWS, Azure GCC High, or similar
Experience supporting joint or enterprise DoD systems