Koniag Government Services

Security Engineer

Koniag Government Services$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, or related field; equivalent experience considered.
  • Minimum 5 years of hands-on experience in security engineering or cybersecurity operations.
  • Experience with enterprise security controls across endpoint, network, application, and cloud environments.
  • Familiarity with ATO activities and NIST SP 800-53 security controls.
  • Hands-on experience in enterprise vulnerability management, including scanning and remediation tracking.
  • Active security clearance or ability to obtain one.

Responsibilities

  • Design and maintain enterprise security architectures across diverse IT environments.
  • Conduct security architecture reviews, identifying risks and recommending controls.
  • Develop security architecture documentation, including diagrams and narratives.
  • Support Zero Trust Architecture implementation throughout the enterprise.
  • Provide security engineering guidance to various IT teams on security requirements.
  • Evaluate emerging technologies to enhance enterprise security posture.

Benefits

  • Health, dental, and vision insurance.
  • 401K with company matching.
  • Flexible spending accounts.
  • Three weeks paid time off.
  • Paid holidays.
Full Job Description
Koniag Data Solutions, a Koniag Government Services company, is seeking an experienced Security Engineer to support enterprise cybersecurity operations and IT administrative and operational support services for a federal government client. This position requires an active security clearance or the ability to obtain and maintain a government background investigation and all requisite IT access authorizations prior to performing work. Specific clearance requirements will be confirmed at time of offer. Primary work will be performed at the client site in Washington DC and approved remote/telework locations.

We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.

This role serves as a critical technical function responsible for the design, implementation, administration, and continuous improvement of enterprise security controls, security architecture, and cybersecurity capabilities across a complex, geographically distributed federal IT environment spanning on-premises infrastructure, cloud platforms, and enterprise applications.

The ideal candidate is a technically proficient and security-focused engineer with deep expertise in enterprise security architecture, security control implementation, vulnerability management, identity and access management, network security, cloud security, and Federal cybersecurity compliance frameworks. This individual must possess the technical depth, analytical rigor, and operational discipline required to design and sustain robust, defensible security capabilities that protect Government data, systems, and mission operations in a highly regulated federal IT environment.

The Security Engineer will serve as a key technical contributor responsible for the design, implementation, administration, and continuous improvement of enterprise security controls, security architectures, and cybersecurity capabilities across the full program environment. This individual works closely with infrastructure engineers, network engineers, cloud operations teams, application developers, DevSecOps engineers, cybersecurity leadership, and Government stakeholders to ensure that security is embedded throughout all layers of the enterprise IT environment-from endpoint and network through application, cloud, and identity-enabling the Government to maintain a strong, measurable, and continuously improving security posture in alignment with Federal cybersecurity frameworks and Zero Trust Architecture principles.

Principal responsibilities will include but are not limited to:

Security Architecture & Engineering
  • Design, implement, and maintain enterprise security architectures and security control frameworks across on-premises, cloud, and hybrid IT environments, ensuring alignment with NIST SP 800-53, NIST SP 800-207 Zero Trust Architecture, applicable DISA STIGs, CIS Benchmarks, and client-specific security requirements.
  • Conduct security architecture reviews for new and existing systems, applications, and infrastructure changes, identifying security risks, recommending compensating controls, and ensuring security requirements are addressed prior to deployment.
  • Develop and maintain security architecture documentation, including security architecture diagrams, data flow diagrams, network security diagrams, and security control implementation narratives, ensuring documentation is current and accurately reflects the operational environment.
  • Support the design and implementation of Zero Trust Architecture principles across the enterprise environment, including micro-segmentation, identity-based access controls, continuous validation, least-privilege enforcement, and encrypted communications.
  • Provide expert security engineering guidance to infrastructure engineers, cloud operations teams, application developers, and DevSecOps engineers, ensuring security requirements are accurately translated into technical implementations across all program workstreams.
  • Evaluate emerging security technologies, tools, and capabilities, providing recommendations to program leadership and Government stakeholders on opportunities to enhance the enterprise security posture.

Security Control Implementation & Administration
  • Implement, configure, and maintain enterprise security controls across endpoint, network, application, cloud, and identity layers, ensuring controls are properly configured, continuously monitored, and aligned with applicable security baselines and compliance requirements.
  • Administer and maintain enterprise security platforms and tools, including Security Information and Event Management (SIEM) systems, Endpoint Detection and Response (EDR) platforms, Data Loss Prevention (DLP) tools, Privileged Access Management (PAM) solutions, Web Application Firewalls (WAF), and network security monitoring platforms.
  • Implement and maintain endpoint security controls, including EDR configuration and tuning, application whitelisting, host-based intrusion detection, and endpoint hardening in accordance with applicable DISA STIGs and CIS Benchmarks.
  • Implement and maintain network security controls, including firewall rule management, intrusion detection and prevention system (IDS/IPS) configuration and tuning, network segmentation, and network access control (NAC) policies.
  • Implement and maintain cloud security controls across AWS (commercial and GovCloud) and Microsoft Azure Government environments, including identity and access management (IAM), network security groups, encryption at rest and in transit, security logging and monitoring, and cloud security posture management (CSPM) capabilities.
  • Implement and maintain identity and access management security controls, including multi-factor authentication (MFA), privileged access management (PAM), role-based access control (RBAC), and identity federation configurations, in coordination with the Microsoft infrastructure and cloud operations teams.
  • Develop and maintain security baseline configurations and hardening standards for all major platform types, including Windows Server, Linux, network devices, cloud workloads, and enterprise applications, ensuring baselines are current and consistently applied across the environment.

Vulnerability Management
  • Own and manage the enterprise vulnerability management program, ensuring vulnerabilities are continuously identified, accurately assessed, prioritized, tracked, and remediated in accordance with defined timelines and risk-based prioritization criteria.
  • Conduct and oversee regular vulnerability scanning activities across all in-scope systems, applications, and cloud environments using industry-standard scanning platforms, ensuring scan coverage is comprehensive and scan results are accurate and current.
  • Analyze vulnerability scan results, applying contextual risk assessment to prioritize remediation activities based on exploitability, asset criticality, exposure, and potential business impact.
  • Develop and maintain the vulnerability remediation tracking register, ensuring all open vulnerabilities are assigned, tracked to resolution, and reported accurately in program status reports and compliance documentation.
  • Coordinate with infrastructure engineers, cloud operations teams, application developers, and system administrators to ensure timely and effective vulnerability remediation, providing technical guidance and remediation recommendations as needed.
  • Develop and maintain vulnerability management reporting capabilities, producing regular vulnerability status reports and trend analyses for program leadership and Government stakeholders.
  • Support penetration testing activities, including scoping, coordination, and remediation tracking for findings identified during authorized penetration tests and red team exercises.

Security Monitoring & Incident Response Support
  • Support the configuration, tuning, and maintenance of the enterprise SIEM platform, developing and refining detection rules, correlation queries, dashboards, and alerting configurations to improve threat detection coverage and reduce false positive rates.
  • Monitor security event feeds and SIEM alerts, triaging security events and escalating confirmed or suspected security incidents to the incident response team in accordance with defined escalation procedures and SLA requirements.
  • Develop and maintain security monitoring use cases and detection logic aligned with the MITRE ATT&CK framework, ensuring detection coverage is continuously improved as the threat landscape evolves.
  • Support cybersecurity incident response activities, providing security engineering expertise to containment, eradication, and recovery efforts, and implementing security control improvements to prevent recurrence.
  • Conduct threat hunting activities, proactively searching for indicators of compromise, adversarial TTPs, and undetected threats within the enterprise environment using available log sources, endpoint telemetry, and threat intelligence.
  • Support digital forensics activities as needed, providing security engineering context and technical analysis to support forensic investigation efforts.

Compliance, ATO & Risk Management
  • Support Authority to Operate (ATO) activities, including the implementation, documentation, and continuous monitoring of required NIST SP 800-53 security controls, system security plan (SSP) development and maintenance, security assessment support, and plan of action and milestones (POA&M) management.
  • Develop and maintain security assessment and authorization documentation, including system security plans, security control implementation statements, risk assessment reports, and continuous monitoring plans.
  • Manage the program's POA&M, ensuring all identified security weaknesses are accurately documented, assigned, tracked, and remediated in accordance with defined timelines and risk acceptance decisions.
  • Conduct continuous monitoring activities, including regular security control assessments, configuration compliance scanning, and security posture reporting, ensuring the Government maintains current and accurate visibility into the security state of all in-scope systems.
  • Support compliance with applicable Federal cybersecurity frameworks and requirements, including FISMA, NIST SP 800-53, FedRAMP, HSPD-12/FIPS 201, NIST SP 800-207 Zero Trust Architecture, OMB M-22-09, applicable DISA STIGs, and client-specific cybersecurity policies.
  • Support supply chain risk management (SCRM) activities, ensuring third-party software components, cloud services, and vendor technologies are assessed for supply chain risk in accordance with applicable Federal requirements.
  • Ensure all security engineering activities involving personally identifiable information (PII), CUI, or other sensitive data categories are conducted in accordance with applicable privacy protection requirements and data handling restrictions.

Security Automation & Tooling
  • Develop and maintain security automation scripts, playbooks, and tooling to improve the efficiency, consistency, and effectiveness of security operations activities, including vulnerability scanning, compliance checking, alert triage, and incident response.
  • Integrate security tools and capabilities with SIEM, SOAR, ITSM, and DevSecOps pipeline platforms to enable automated detection, alerting, ticketing, and response workflows.
  • Develop and maintain security metrics collection and reporting automation, ensuring program leadership and Government stakeholders receive accurate, timely, and actionable security posture data.
  • Evaluate and recommend security automation opportunities, identifying manual security processes that can be improved through scripting, orchestration, or tool integration.

Documentation, Reporting & Knowledge Sharing
  • Develop and maintain comprehensive security engineering documentation, including security architecture diagrams, security control implementation guides, hardening standards, operational runbooks, and standard operating procedures.
  • Prepare and present security status reports, vulnerability trend analyses, and security posture briefings for program leadership and Government stakeholders, communicating complex security information clearly and actionably.
  • Contribute security findings, indicators of compromise, and threat intelligence to the program's knowledge management repository, supporting broader detection, prevention, and response capabilities.
  • Provide technical guidance and mentorship to program personnel on security engineering practices, tools, and Federal compliance requirements.
  • Support the development and delivery of security awareness training materials for program personnel and Government stakeholders as directed.


Education and Experience:

Required:
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related field from an accredited college or university. Equivalent combination of education and directly relevant experience may be considered.
  • Minimum of 5 years of hands-on experience in security engineering, cybersecurity operations, or a closely related discipline within a federal government IT contracting or enterprise security environment.
  • Demonstrated hands-on experience implementing and administering enterprise security controls across endpoint, network, application, and cloud environments.
  • Experience supporting ATO activities, including NIST SP 800-53 security control implementation, SSP development, POA&M management, and continuous monitoring.
  • Experience with enterprise vulnerability management, including vulnerability scanning, risk-based prioritization, remediation tracking, and reporting.
  • Active security clearance or the ability to obtain and maintain a government background investigation and all requisite IT access authorizations. Specific clearance requirements will be confirmed at time of offer.

Preferred:
  • Prior experience serving as a Security Engineer on a federal IT O&M program of comparable scale and complexity.
  • Experience supporting FedRAMP authorization activities and implementing cloud security controls within AWS GovCloud and/or Microsoft Azur

About Koniag Government Services

Koniag Government Services Careers

Join the dynamic team at Koniag Government Services, a leader in providing innovative solutions to government clients. This esteemed company offers a plethora of job opportunities that pave the way for professional growth and career advancement in a diverse and inclusive environment.

Explore Career Opportunities

Koniag Government Services is actively hiring and offers a range of positions that cater to various skills and experiences. Whether you're a seasoned professional or a recent graduate, Koniag Government Services provides a platform to enhance your career through meaningful work in a supportive culture.

Innovation and Leadership

At the forefront of innovation, Koniag Government Services encourages its team to lead with creativity and strategic thinking. The company is committed to leadership development and diversity training, ensuring that all team members have the opportunity to excel and contribute to industry-leading projects.

Professional Growth and Development

Koniag Government Services is dedicated to the professional development of its employees. With comprehensive benefits, competitive employment packages, and opportunities for advancement, the company supports its team in achieving their career goals. Networking within the company and industry is encouraged, fostering a community of learning and mutual growth.

Internship Programs

For those starting their career journey, Koniag Government Services offers internship programs that provide real-world experience and a pathway to full-time employment. Interns gain valuable industry knowledge and develop essential skills under the guidance of experienced mentors.

Commitment to Diversity and Inclusion

Diversity is at the core of Koniag Government Services' values. The company is committed to creating an inclusive environment where diverse voices are heard and valued. Diversity training is integral, equipping the team with the tools to thrive in a multicultural setting.

Applying for a Position

To apply for a position at Koniag Government Services, candidates should prepare a resume that highlights relevant experience and skills. The interview process is designed to assess fit both for the role and the company culture, ensuring alignment with the team’s values and objectives.

Stay Connected with Koniag Government Services Careers

Explore the various job opportunities and embark on a path of professional growth and innovation. Koniag Government Services is not just a workplace but a community where careers flourish in an environment of respect, integrity, and continuous learning.

Search Koniag Government Services Jobs

Discover the exciting career opportunities available at Koniag Government Services. Search for open positions that match your skills and interests, and join a team that values curiosity, creativity, and collaboration.

Keep Up to Date

Stay informed with the latest career tips, industry insights, and company updates directly from Koniag Government Services. Engage with content that can transform your professional journey and lead to rewarding opportunities.

Job Alert Emails

Personalize your subscription to receive job alerts and insider tips tailored to your preferences from Koniag Government Services. See what exciting and rewarding opportunities await in the field of government services.
Learn more about Koniag Government Services
Size
501 employees
Industry

Similar Jobs

More Jobs at Koniag Government Services

  • Koniag Government Services
    SIEM UEBA Engineer Mid
    $95K — $115K *
    Fort Washington, MD 20744 (Prince Georges County)
    Information Technology
    In-Person
  • Koniag Government Services
    Zero Trust Engineer
    $110K — $130K *
    Fort Washington, MD 20744 (Prince Georges County)
    Information Technology
    In-Person
  • Koniag Government Services
    Sr Palo Alto Integration Engineer
    $120K — $145K *
    Washington, DC 20011 (District Of Columbia County)
    Information Technology
    In-Person
  • Koniag Government Services
    Sr Palo Alto Integration Engineer
    $120K — $145K *
    Fort Washington, MD 20744 (Prince Georges County)
    Information Technology
    In-Person
  • Koniag Government Services
    Sr Okta IAM Engineer
    $120K — $145K *
    Fort Washington, MD 20744 (Prince Georges County)
    Information Technology
    In-Person

More Information Technology Jobs

Find similar Security Engineer jobs: