Acuity INC logo

Security Engineer

Acuity INC
  • UNAVAILABLE, DC
  • $108,000 Per Year
8 days ago

Job Description

Overview

Looking to make a difference and help protect critical government missions? Join Acuity's team of cybersecurity professionals supporting the U.S. Department of State. As a Security Engineer you will help secure enterprise infrastructure and cloud environments through continuous monitoring, vulnerability management, secure configuration and STIG enforcement, ATO sustainment, cloud security posture management, Zero Trust implementation, incident response, and compliance with federal cybersecurity standards. This role partners closely with system administrators, cloud and infrastructure engineers, security analysts, and government stakeholders to strengthen the organization's security posture while supporting modernization initiatives. The position is centered on infrastructure and cloud security rather than application-development security, while maintaining enough application security awareness to collaborate effectively across the broader Department of State security ecosystem.

Why Acuity?

Are you ready to use your expertise in the areas of IT Modernization, Data Enablement, and Hyperautomation to make a real difference? Join Acuity, Inc., a technology consulting firm that supports federal agencies. We combine industry partnerships and long-term federal experience with innovative technical leadership to support our customers’ critical missions.

Responsibilities

  • Administer and support infrastructure and cloud security technologies, including Microsoft Defender for Cloud, Microsoft Purview, SCUBA, Rapid7, Tenable, ScienceLogic, and comparable enterprise security platforms.
  • Support continuous monitoring and infrastructure security operations across servers, virtual machines, cloud platforms, networked systems, and enterprise services; identify security findings and coordinate remediation with infrastructure and operations teams.
  • Perform security assessments, vulnerability analysis, risk assessments, and security control validation in accordance with NIST RMF and Department of State security requirements.
  • Support continuous monitoring, iPost activities, security compliance, documentation, audit readiness, and ATO sustainment for enterprise systems.
  • Administer and support security technologies for vulnerability management, cloud security posture management, identity and access management (IAM), configuration management, system hardening, and security monitoring.
  • Conduct and support enterprise vulnerability management using tools such as Tenable, Rapid7, Microsoft Defender for Cloud, and comparable platforms; track findings through remediation and validation.
  • Support security incident response and remediation activities in accordance with NIST SP 800-61 and applicable Department of State guidance, coordinating with Security Operations Center (SOC) personnel as needed.
  • Review system configurations, STIGs, security baselines, and access controls to ensure compliance with least-privilege principles, Department of State requirements, and federal cybersecurity standards.
  • Support security monitoring of enterprise environments including Windows Server, VMware ESXi, VMware vCenter, Active Directory, cloud platforms, virtualized infrastructure, and associated enterprise services using tools such as ScienceLogic and other monitoring platforms.
  • Maintain working familiarity with Department of State application security and code-scanning capabilities, including Fortify and comparable SAST/DAST/SCA tools, to understand application-related findings, dependencies, and interfaces with infrastructure security; hands-on administration of these tools is not the primary focus of this role.
  • Assist with implementation and monitoring of security controls across cloud, network, and infrastructure environments, including cloud security posture management and Zero Trust initiatives.
  • Collaborate with system administrators, cloud and infrastructure engineers, security analysts, project teams, and business stakeholders to identify risks, recommend security improvements, and resolve technical issues.
  • Prepare and maintain technical documentation, security procedures, risk assessments, remediation plans, Plan of Action and Milestones (POA&Ms), ATO/compliance artifacts, and continuous monitoring documentation.
  • Perform additional duties as assigned in support of customer mission objectives.

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field (or equivalent experience).
  • Minimum of five (5) years of experience in cybersecurity engineering, infrastructure security, cloud security, security operations, or information assurance.
  • Hands-on experience with enterprise infrastructure, vulnerability management, cloud security, or security monitoring tools such as Microsoft Defender for Cloud, Microsoft Purview, SCUBA, Rapid7, Tenable, ScienceLogic, Splunk, Microsoft Sentinel, or comparable technologies.
  • Experience supporting enterprise vulnerability management, continuous monitoring, system hardening, STIG enforcement, security finding remediation, and infrastructure security operations.
  • Experience working with NIST SP 800-53, Risk Management Framework (RMF), FISMA, and Department of State or comparable federal cybersecurity policies and requirements.
  • Experience supporting vulnerability management and security monitoring solutions such as Tenable, Rapid7, Microsoft Defender for Cloud, ScienceLogic, Splunk, Microsoft Sentinel, or comparable enterprise platforms.
  • Experience with Identity and Access Management (IAM), Active Directory, Windows Server, VMware or other virtualized infrastructure, and enterprise system hardening.
  • Experience supporting security incident response, continuous monitoring, ATO sustainment, compliance initiatives, and remediation tracking.
  • Working knowledge of cloud security principles and cloud security posture management across Azure, AWS, or hybrid cloud environments.
  • Experience implementing or supporting Zero Trust security principles across enterprise infrastructure and cloud environments.
  • Working knowledge of application security concepts and tools such as Fortify, OWASP ZAP, Veracode, Checkmarx, Sonatype, or comparable technologies sufficient to collaborate with application security and development teams; deep application security engineering or code-scanning specialization is not required.
  • Familiarity with automation and infrastructure technologies such as PowerShell, Python, Ansible, Terraform, Azure DevOps, or comparable tools used to support secure infrastructure operations.
  • Understanding of network security, endpoint/server security, vulnerability remediation, configuration compliance, and security monitoring in enterprise environments.
  • Strong analytical, troubleshooting, communication, documentation, and customer service skills.
  • Ability to work independently while collaborating effectively across technical and non-technical teams.

Preferred Qualifications

  • Active cybersecurity certification such as CISSP, CCSP, Security+, CISM, CISA, CEH, Cloud+, or comparable DoD 8140-approved certification.
  • Experience supporting the U.S. Department of State or other federal civilian agencies.
  • Experience implementing Zero Trust architecture, cloud security posture management, and secure-by-design principles in federal or enterprise environments.
  • Familiarity with Fortify or other application security testing platforms used within Department of State environments is a plus, particularly where application findings intersect with infrastructure, cloud, configuration, or vulnerability remediation activities.
  • Familiarity with Department of State iPost, STIG compliance, ATO sustainment, F5, Palo Alto, or other enterprise network and infrastructure security technologies.

Clearance Requirement

  • Active Secret or Top Secret security clearance required.

 

 

Min

USD $108,000.00/Yr.

Max

USD $221,000.00/Yr.

Salary Range

The salary range for this position represents Acuity's good faith estimate of the compensation for this job title at the time of posting. Final compensation will be determined based on factors including, but not limited to, the candidate's qualifications, experience, education, certifications, skills, geographic location, contract requirements, applicable labor categories, and, where applicable, contract award and funding.

Numbers & Facts

LocationUNAVAILABLE, DC
IndustryOther/Not Classified
Company Size20 to 49 employees
Year Founded2006
Websitehttp://www.myacuity.com/

About Company

Meet Acuity: We are a Management and Technology Consulting firm specialized in addressing the unique challenges of public sector organizations. We have served 9 of 15 federal cabinet-level agencies and hold particularly deep expertise with organizations whose missions center on serving and protecting our nation’s citizens, global reputation, and critical assets.

We pride ourselves on unmatched customer service and a history of transformative client results. Each service we offer and every methodology we deploy is carefully designed to help our clients improve overall performance and achieve mission success.

Our team of pragmatic and innovative consultants is highly trained and highly skilled.

At Acuity, we work smart, we work hard, and we cultivate lasting relationships that deliver real, meaningful, and measurable results.

Skills

  • Access Controlunmatched
  • Amazon Web Services (AWS)unmatched
  • Analysis Skillsunmatched
  • Ansibleunmatched
  • Applications Securityunmatched
  • Automationunmatched
  • CCSP - Cisco Certified Security Professionalunmatched
  • CISA - Certified Information Systems Auditorunmatched
  • CISM - Certified Information Security Managerunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Cloud Architectureunmatched
  • Cloud Computingunmatched
  • CompTIA Security+unmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Configuration Managementunmatched
  • Consultingunmatched
  • Customer Support/Serviceunmatched
  • DevOpsunmatched
  • DoD Directive 8140unmatched
  • DoD Directive 8570unmatched
  • Documentationunmatched
  • Ecosystemsunmatched
  • Endpoint Securityunmatched
  • Enterprise Protectionunmatched
  • Environmental Monitoringunmatched
  • F5 Network Softwareunmatched
  • FISMA - Federal Information Security Management Actunmatched
  • Federal Compliance Regulationsunmatched
  • Federal Governmentunmatched
  • Governmentunmatched
  • Hardware Virtualizationunmatched
  • Hybrid Cloudunmatched
  • Identify Issuesunmatched
  • Identity Data Managementunmatched
  • Incident Responseunmatched
  • Information Technology & Information Systemsunmatched
  • Information/Data Security (InfoSec)unmatched
  • Internet Securityunmatched
  • Maintain Complianceunmatched
  • Microsoft Active Directoryunmatched
  • Microsoft Product Familyunmatched
  • Microsoft Windows Azureunmatched
  • Microsoft Windows Serverunmatched
  • Network Securityunmatched
  • Network Systemsunmatched
  • Operational Supportunmatched
  • Operations Security (OPSEC)unmatched
  • Problem Solving Skillsunmatched
  • Python Programming/Scripting Languageunmatched
  • Risk Analysisunmatched
  • Risk Management Framework (RMF)unmatched
  • Security Analysisunmatched
  • Security Architectureunmatched
  • Security Complianceunmatched
  • Security Infrastructureunmatched
  • Security Monitoringunmatched
  • Software Administrationunmatched
  • Software Developmentunmatched
  • Software Engineeringunmatched
  • Software Testingunmatched
  • Splunkunmatched
  • Systems Administration/Managementunmatched
  • Systems Maintenanceunmatched
  • Technical Leadershipunmatched
  • Technical Supportunmatched
  • Technical Writingunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • VMWareunmatched
  • VMWare ESX/ESXiunmatched
  • VMWare vCenterunmatched
  • Virtual Machine (VM)unmatched
  • Virtualizationunmatched
  • Windows PowerShellunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder