Demonstrated ability to review technical controls directly, as a core part of the role — for example: verifying FIPS-validated encryption, auditing SIEM logging architecture, reviewing IAM/MFA enforcement (AD, Okta, Azure AD), analyzing firewall/ACL/Security Group configurations, and evaluating DISA STIG results. About steampunk : Steampunk relies on several factors to determine salary, including but not limited to geographic location, contractual requirements, education, knowledge, skills, competencies, and experience.