Security Engineer, Federal Assurance

2 Months ago • All levels • Cyber Security • $165,600 PA - $198,720 PA

Job Summary

Job Description

The Security Engineer will be responsible for supporting Assessment and Authorization and agency audit activities for Scale’s products in the US Government and global Public Sector space. This role involves leading public sector security compliance projects, collaborating with various teams to implement security controls, working with 3PAOs and federal government AOs, ensuring security configurations, conducting vulnerability scans, and leading Risk Management Assessment and Authorization processes. This position requires developing and maintaining security documentation, leading compliance reviews, evaluating new certification programs, and providing security awareness training. The ideal candidate should have a strong understanding of cybersecurity principles, project management experience, and excellent communication skills.
Must have:
  • Active US Top Secret security clearance.
  • Minimum IAT Level 2 certification (Security +, CASP, or similar).
Good to have:
  • Experience with FedRAMP, DoD Cloud Computing SRG, NIST 800-171, NIST 800-53, CMMC, NIST 800-53.
  • STIG/RMF policy knowledge & implementation.
  • Experience in project management.
  • Ability to translate between business and technical risk.
  • Excellent organizational and communications skills.
  • Understanding of cybersecurity controls for cloud service providers.
  • Knowledge of AWS and other government authorized cloud services.
  • 5+ years of security compliance or technology audit related experience.

Job Details

Our Security team works on operational issues at the leading edge of machine learning technology. You will join a creative and solutions-oriented team collaborating with internal teams at Scale and externally with our customers. Scale is looking for an experienced security and compliance professional to support Assessment and Authorization and agency audit activities for Scale’s products that are offered in the US Government and global Public Sector space. We are looking for relentlessly curious, deliberately open-minded, and action-oriented generalists who can design effective legal advice, internal policies, and operational processes while employing an empathetic interpersonal style. If you enjoy solving novel and challenging problems and building strong teams and relationships while doing it, we’d love to hear from you!

You will:

  • Lead public sector security compliance projects and audits (FedRAMP HIGH, DoD Cloud Computing SRG IL4/IL5/IL6 , NIST 800-53 rev 5, NIST 800-171/CMMC, Risk Management Framework)
  • Collaborate with product, engineering, security, operations, people operations, and legal to implement new technical, administrative, and operational controls
  • Work with 3PAOs and federal government AOs to achieve compliance certifications and reports
  • ​​Ensure the implementation, oversight, monitoring, and maintenance of security configurations, practices, and procedures 
  • Serve as a liaison between system owners and other security personnel, ensuring that selected security controls are effectively implemented and maintained throughout the lifecycle of projects
  • Act as a liaison between system owners and other security personnel to facilitate effective communication and collaboration
  • Develop, maintain, review, and update system security documentation on a continuous basis 
  • Conduct required vulnerability scans and develop Plan of Action and Milestones (POAMs) in response to reported security vulnerabilities. Manage risks by coordinating correction or mitigation actions and tracking the completion of POAMs 
  • Coordinate system owner concurrence for correction or mitigation actions and monitor security controls to maintain security Authorized To Operate (ATO)
  • Upload security control evidence to the Governance, Risk, and Compliance (GRC) application (eMASS or Xacta) to support security control implementation during the monitoring phase
  • Lead Risk Management Assessment and Authorization (A&A) processes for deployments
  • Perform Cloud system risk assessments, enhance process workflows, and develop new processes
  • Implement all applicable manual Security Technical Implementation Guides (STIGs), vendor hardening guides and ensuring timely installation of all available patches
  • Create and maintain ATO packages
  • Lead security compliance reviews for new products, changes, and features
  • Proactively evaluate and advise the business on new and evolving certification programs, requirements, and technologies
  • Develop and provide training to improve the security awareness and knowledge for all employees and contractors

Required:

Active US Top Secret security clearance with minimum IAT Level 2 certification (Security +, CASP, or similar) 

Ideally you’d have:

  • Experience implementing and maintaining some of the following frameworks and standards: FedRAMP, DoD Cloud Computing SRG, NIST 800-171, NIST 800-53, CMMC, NIST 800-53.
  • STIG/RMF policy knowledge & implementation, including validating compliance via ACAS and other relevant tests.
  • Experience in project management and taking projects from conception to launch
  • An ability to translate between business and technical risk and communicate clearly to leadership
  • Excellent organizational and communications skills
  • Understanding of cybersecurity controls for cloud service providers
  • Knowledge of AWS and other government authorized cloud services
  • 5+ years of security compliance or technology audit related experience

Nice-to-haves:

  • Bachelor’s degree in accounting, information systems, computer science, or a related field

Similar Jobs

Adyen - Demand Generation Manager

Adyen

Shanghai, China (On-Site)
1 Month ago
Canva - Account Executive, Government & Healthcare

Canva

Austin, Texas, United States (Remote)
1 Week ago
Marvell - Senior Corporate Paralegal

Marvell

Santa Clara, California, United States (On-Site)
1 Month ago
Survay Monkey - Senior Sales Enablement Program Manager

Survay Monkey

Dublin, County Dublin, Ireland (Hybrid)
1 Month ago
Epic Games - Principal Programmer, Horde

Epic Games

Montreal, Quebec, Canada (On-Site)
4 Months ago
Roof Stacks - Senior Cyber Security Engineer

Roof Stacks

Istanbul, İstanbul, Türkiye (On-Site)
3 Months ago
Zscaler - Principal Information Security Engineer - Container Security

Zscaler

Bengaluru, Karnataka, India (Hybrid)
1 Month ago
Ion - Reporter – Cybersecurity Law Report

Ion

New York, United States (On-Site)
4 Months ago
Tide - Staff Security Engineer, Identity

Tide

Delhi, India (On-Site)
2 Months ago
Crowd Strick - Platform Security Operations Engineer III

Crowd Strick

Bucharest, Bucharest, Romania (Hybrid)
1 Month ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Ion - Senior Business Consultant - Endur

Ion

London, England, United Kingdom (On-Site)
8 Months ago
Blenheim Chalcot India - Finance Manager

Blenheim Chalcot India

Mumbai, Maharashtra, India (On-Site)
3 Weeks ago
Krafton - Senior Gameplay Animator - Viewmodel

Krafton

Madison, Wisconsin, United States (On-Site)
3 Weeks ago
Zenoti - Manager - Sales Development

Zenoti

Manchester, England, United Kingdom (On-Site)
2 Weeks ago
Iron Mountain - Scanning Admin Specialist

Iron Mountain

Risley, England, United Kingdom (On-Site)
2 Months ago
Roblox - Senior Full Stack Software Engineer, Open Platform & AI Enablement

Roblox

San Mateo, California, United States (On-Site)
1 Week ago
Razer - Technical & Customer Service- Intern

Razer

Shah Alam, Selangor, Malaysia (On-Site)
2 Weeks ago
Notion - Software Engineer, Deploy Observability Infra

Notion

San Francisco, California, United States (On-Site)
1 Month ago
Tencent - Senior Combat Designer

Tencent

Shanghai, Shanghai, China (On-Site)
6 Months ago
Zenoti - Sales Development Representative - Outbound

Zenoti

Hyderabad, Telangana, India (On-Site)
2 Days ago

Get notifed when new similar jobs are uploaded

Jobs in Washington, District of Columbia, United States

sofar sounds - Freelance Producer

sofar sounds

New York, United States (Hybrid)
2 Months ago
Evolution  - In- Studio LIVE Game Presenter - Full Benefits, $20 - $25/hr- NO EXPERIENCE NECESSARY

Evolution

Atlantic City, New Jersey, United States (On-Site)
11 Months ago
Next Level Business Services - Web Development

Next Level Business Services

Moline, Illinois, United States (On-Site)
8 Months ago
Morning Star - Senior Mobile Device Management Engineer

Morning Star

Chicago, Illinois, United States (Hybrid)
1 Month ago
Scout - Specialist, Vehicle Logistics

Scout

Novi, Michigan, United States (On-Site)
1 Month ago
Tencent - Senior Strategic Sales Executive

Tencent

California, United States (On-Site)
4 Months ago
flip fit - Product Manager - Content Ecosystem

flip fit

New York, New York, United States (Hybrid)
3 Months ago
Apple - US-Business Expert

Apple

United States (On-Site)
4 Weeks ago
Penumbrainc - Supplier Quality Engineering Manager

Penumbrainc

Alameda, California, United States (On-Site)
1 Month ago
Notion - Product Manager, Growth

Notion

San Francisco, California, United States (On-Site)
1 Month ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

ZeniMax Media - Senior Application Security Engineer

ZeniMax Media

Rockville, Maryland, United States (On-Site)
1 Month ago
Ion - Vulnerability Management Analyst

Ion

London, England, United Kingdom (On-Site)
1 Week ago
CD PROJEKT RED - Cybersecurity Specialist

CD PROJEKT RED

Warsaw, Masovian Voivodeship, Poland (On-Site)
4 Months ago
CyberArk - Manager, IT Security Architecture

CyberArk

Israel (Hybrid)
1 Month ago
Anavation - Network Security Engineer

Anavation

Clarksburg, West Virginia, United States (Hybrid)
3 Months ago
Cadence - Senior Cybersecurity Engineer

Cadence

San Jose, California, United States (On-Site)
2 Months ago
NVIDIA - Senior Python Software Engineer, Security

NVIDIA

Bengaluru, Karnataka, India (Hybrid)
2 Months ago
Take-Two Interactive - Senior Analyst - Cybersecurity Policy & Compliance

Take-Two Interactive

New York, United States (On-Site)
1 Month ago
kaizen gaming  - Senior Information Security Engineer

kaizen gaming

Athens, Greece (On-Site)
2 Weeks ago
bytedance - Algorithm Engineer, Security Assurance

bytedance

Singapore (On-Site)
2 Months ago

Get notifed when new similar jobs are uploaded

About The Company

New York, United States (On-Site)

San Francisco, California, United States (On-Site)

San Francisco, California, United States (On-Site)

San Francisco, California, United States (On-Site)

San Francisco, California, United States (On-Site)

San Francisco, California, United States (On-Site)

San Francisco, California, United States (On-Site)

San Francisco, California, United States (On-Site)

San Francisco, California, United States (On-Site)

View All Jobs

Get notified when new jobs are added by Scale AI

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug