Noblis is seeking a FedRAMP Senior Cyber Engineer to enhance cybersecurity measures across federal cloud services. The role involves compliance reviews, risk-based guidance, and collaboration with industry stakeholders.
Responsibilities Are you a Cyber Security professional or a Cloud Computing Engineer/Architect interested in Cyber Security? Are you looking to make an impact across the entire federal government? Do you want to help reshape the Federal Security assurance model? Do you love researching new technologies and capabilities? Are you self-driven and detail oriented with excellent written and verbal skills? Then this job is for you! Come be a part of a growing team of highly skilled FedRAMP cyber security SMEs and help reimagine the FedRAMP process. FedRAMP Cyber Security Engineers are technologists with an eye for cyber security and policy. We are visionaries, reshaping how the Federal Government thinks about secure cloud implementation. We review security packages to evaluate compliance with FedRAMP security requirements and ensure package deliverables clearly and accurately represent the security and risk posture of the cloud service offering. FedRAMP Cyber Security Engineers review the system architecture, key performance indicators, security controls, and the results of an independent security assessment to determine suitability for government-wide use. Cyber Security Engineers work with the FedRAMP team to advise on new and emerging technologies with an emphasis on security impact. We are seeking qualified individuals to be FedRAMP SMEs and develop government-wide guidance. Key Responsibilitiesa: • Perform compliance reviews of cloud service offering (CSO) system security plans (SSPs) and/or Key Security Indicators to ensure the security posture is sufficient for multi-agency USG use • Provide risk-based guidance to cloud service providers (CSPs) to address security concerns • This position requires the successful candidate to: • Work hand-in-glove with a team of SMEs that are performing the same level of review on other portions of the compliance package • Collaboration with industry to advance transparency and efficiency • Operate in a high-visibility environment where your judgement will: • Have significant impact on cybersecurity for the USG • Be scrutinized in detail, first by your colleagues within the program, and then by external stakeholders • Be completely supported by the program when finalized • Organizationally, day-to-day activities require: • Maintaining focus on the highest priority package at hand • Rapidly shifting focus to support stakeholder review meetings to present your findings • Daily reporting of package status to coordinate multiple teams reviewing multiple packages • Contributing to, and following, detailed standard operating procedures to ensure: • Firm, fair, and consistent reviews from one package to the next • Secure handling of sensitive and proprietary vendor data • Coordination of document revision control with your team members • Exceptional candidates will have experience in several of the following areas of compliance focus: • FIPS 140 validated encryption addressing data at rest, data in transit, and MFA authenticators • Human-to-machine authentication based on NIST SP 800-63-3 • Familiarity with service offerings from hyperscale IaaS/PaaS vendors such as AWS, Azure, Google, IBM, and Oracle such as: • How a vendor implements TCP/IP constructs within their respective software defined networking (SDN) architectures • Which implementations are deployed for customers by default, versus requiring customer configuration, or entirely a customer responsibility • Aspects of DNS including DNSSEC, typical configurations for DDoS protection, DNS over TLS (DoT), and DNS over HTTPS (DoH) • Domain-based Message Authentication, Reporting & Conformance (DMARC) for email • Research evolving Federal policy and guidance for application to FedRAMP initiatives and cloud service reviews • Develop policy/guidance for new/emerging technologies Required Qualifications • Understanding of government cryptography requirements • Strong understanding of cloud architecture, various cloud technologies, and security concepts • Strong understanding of networking principles and security best practices Strong analytical and writing skills • Strong technical research skills • Strong communication skills and ability to explain complex technical concepts to non- technical stakeholders • Excellent teamwork, organizational, communication, and collaboration skills • US citizen and eligible for public trust Jr level Bachelor's degree in Computer Science, Software Engineering, or a related field plus 3 years of experience OR Master's degree in Computer Science, Software Engineering, or a related field plus 1 years of experience; or Associate's Degree + 6 years of experience, Or High School diploma or equivalent + 9 years of experience. • Compensation: $77,000 - $120,275 Mid level Bachelor's degree in Computer Science, Software Engineering, or a related field plus 5 years of experience. OR Master's degree + 3 years of experience; or Associate degree + 8 years of experience, Or High School diploma pr equivalent + 11 years of experience. • Compensation: $93,200 - $145,550 Senior level Bachelor's degree in Computer Science, Software Engineering, or a related field plus 8 years of experience; OR Master's degree + 6 years of experience; or Associate's degree + 11 years of experience; or High School diploma + 14 years of experience. • Compensation: $112,700 - $176,150 Desired Qualifications • Application development • Security automation techniques • Security testing and penetration testing experience • Vulnerability management experience • API development and security practices • Experience developing enterprise security policies and procedures • OSCAL experience • CISSP, CISA, CISM or similar certifications • Experience with operating system or network security management Experience managing incident response and after-action remediation • Post graduate degree in computer science, cybersecurity or information systems Overview Noblis (/ noblis. org/) and our wholly owned subsidiaries, Noblis ESI , and Noblis MSD tackle the nation's toughest problems and apply advanced solutions to our clients' most critical missions. We bring the best of scientific thought, management, and engineering expertise together in an environment of independence and objectivity to deliver enduring impact on federal missions. Noblis works with a wide range of government clients in the defense, intelligence and federal civil sectors. Learn more at Noblis -About Us (/careers. noblis. org/about-noblis/) Why work at a Noblis company? Our employees find greater meaning in.
Noblis is seeking a FedRAMP Senior Cyber Engineer to enhance cybersecurity across federal cloud services. The role involves compliance reviews, risk-based guidance, and collaboration with industry experts.
Noblis is seeking a FedRAMP Senior Cyber Engineer to enhance cybersecurity measures across federal cloud services. The role involves compliance reviews, risk-based guidance, and collaboration with industry stakeholders.
Noblis is seeking a FedRAMP Senior Cyber Engineer to enhance federal cybersecurity through compliance reviews and guidance for cloud service offerings. This role involves collaboration with experts to reshape the FedRAMP process and ensure secure cloud implementations.
Noblis is seeking a FedRAMP Senior Cyber Engineer to enhance cybersecurity practices across federal cloud services. The role involves compliance reviews, risk-based guidance, and collaboration with industry experts.
Noblis is seeking a FedRAMP Senior Cyber Engineer to enhance cybersecurity across federal cloud services. The role involves compliance reviews, risk guidance, and collaboration with industry experts.
Noblis is seeking a FedRAMP Senior Cyber Engineer to evaluate cloud service offerings for compliance with federal security requirements. The role involves collaboration with a team of experts to enhance the FedRAMP process and ensure secure cloud implementations across the federal government.
Noblis is seeking a FedRAMP Senior Cyber Engineer to enhance cybersecurity across federal cloud services. The role involves compliance reviews, risk-based guidance, and collaboration with industry experts.
Noblis is seeking a FedRAMP Senior Cyber Engineer to enhance cybersecurity measures across federal cloud services. The role involves compliance reviews, risk-based guidance, and collaboration with industry stakeholders.
Noblis is seeking a FedRAMP Senior Cyber Engineer to enhance federal cybersecurity through compliance reviews and guidance for cloud service offerings. This role involves collaboration with experts to reshape the FedRAMP process and ensure secure cloud implementations.
Noblis is seeking a FedRAMP Senior Cyber Engineer to enhance cybersecurity practices across federal cloud services. The role involves compliance reviews, risk-based guidance, and collaboration with industry experts.
Noblis is seeking a FedRAMP Senior Cyber Engineer to enhance cybersecurity across federal cloud services. The role involves compliance reviews, risk guidance, and collaboration with industry experts.
Noblis is seeking a FedRAMP Senior Cyber Engineer to evaluate cloud service offerings for compliance with federal security requirements. The role involves collaboration with a team of experts to enhance the FedRAMP process and ensure secure cloud implementations across the federal government.
Noblis is seeking a FedRAMP Senior Cyber Engineer to enhance cybersecurity across federal cloud services. The role involves compliance reviews, risk-based guidance, and collaboration with industry experts.
Noblis is seeking a FedRAMP Senior Cyber Engineer to enhance cybersecurity measures across federal cloud services. The role involves compliance reviews, risk-based guidance, and collaboration with industry stakeholders.
Noblis is seeking a FedRAMP Senior Cyber Engineer to enhance cybersecurity measures across federal cloud services. The role involves compliance reviews, risk-based guidance, and collaboration with industry stakeholders.