Systems Security Engineer
Listed on 2026-02-24
-
IT/Tech
Cybersecurity, Information Security, Systems Engineer, IT Consultant
Overview
Date Posted: 02/18/2026
Date posted by:
Rose International
Position Number: 497221
Industry: Government
Job Title:
Systems Security Engineer
Job Location:
Austin, TX, USA, 78751
Work Model:
Hybrid (2 days on-site, 3 days remote)
Shift: M-F, 8-5
Employment Type:
Temporary
FT/PT:
Full-Time
Estimated Duration (In months): 6
Min Hourly Rate($): 95.00
Max Hourly Rate($): 110.00
Must Have Skills/Attributes: CMS, Compliance, Enterprise Architecture, Governance, Implementation, Risk Analysis, Security, SSP
Nice To Have Skills/Attributes:
State Agency experience
Experience Desired:
Governance, Risk & Compliance (GRC), Enterprise Security & Architecture, Vulnerability Management (12 yrs);
Penetration Testing, Cloud Security, and hybrid environments (12 yrs);
Owning end to end development of SSP documentation (10 yrs); CMS MARS E v2.2 or comparable federal/state security frameworks (10 yrs);
Control implementation documentation, audit evidence collection/validation, and POA&M creation (10 yrs); NIST 800 53, NIST RMF, and privacy control frameworks (8 yrs);
Secure SDLC and Dev Sec Ops practices (8 yrs)
C2C is not available
Job Description
Candidates must be located in the Austin, TX area
Minimum Requirements- 12 years – Deep experience in Governance, Risk & Compliance (GRC), Enterprise Security & Architecture, Vulnerability Management, Penetration Testing, Cloud Security, and hybrid environments
- 10 years – Proven experience owning end to end development of SSP documentation
- 10 years – Hands on experience with CMS MARS E v2.2 or comparable federal/state security frameworks
- 10 years – Strong expertise in control implementation documentation, audit evidence collection/validation, and POA&M creation, tracking, and remediation management
- 8 years – Ability to translate technical security issues into compliance aligned remediation requirements
- 8 years – Strong stakeholder management experience across security, infrastructure, and application teams
- 8 years – Excellent written and verbal communication skills, especially for executive audiences
- 8 years – Knowledge of NIST 800 53, NIST RMF, and privacy control frameworks
- 8 years – Knowledge of Secure SDLC and Dev Sec Ops practices
- 5 years – Experience operating in multi vendor, multi platform enterprise environments
- 5 years – Demonstrated ability to reduce repeat audit findings and improve compliance maturity
- 5 years – Experience mentoring or guiding teams on security governance best practices
- 1 year – Experience supporting HHSC systems, including SSP development and compliance efforts
- The Security Engineer leads security governance, compliance, and risk management initiatives with a specialized focus on System Security & Privacy Plans (SSP/SSPP).
- This role serves as a critical bridge between technical security operations and regulatory compliance, ensuring audit readiness, timely vulnerability remediation, and secure delivery of public facing services across complex, hybrid, and multi platform environments.
- The engineer will develop and maintain assessor ready documentation, drive POA&M remediation, and oversee adherence to federal/state security frameworks and NIST controls.
- Lead end-to-end development, maintenance, and updates of System Security & Privacy Plans (SSP/SSPP) for enterprise systems
- Manage POA&M lifecycle activities to ensure timely remediation and closure of compliance gaps
- Translate penetration testing and vulnerability assessment findings into actionable remediation artifacts (EPICs, user stories)
- Collaborate with application, infrastructure, and security teams to validate remediation efforts through re-testing and evidence collection
- Oversee risk based vulnerability management programs, including prioritization and SLA driven remediation tracking
- Provide governance oversight for endpoint protection, web application security, and cloud security controls
- Produce assessor ready documentation, including configurations, monitoring evidence, approvals, and incident response traceability
- Maintain continuous audit readiness and reduce repeat findings through structured governance and documentation discipline
- Only those lawfully authorized…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).