Security Engineer
Listed on 2026-02-28
-
IT/Tech
Cybersecurity, Information Security, IT Consultant, Systems Engineer
Our government client is seeking an experienced Security Engineer on a hybrid 6+ months renewable contract opportunity in Austin, TX
.
Security Engineer
Job DescriptionThe Security Engineer will project work by leading security governance, compliance, and risk management activities, with a strong focus on System Security & Privacy Plans (SSP/SSPP). This role bridges technical security operations and regulatory compliance, ensuring audit readiness, effective vulnerability remediation, and secure delivery of public-facing services across complex, multi-platform environments.
Responsibilities- Lead end to end System Security & Privacy Plan (SSP/SSPP) development, maintenance, and updates for enterprise systems
- Drive remediation activities through POA&M management, ensuring timely closure of compliance gaps
- Translate penetration testing and vulnerability findings into actionable remediation work items (EPICs/user stories)
- Coordinate with application, infrastructure, and security teams to validate remediation through re-testing and evidence
- Oversee risk-based vulnerability management, including prioritization and SLA-driven remediation
- Provide governance oversight for endpoint protection, web application security, and cloud security controls
- Produce assessor ready documentation, including configurations, monitoring evidence, approvals, and incident traceability
- Support continuous audit readiness and reduce repeat findings through disciplined governance and documentation practices
Minimum years of experience: 12 years required deep focus on Governance, Risk, and Compliance (GRC), Enterprise Security, Security Architecture, Vulnerability Management, Penetration Testing, Cloud Security and hybrid environments.
Requirements: 10 years required proven experience owning SSP development end to end; 10 years required hands on experience with CMS MARS E v2.2 or comparable federal/state security frameworks; 10 years required strong expertise in control implementation documentation, audit evidence collection and validation, POA&M creation, tracking, and remediation management; 8 years required ability to translate technical security issues into compliance aligned remediation actions;
8 years required strong stakeholder management skills across security, infrastructure, and application teams; 8 years required excellent written and verbal communication skills, particularly for executive stakeholders; 8 years required knowledge of NIST 800-53, NIST RMF, and privacy controls; 8 years required knowledge of Secure SDLC and Dev Sec Ops practices; 5 years preferred experience operating in multi-vendor, multi-platform environments; 5 years preferred demonstrated ability to reduce repeat audit findings and improve compliance maturity;
5 years preferred experience mentoring or guiding teams on security governance best practices; 1 year preferred experience supporting HHSC systems, including SSP development and compliance.
Skills and Qualifications
- 12 Years Required deep focus on Governance, Risk, and Compliance (GRC), Enterprise Security and Security Architecture, Vulnerability Management and Penetration Testing, Cloud Security and hybrid environments
- 10 Years Required proven experience owning SSP development end to end
- 10 Years Required hands on experience with CMS MARS E v2.2 or comparable federal/state security frameworks
- 10 Years Required strong expertise in control implementation documentation, audit evidence collection and validation, POA&M creation, tracking, and remediation management
- 8 Years Required ability to translate technical security issues into compliance aligned remediation actions
- 8 Years Required strong stakeholder management skills across security, infrastructure, and application teams
- 8 Years Required excellent written and verbal communication skills, particularly for executive stakeholders
- 8 Years Required knowledge of NIST 800-53, NIST RMF, and privacy controls
- 8 Years Required knowledge of Secure SDLC and Dev Sec Ops practices
- 5 Years Preferred experience operating in multi-vendor, multi-platform environments
- 5 Years Preferred demonstrated ability to reduce repeat audit findings and improve compliance maturity
- 5 Years Preferred experience mentoring or guiding teams on security governance best practices
- 1 Year Preferred experience supporting HHSC systems, including SSP development and compliance
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).