Security Engineer
Location: Herndon, VA (Remote Possible)
Duration: 6 Months Contract
Employment Type: Contract
Clearance: Must be able to obtain/maintain required government suitability
Environment: AWS GovCloud | FedRAMP | FISMA Moderate | UiPath
Responsibilities:
Monitor systems for abnormal activity.
Analyze alerts, distinguish threats from false positives, and categorize incidents by risk.
Lead incident response: containment, eradication, recovery, post-incident analysis, and documenting steps.
Optimize detection capabilities: refine alert thresholds, tune SIEM rules, integrate new data sources, and reduce false positives.
Compile weekly/monthly reports on incident trends, threat activity, and security posture for internal stakeholders.
Actively participate in team meetings, client reviews, and cross-departmental syncs.
Required Skills:
5+ years of security engineering experience for a FedRAMP or FISMA Moderate system in an AWS GovCloud environment.
Hands-on UiPath architecture experience: Orchestrator, attended/unattended robots, Assets and Credential Stores, queues, and robot host builds.
Design and implementation of service account models, credential vaulting, RBAC, separation of duties, and session/audit logging.
Applied NIST SP 800-53 Rev. 5 Moderate controls in build decisions across the AC, AU, CM, IA, and SC families.
STIG/CIS hardening, vulnerability scanning, patch and configuration management.
Secure SDLC and code review of automation workflows and scripts.
Ability to translate engineering decisions into control language for the A&A team.