Security Engineer
Hybrid in Austin, TX, US • Posted 7 hours ago • Updated 7 hours ago

Y & L Consulting Inc.
Dice Job Match Score™
⭐ Evaluating experience...
Job Details
Skills
- Security
- GRC
- Cloud Security
- SSP
- CMS MARS E
- DevSecOps
- NIST
Summary
We are seeking an experienced Security Engineer for a hybrid contract in Austin, TX.
Responsibilities:
- The Security Engineer will project work by leading security governance, compliance, and risk management activities, with a strong focus on System Security & Privacy Plans (SSP/SSPP). This role bridges technical security operations and regulatory compliance, ensuring audit readiness, effective vulnerability remediation, and secure delivery of public-facing services across complex, multi-platform environments.
- Lead end to end System Security & Privacy Plan (SSP/SSPP) development, maintenance, and updates for enterprise systems
- Drive remediation activities through POA&M management, ensuring timely closure of compliance gaps
- Translate penetration testing and vulnerability findings into actionable remediation work items (EPICs/user stories)
- Coordinate with application, infrastructure, and security teams to validate remediation through re-testing and evidence
- Oversee risk-based vulnerability management, including prioritization and SLA-driven remediation
- Provide governance oversight for endpoint protection, web application security, and cloud security controls
- Produce assessor ready documentation, including configurations, monitoring evidence, approvals, and incident traceability
- Support continuous audit readiness and reduce repeat findings through disciplined governance and documentation practices
Minimum Qualifications:
- 12 years experience with Governance, Risk, and Compliance (GRC), Enterprise Security and Security Architecture, Vulnerability Management and Penetration Testing , Cloud Security and hybrid environments
- 10 years of Proven experience owning SSP development end to end
- 10 years of Hands on experience with CMS MARS E v2.2 or comparable federal/state security frameworks
- 10 years Strong expertise in: Control implementation documentation, Audit evidence collection and validation, POA&M creation, tracking, and remediation management
- 8 years experience translating technical security issues into compliance aligned remediation actions
- 8 years experience of stakeholder management skills across security, infrastructure, and application teams
- 8 years of Excellent written and verbal communication skills, particularly for executive stakeholders
- Knowledge of NIST 800 53, NIST RMF, and privacy controls
- Knowledge of Secure SDLC and DevSecOps practices
Preferred Qualifications:
- Experience operating in multi-vendor, multi-platform environments
- Demonstrated ability to reduce repeat audit findings and improve compliance maturity
- Experience mentoring or guiding teams on security governance best practices
What We Offer:
Sistema offers competitive pay and solid benefits, including medical, dental, and vision coverage. We keep things simple, focus on people, and prioritize long-term relationships with our clients and consultants.
Apply now if you re a clear communicator, problem solver, and ready to work hybrid in Austin, TX!
- Dice Id: ylcon
- Position Id: 8890206
- Posted 7 hours ago
Company Info
About Y & L Consulting Inc.
Y&L Consulting is a provider of the highest-caliber local and international IT professionals, positioned to help you maximize profitability and growth.
As a global corporation with local presence and sensitivity, Y&L offers IT services and support primarily to medium and large companies. Knowledgeable and proficient in all primary technologies, we customize programs to fit your current business needs while maintaining the flexibility to ramp up or down as your situations change. By avoiding stringent service provider contracts and rigid methodologies, you enjoy flexible capabilities, local relationships, international resources, and significant cost savings.
IT Consulting San Antonio Expertise
Design, architecture, development, and maintenance of custom applications using ATG, MS, .NET, Java/J2EE, and other popular technologies
Implementation, upgrade, and maintenance for packaged application solutions SAP, PeopleSoft, Oracle Apps, Cognos, and Actuate
Quality Assurance and Testing Services Mercury partner
Programmers and Database Administrators
In addition, we have a number of highly-qualified Project Managers, Business Analysts, and Technical Writers on our bench.
Similar Jobs
It looks like there aren't any Similar Jobs for this job yet.
Search all similar jobs