Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Booz Allen Hamilton

Information Systems Security Engineer

Booz Allen Hamilton

. Engineer, implement, and assess security controls for cloud-hosted information systems in accordance with RMF, ICD 503, NIST guidance, and assessment and authorization requirements .

Posted 9/24/2026full-timeReston • Virginia • United StatesSeniorLead💰 $99,000 - $225,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in engineering and implementing security controls for cloud-hosted information systems, with a strong focus on compliance with RMF, ICD 503, and NIST guidance. Proficient in developing A&A artifacts and applying security best practices such as Zero Trust and defense in depth.

Highest-signal resume keywords
Cloud Security EngineeringSecurity Control AssessmentA&A Artifacts DevelopmentZero Trust ImplementationTS/SCI Clearance

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Information Systems Security EngineeringSecurity Control ImplementationVulnerability ManagementConfiguration ComplianceInfrastructure as CodeAutomated Security ConfigurationSecurity Assessment PlansControl ValidationContinuous MonitoringRisk Assessment
Soft Skills
Communication of Security RisksStakeholder Engagement
Tools & Technologies
SIEMSOARTerraformAnsibleAPIsCloud Security Posture Management
Certifications & Qualifications
Associate Level Security CertificationProfessional Level Security CertificationArchitecture CertificationNetworking CertificationCloud Operations Certification
Industry Keywords
RMFICD 503NIST GuidanceGovernment Information SystemsClassified Information Systems

Tech Stack

Tools & technologies
AnsibleCloudCyber SecurityTerraformTypeScript

About the role

Key responsibilities & impact
  • Engineer, implement, and assess security controls for cloud-hosted information systems in accordance with RMF, ICD 503, NIST guidance, and assessment and authorization requirements
  • Translate security requirements, system architectures, data flows, and mission use cases into implementable technical controls and documented security designs
  • Develop and maintain A&A artifacts, including system security plans, control implementation statements, architecture diagrams, security assessment plans and procedures, POA&Ms, continuous-monitoring plans, and evidence packages
  • Assess control implementation and effectiveness, identify security gaps and residual risk, recommend remediation, and track corrective actions to closure
  • Apply Zero Trust, least privilege, defense in depth, segmentation, encryption, auditability, and secure configuration practices
  • Perform security engineering across requirements analysis, architecture reviews, implementation oversight, vulnerability remediation, testing, deployment, and operational transition
  • Support security assessments, authorization decisions, control validation, audit readiness, and continuous-monitoring activities
  • Communicate security risks, decisions, compliance status, remediation plans, and technical recommendations to program stakeholders

Requirements

What you’ll need
  • 8+ years of experience in information systems security engineering, cloud security, or cybersecurity
  • Experience engineering, implementing, and assessing security controls for cloud-hosted information systems in accordance with RMF, ICD 503, NIST guidance, and assessment and authorization processes
  • Experience securing cloud environments across identity, network, compute, storage, database, logging, monitoring, encryption, secrets management, and privileged-access capabilities
  • Experience translating security requirements, system architectures, data flows, and mission use cases into implementable technical controls and documented security designs
  • Experience developing and maintaining A&A artifacts, including system security plans, control implementation statements, security assessment plans, POA&Ms, continuous-monitoring plans, and evidence packages
  • Experience applying Zero Trust, least privilege, defense in depth, segmentation, encryption, auditability, and secure configuration practices
  • Experience performing security engineering across the system lifecycle
  • Ability to assess control effectiveness, identify security gaps and residual risk, recommend remediation, and track corrective actions to closure
  • TS/SCI clearance required; willingness to take a polygraph exam
  • Bachelor’s degree
  • Experience supporting classified, Government, or highly regulated information systems
  • Experience with vulnerability management, configuration compliance, SIEM, SOAR, endpoint security, or cloud security posture management tools
  • Experience with infrastructure as code and automated security configuration using Terraform, OCI Resource Manager, Ansible, APIs, or scripting
  • Experience supporting authorization packages, control validation, audit readiness, remediation tracking, or continuous monitoring in an agency environment
  • Associate or Professional level security, architecture, networking, or cloud operations certification

Benefits

Comp & perks
  • Health benefits
  • Life insurance
  • Disability benefits
  • Financial benefits
  • Retirement benefits
  • Paid leave
  • Professional development
  • Tuition assistance
  • Work-life programs
  • Dependent care
  • Recognition awards for exceptional performance and superior demonstration of values