Core One

SeniorSecurityEngineer

$145–195k ~AI est. Sterling, Virginia, United States
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Senior candidates.

The Brief

“Senior Security Engineer at Core One. Skills: FedRAMP authorization, NIST RMF, Cloud security, Incident response. Lead FedRAMP authorization efforts. Support FedRAMP authorization efforts”

Industry & Context.

Problems you'll solve

Risk assessment; Gap analysis; Security architecture review; Vulnerability management; Incident response; Root cause analysis

Eligibility Requirements

Active TS/SCI with Polygraph

What They're Looking For.

Must Have

Active TS/SCI with Polygraph, 5+ years' experience in Cybersecurity, Knowledge of NIST RMF, Knowledge of NIST 800-53, Knowledge of FedRAMP requirements, CISM or CISA certification, CompTIA Security+ certification, CAP certification, CCSP certification, Experience with NIST 800-53, Experience with RMF, Experience with FedRAMP, Experience with ICD 503, Experience with ServiceNow GRC, Experience with Splunk, Experience with AWS GovCloud, Experience with Azure

Nice to Have

Experience with cloud-native security tools, Knowledge of Zero Trust Architecture, Experience with cross-domain solutions, Familiarity with DevSecOps pipelines

What You'll Do.

Lead FedRAMP authorization efforts

Support FedRAMP authorization efforts

Lead IC ATO authorization efforts

Support IC ATO authorization efforts

Ensure compliance with NIST RMF

Ensure compliance with NIST 800-53

Ensure compliance with NIST 800-37

Ensure compliance with FedRAMP

Ensure compliance with ICD 503

Conduct risk assessments

Conduct security control assessments

Conduct security architecture reviews

Develop security documentation

Maintain security documentation

Track remediation activities

Execute ConMon programs

Lead vulnerability management activities

Validate remediation efforts

Coordinate risk mitigation efforts

Support Security Operations

Support Incident Response

Analyze security alerts

Investigate security incidents

Perform root cause analysis

Coordinate with government stakeholders

Design security controls for AWS GovCloud

Assess security controls for AWS GovCloud

Design security controls for Azure Government

Assess security controls for Azure Government

Implement IAM controls

Implement encryption controls

Implement logging controls

Implement least-privilege access controls

Integrate security into DevSecOps pipelines

Integrate security into CI/CD pipelines

Support audits and assessments

Prepare evidence for audits

Coordinate with auditors

Coordinate with assessors

Administer governance tools

Utilize compliance tools

Utilize monitoring tools

Utilize vulnerability management tools

Collaborate with developers

Collaborate with engineers

Collaborate with cloud architects

Collaborate with ISSOs/ISSMs

Collaborate with compliance teams

Provide cybersecurity guidance

Contribute to security governance

Contribute to policy development

Contribute to cybersecurity program maturity

Promote organizational security culture

How You'll Work.

Team & Collaboration

Developers; Engineers; Cloud architects; ISSOs/ISSMs; Compliance teams; Government stakeholders

Communication Scope

Cybersecurity guidance

Process & Methodology

Risk Management Framework (RMF), DevSecOps, CI/CD

Full Job Description

Join our team at Core One! Our mission is to be at the forefront of devising analytical, operational and technical solutions to our Nation's most complex national security challenges. In order to achieve our mission, Core One values people first! We are committed to recruiting, nurturing, and retaining top talent! We offer a competitive total compensation package that sets us apart from our competition. Core One is a team-oriented, dynamic, and growing company that values exceptional performance! Clearance Required: Active TS/SCI with Polygraph Summary We are seeking a Senior Security Engineer to support cybersecurity operations, compliance, and risk management for FedRAMP-authorized and Intelligence Community (IC) systems. This role is responsible for ensuring systems meet stringent federal security requirements while enabling secure, scalable, and compliant cloud and on-premises solutions. The ideal candidate brings deep expertise in NIST frameworks, FedRAMP authorization processes, continuous monitoring (ConMon), cloud security, incident response, and ATO lifecycle management, along with the ability to operate effectively within classified and high-security environments. The Senior Security Engineer serves as the primary cybersecurity technical authority supporting system engineering, cloud architecture, DevSecOps pipelines, compliance initiatives, and operational security monitoring. Key Responsibilities Lead and support FedRAMP Moderate/High and IC ATO authorization efforts, ensuring compliance with NIST RMF, NIST 800-53, NIST 800-37, FedRAMP, and ICD 503 requirements. Conduct risk assessments, security control assessments, gap analyses, and security architecture reviews to identify and mitigate cybersecurity risks. Manage the full Risk Management Framework (RMF) lifecycle, including system categorization, control selection, implementation, assessment, authorization, and continuous monitoring. Develop and maintain security documentation such as SSPs, SARs, POA&

Free ATS check

Applying for this Senior Security Engineer role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Greenhouse

  • Create a Greenhouse profile before applying — it saves time across multiple applications.
  • Upload your resume as a PDF; the parser handles it better than Word.
  • Answer all knockout questions carefully — wrong answers auto-reject before a human sees you.
  • Enable email notifications to track application status in real time.

ANONYMOUS · UNFILTERED

What do employees actually say about Core One?

Real rants from real employees. Read before you apply.

Read Company Rants →