Security Engineer/Cyber Security Analyst
Overview
In this role you will serve as the security authority for RMF and ATO processes, ensuring AI/ML systems meet strict security and compliance requirements. You will collaborate with AI/ML teams to embed security throughout development and production. You will maintain security documentation and lead assessments to uphold ongoing compliance, while keeping pace with evolving cyber threats and NIST guidance. This is a chance to shape secure AI/ML deployments in a consulting setting.
ResponsibilitiesLead and manage the RMF and ATO process for new and existing systems; serve as SME on NIST 800-53 controlsDevelop and maintain SSP, SAR, POA&M, and Continuous Monitoring StrategyPerform security control assessments and gap analyses; drive remediation with engineering teamsEmbed security into AI/ML development lifecycle (AISecOps); conduct threat modeling for AI systemsSecure AI training data pipelines, model repositories, and inference endpointsDesign/implement security architecture for cloud and on-prem environments hosting AI workloadsConfigure/manage security tooling for vulnerability scanning, IDS, and log management (Tenable, Splunk, Wiz)Implement IAM, network security controls, and data encryption; manage continuous monitoring and posture improvementsStay current with cybersecurity threats and evolving NIST guidelines; analyze findings from audits and logs
Key requirementsBachelor’s degree in computer science, Cybersecurity, Information Technology, or related field, or equivalent practical experience5 years of hands-on cybersecurity engineering/analyst experienceExpert-level RMF experience and successful ATO for federal/DoD systemsDeep knowledge of NIST 800-53 (Rev 4 or 5) and practical implementationStrong cloud security background (AWS, Azure, or GCP) and infrastructure-as-code (Terraform, CloudFormation)Experience with security assessment and scanning toolsExcellent written and verbal communication skillsExcellent written and verbal communicationTranslate complex technical concepts for engineers and managementCross-functional collaborationNIST RMF and NIST 800-53 controlsAI/ML security and AISecOpsThreat modeling for AI systems