Cyber Security Engineer
Job Description
SHR Consulting Group, LLC supports cybersecurity work that helps strengthen national security and public welfare. This hybrid role is based in Ft Meade, MD, offering a collaborative, flexible, and forward-thinking environment, along with competitive compensation, comprehensive benefits, and career development opportunities.
Responsibilities
- Provide hands-on cybersecurity engineering support across development, testing, staging, and production environments.
- Support security for enterprise applications and infrastructure hosted in Google Cloud Platform (GCP).
- Implement and maintain technical security controls aligned to applicable organizational and federal security requirements.
- Assist with security authorization, assessment, and continuous monitoring activities.
- Identify, analyze, track, prioritize, and support remediation of vulnerabilities across applications, infrastructure, cloud platforms, and configurations.
- Review security scan results, evaluate findings, coordinate remediation with engineering and development teams, and validate corrective actions.
- Develop and maintain security artifacts and supporting documentation related to vulnerabilities and remediation efforts.
- Integrate automated security testing and security controls into DevSecOps and CI/CD processes.
- Support incident response activities including investigation, containment, remediation, and root cause analysis.
- Support security logging, monitoring, alerting, and audit capabilities.
- Develop and maintain security documentation and evidence for security assessments, audits, releases, and change-control activities.
- Protect PII, sensitive information, and system data from unauthorized access, disclosure, modification, or loss.
- Participate in Agile/SAFe planning, sprint activities, technical working sessions, and security reviews.
Requirements
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or related field, or equivalent relevant experience.
- 5+ years of cybersecurity engineering, security operations, or information systems security experience.
- Experience securing cloud-hosted applications and infrastructure, preferably within GCP.
- Experience with NIST SP 800-53, FISMA, RMF, vulnerability management, continuous monitoring, and security control implementation.
- Experience with vulnerability scanning, security monitoring/logging, incident response, and DevSecOps security practices.
- Experience supporting security assessments and remediation of identified vulnerabilities.
- CompTIA Security+ or equivalent industry-recognized security certification (Required).
Technologies
- Google Cloud Platform (GCP)
- Google Cloud Professional Cloud Security Engineer
- NIST SP 800-53
- FISMA
- RMF
- DevSecOps
- CI/CD
- Agile
- SAFe
Certifications
- CompTIA Security+ or equivalent industry-recognized security certification (Required)
- CISSP; CCSP; Google Cloud Professional Cloud Security Engineer; CompTIA CySA+; GIAC certifications (Preferred)
Compensation: USD 130,000 - 150,000 per year.