EngineerJobs.io
← Back to all jobs

Job Description

The IT Senior Security Engineer position is a hands-on security role on the National Library of Medicine Security Compliance team. The focus is on implementing and improving security controls and compliance across hybrid on-prem and cloud environments, including automation and continuous monitoring.

Location and Work Schedule

  • Bethesda, MD (onsite)
  • Onsite requirement: 3 to 5 days per week based on changing needs

Employment Type

  • Full-time

Key Responsibilities

  • Enhance and automate security and compliance checks using scripting and available tools; evaluate emerging technologies, including AI capabilities, to expand security coverage and improve operational efficiency.
  • Lead efforts to integrate AI/ML-driven capabilities with current security tools and operations, including automated assessment and remediation using LLM within NLM.
  • Implement and maintain security controls across on-prem and cloud environments (AWS, GCP, Azure) to ensure compliance with FISMA, NIH policy, and applicable federal security requirements.
  • Recommend and support security services for identity access, privileged access, vulnerability management, encryption, network micro-segmentation, and centralized log management across cloud and on-prem systems.
  • Integrate and optimize enterprise security and SIEM solutions (including Splunk and Tenable) to support continuous monitoring, event correlation, and compliance visibility in hybrid environments.
  • Perform threat modeling and security assessments for cloud deployments, identify and mitigate vulnerabilities, and support secure cloud migrations.
  • Provide security guidance, best practices, and compliance support to developers, operations teams, and system owners to promote security awareness across the organization.
  • Analyze vulnerability and assessment data to identify systemic risks, remediation trends, and opportunities to improve processes or tools, collaborating with system administrators and security teams for practical, risk-informed remediation.
  • Contribute to and manage documentation, standard operating procedures, and technical guidance to support the broader security program and consistent practices.

Required Qualifications

  • Extensive experience securing on-premises and cloud environments (AWS, GCP, Azure), with strong working knowledge of cloud security models, logging, tagging strategies, ephemeral resource tracking, and cross-platform operations, including hands-on security engineering in federal or regulated settings.
  • 10+ years securing information technology, plus 7+ years hands-on security engineering grounded in systems administration, including at least 3 years focused on cloud security and administration of Linux and Windows endpoints.
  • Familiarity with AI/ML integration in security tooling and operations for modern threat detection and remediation approaches.
  • Demonstrated expertise applying federal compliance frameworks and processes, including FISMA, NIST 800-53, FedRAMP, RMF, and supporting system authorization activities such as ATO and POA&M.
  • Admin or engineering-level experience with at least two security tools such as Tenable, Checkmarx, or Splunk, including understanding vulnerability management, application security testing, and remediation workflows.
  • Bachelor’s degree in computer science, cybersecurity, information technology, or related technical field (or equivalent technical experience).
  • CISSP certification (or ability to obtain within 6 months).
  • Ability to collaborate with and guide multi-disciplinary teams managing servers, workstations, network and security appliances within regulated environments, with adaptability to shifting priorities.
  • Strong written and verbal communication skills, including the ability to produce clear security documentation and explain technical concepts to technical and non-technical stakeholders.

Technologies and Tools

  • AWS, GCP, Azure
  • Splunk, Tenable, Checkmarx
  • FISMA, NIST 800-53, FedRAMP, RMF
  • ATO, POA&M
  • AI/ML, LLM
  • PowerShell, Bash, Python
  • Linux, Windows, Linux and Windows endpoints
  • Docker, Kubernetes

Desired Qualifications

  • Hands-on experience with AI/ML automation, security event correlation, asset inventory tracking, and SIEM management (preferably in Splunk) using scripting or programming such as PowerShell, Bash, Python or equivalent, including use of APIs.
  • Advanced Linux and Windows administration experience, including being certified in AWS, Azure, and GCP.
  • Experience with container security, such as Docker and Kubernetes.
  • Master’s degree in computer science, Cybersecurity, Information Technology, or a related technical field.

Minimum Experience and Education

  • Minimum experience: 10 years
  • Education: Bachelor’s degree in computer science, cybersecurity, information technology, or related technical field (or equivalent technical experience)

Similar Jobs