InfoSec Engineer III

Wichita Tribal Enterprise US,
Onsite

About The Position

This position is contingent upon contract award. Wichita Tribal Enterprises, a Quivera Enterprises company, is seeking an experienced Information Security Engineer III to support the Department of the Interior (DOI), Indian Affairs (IA) Office of Information Technology (OIT). This position provides senior-level cybersecurity engineering and Risk Management Framework (RMF) support for enterprise information systems, ensuring compliance with federal cybersecurity requirements and NIST guidance. The Information Security Engineer III serves as a subject matter expert responsible for developing security authorization packages, conducting security assessments, implementing RMF processes, developing security policies, and advising leadership on enterprise cybersecurity strategy. This role partners with federal stakeholders, project managers, and technical teams to ensure information systems remain secure, compliant, and authorized to operate.

Requirements

  • Bachelor's degree and six (6) years of relevant experience; or Master's degree and five (5) years of relevant experience; or Eight (8) years of directly related experience in lieu of a degree.
  • Industry-recognized cybersecurity certification may substitute for one year of experience.
  • Minimum four (4) years of full-time experience conducting security assessments and developing complete RMF authorization packages.
  • Experience implementing the NIST Risk Management Framework (RMF).
  • Extensive experience developing Authority to Operate (ATO) packages.
  • Experience conducting risk assessments and security control assessments.
  • Experience implementing and documenting NIST SP 800-53 security controls.
  • Strong understanding of: NIST SP 800-37, NIST SP 800-53, FIPS 199, FIPS 200, Risk Assessments, Configuration Management, Vulnerability Management, Contingency Planning, Disaster Recovery, Continuous Monitoring.
  • Experience writing security policies, procedures, and technical documentation.
  • Excellent written and verbal communication skills.

Nice To Haves

  • CISSP
  • CAP (Certified Authorization Professional)
  • CISM
  • Security+
  • CASP+
  • CEH
  • Experience supporting Department of the Interior, Bureau of Indian Affairs, Department of Energy, Department of Defense, or other federal agencies.
  • Experience with eMASS, CSAM, Xacta, Archer, or similar Governance, Risk, and Compliance (GRC) platforms.
  • Experience with cloud security and FedRAMP.
  • Knowledge of industrial control systems (ICS) or operational technology (OT) security.
  • GSEC
  • GSLC

Responsibilities

  • Lead implementation of the NIST Risk Management Framework (RMF) throughout the system development lifecycle.
  • Develop, maintain, and update complete authorization packages supporting Authority to Operate (ATO), Interim Authority to Test (IATT), and continuous authorization activities.
  • Develop and maintain System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), Risk Assessment Reports (RARs), Configuration Management Plans, Contingency Plans, Incident Response Plans, Privacy documentation, and supporting RMF artifacts.
  • Conduct security categorization and control selection in accordance with FIPS 199, FIPS 200, NIST SP 800-37, and NIST SP 800-53.
  • Perform comprehensive security assessments of technical, operational, and management controls.
  • Evaluate implementation of NIST SP 800-53 security controls and document compliance findings.
  • Identify system vulnerabilities and recommend risk mitigation strategies.
  • Develop remediation plans and assist technical teams with corrective actions.
  • Conduct vulnerability assessments and support remediation validation activities.
  • Ensure compliance with applicable federal cybersecurity regulations, Department of the Interior policies, and Indian Affairs security requirements.
  • Provide technical security guidance supporting enterprise applications, infrastructure, cloud services, and industrial control systems.
  • Support secure system architecture reviews and recommend security enhancements.
  • Evaluate proposed system modifications to ensure security requirements are incorporated throughout the System Development Life Cycle (SDLC).
  • Participate in continuous monitoring activities and support ongoing authorization requirements.
  • Review security documentation for completeness, accuracy, and regulatory compliance.
  • Develop and maintain cybersecurity policies, standards, procedures, and Standard Operating Procedures (SOPs).
  • Recommend improvements to enterprise security governance and compliance processes.
  • Assist senior leadership in developing organization-wide remediation strategies for cybersecurity weaknesses.
  • Provide strategic recommendations supporting the continued maturity of the Indian Affairs cybersecurity program.
  • Promote a security-first culture across the organization.
  • Provide cybersecurity oversight and recommendations for new and existing IT projects.
  • Partner with Project Managers, System Owners, Information System Security Officers (ISSOs), Information Owners, and technical teams throughout project lifecycles.
  • Coordinate with federal agencies, vendors, and cybersecurity Subject Matter Experts to remain informed of evolving technologies, threats, and regulatory changes.
  • Present cybersecurity findings and risk recommendations to executive leadership.
  • Support audit activities and security reviews.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service