Lead Security Engineer

Emagine IT•Rockville, MD
•Remote

About The Position

Emagine IT is seeking a Lead Security Engineer to lead the security engineering workstream of the Government's cybersecurity program. As designated Key Personnel, this role directs technical security architecture, continuous monitoring, Zero Trust, and emerging-technology security across the Government's hybrid AWS environment, and leads the engineers who operate the Government's security tools and build the program's automation, dashboards, and DevSecOps pipeline. The Lead Security Engineer translates Department and agency security requirements into practical technical solutions for system owners and developers. Consistent with the CIO-SP3 Systems Engineer – Level III labor category, the role supervises, coordinates, and performs additions and changes to systems and attached devices, participates in planning, design, and technical review of new infrastructure, and diagnoses and resolves complex problems.

Requirements

  • Undergraduate degree.
  • At least 8 years of enterprise security architecture, security engineering, and system administration experience, and 2 to 3 years of cloud security experience.
  • One of CISSP, CAP, CEH, Security+, GCIH, OSCP, or equivalent.
  • Familiarity with CDM and DevOps concepts and capabilities, such as CI/CD and infrastructure as code.
  • U.S. citizen or lawful permanent resident.
  • Ability to obtain and maintain a Public Trust suitability determination (Tier 4 likely given privileged access; to be confirmed with the Government), obtain a Government PIV card, and sign the Government Contractor Non-Disclosure Agreement and Government Rules of Behavior before receiving access to Government systems or data.
  • Must complete Government security awareness, privacy, and records management training before performing work and annually thereafter.

Nice To Haves

  • Cloud security certification: AWS Certified Security – Specialty, Azure Security Engineer, or CCSP (PWS: highly preferred).
  • Experience with the CISA Zero Trust Maturity Model 2.0, SCuBA baselines, and CDM Phase 4.
  • Experience in federal health-sector environments handling PII/PHI.

Responsibilities

  • Supervise, coordinate, and/or perform additions and changes to security tools, network and operating system configurations, and attached devices, including investigation, analysis, recommendation, configuration, installation, and testing.
  • Provide direct support for day-to-day operations, including evaluation of system utilization, monitoring response time, and primary support for detection and correction of operational problems; diagnose and resolve complex problems.
  • Participate in planning, design, technical review, and implementation of new security infrastructure, and provide technical consultation, training, and support to IT staff as designated by the Government.
  • Design, implement, and maintain a NIST SP 800-137 continuous monitoring program for all Government systems, delivering the Continuous Monitoring Implementation Plan within 30 days of award.
  • Direct security monitoring and correlation across CrowdStrike, Splunk/ELK, Tenable, Tanium, Okta, and AWS native services, aligned to MITRE ATT&CK and OMB M-21-31 logging requirements.
  • Perform security impact analyses for change requests within 5 business days and analyze the Department Computer Security Incident Response Center (CSIRC) threat communications within one business day; support incident response coordination and 24-hour reporting of notifiable events.
  • Lead the Zero Trust Maturity Assessment (90 days) and Zero Trust Roadmap (120 days) and collaborate with the Department ZTA effort on system-level maturity scorecards.
  • Deliver the Post-Quantum Computing Transition Roadmap (6 months) and Analyses of Alternatives for new security technologies; advise the CISO on cryptographic modernization.
  • Develop cybersecurity policy and risk assessment procedures for AI/ML systems per EO 14306 and NIST AI RMF 1.0 and maintain the AI Security Risk Register.
  • Provide technical solutions to vulnerability findings and security gaps during system development; analyze Government design requirements and determine security technology deployment strategies.
  • Direct Task 6 engineering: DevSecOps strategy (6 months), GitLab CI/CD security scanning, security automation scripts, NIST CSF and Enterprise Security Metrics dashboards, and OSCAL artifacts.
  • Oversee CDM Phase 4 integration and Department CDM Dashboard submissions; serve as liaison to the Department CDM community of practice.
  • Lead, train, and certify proficiency of the Security Engineer and Security Engineer/Architect.

Benefits

  • medical, dental, and vision insurance
  • a 401(k) with company match
  • paid time off and holidays
  • professional development and certification support
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service