Security Engineer-Senior

Wichita Tribal Enterprise US,
Onsite

About The Position

Wichita Tribal Enterprises, a Quivera Enterprise company, is seeking an experienced Security Engineer – Senior to support the Department of the Interior (DOI), Indian Affairs (IA), Office of Information Technology (OIT). This position provides senior-level cybersecurity engineering and Risk Management Framework (RMF) support for enterprise information systems and continuous monitoring activities. The Security Engineer – Senior serves as a technical subject matter expert responsible for conducting comprehensive security assessments, developing system authorization packages, implementing NIST Risk Management Framework (RMF) processes, and supporting federal cybersecurity compliance initiatives. Working closely with Information System Owners (ISOs), Information System Security Officers (ISSOs), developers, IT operations personnel, and federal stakeholders, this position develops security documentation, performs technical security assessments, evaluates security controls, and supports continuous monitoring efforts to ensure compliance with NIST guidance, FISMA, Departmental policy, and federal cybersecurity requirements. The successful candidate will possess extensive experience in information assurance, risk assessment, security engineering, and security authorization activities while supporting secure, compliant, and mission-focused federal IT systems.

Requirements

  • Bachelor's degree and four (4) years of relevant professional experience; or Master's degree and three (3) years of relevant professional experience; or Six (6) years of directly related professional experience in lieu of a degree.
  • An industry-recognized technical certification may substitute for two (2) years of required experience where permitted by contract.
  • Experience supporting Risk Management Framework (RMF) activities.
  • Experience conducting technical security assessments.
  • Experience developing complete security authorization packages.
  • Experience with information assurance or cybersecurity engineering.
  • Experience implementing NIST RMF guidance.
  • Experience conducting security assessments of complex information systems with minimal supervision.
  • Experience performing vulnerability assessments and risk analysis.
  • Experience developing POA&Ms and remediation recommendations.
  • Experience supporting continuous monitoring activities.
  • Experience evaluating management, operational, and technical security controls.
  • NIST SP 800-37 Risk Management Framework
  • NIST SP 800-53 Security Controls
  • NIST SP 800-18 System Security Plans
  • NIST SP 800-34 Contingency Planning
  • NIST SP 800-27 Security Engineering
  • NIST SP 800-60 Information Categorization
  • FIPS 199
  • Risk Assessment & Management
  • Vulnerability Analysis
  • Configuration Management
  • Disaster Recovery
  • Contingency Planning
  • Security Engineering
  • Authorization & Assessment (A&A)
  • Security Authorization Packages
  • Continuous Monitoring
  • Federal Information Security Modernization Act (FISMA)

Nice To Haves

  • CISSP
  • CAP (Certified Authorization Professional)
  • Security+
  • CASP+
  • CISM
  • CEH
  • GSEC
  • Experience supporting Department of the Interior or Bureau of Indian Affairs.
  • Experience with eMASS, CSAM, Xacta, Archer, or similar GRC platforms.
  • Experience supporting cloud security and FedRAMP initiatives.
  • Experience with industrial control systems (ICS) or operational technology (OT) environments.

Responsibilities

  • Conduct security assessments of federal information systems in accordance with NIST SP 800-37 and NIST SP 800-53 guidance.
  • Develop complete security authorization packages supporting Authority to Operate (ATO) and continuous authorization activities.
  • Perform system security categorization in accordance with NIST SP 800-60 and FIPS 199 requirements.
  • Document security control selection and tailoring in accordance with NIST SP 800-53 and NIST SP 800-18.
  • Develop and maintain System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), Plans of Action and Milestones (POA&Ms), Contingency Plans (CPs), and supporting RMF documentation.
  • Support implementation of RMF activities throughout the System Development Life Cycle (SDLC).
  • Conduct technical security assessments of complex information systems, network infrastructures, cloud environments, and industrial control systems with minimal supervision.
  • Evaluate management, operational, and technical security controls for effectiveness and compliance.
  • Perform vulnerability analysis and identify security weaknesses affecting federal information systems.
  • Apply NIST security engineering principles throughout system design, implementation, and operation.
  • Develop remediation recommendations and mitigation strategies for identified vulnerabilities.
  • Provide preliminary POA&M recommendations supporting corrective action planning.
  • Conduct concurrent risk assessments and document findings within Security Assessment Reports.
  • Support Indian Affairs Risk Management Framework and Continuous Monitoring Programs.
  • Monitor implementation of security controls to ensure ongoing compliance with federal cybersecurity requirements.
  • Participate in continuous assessment of technical, operational, and management controls.
  • Assist with ongoing authorization activities and security documentation updates.
  • Support compliance with FISMA, Departmental policy, and organizational cybersecurity standards.
  • Develop initial and updated System Security Plans.
  • Develop Contingency Plans aligned with NIST SP 800-34 guidance.
  • Prepare Security Assessment Plans and execute assessment activities.
  • Develop Security Assessment Reports documenting assessment findings.
  • Prepare Risk Assessment Reports identifying organizational and system risks.
  • Develop and maintain POA&M documentation identifying weaknesses, remediation activities, and risk priorities.
  • Maintain documentation supporting system authorization and continuous monitoring.
  • Perform enterprise and system-level risk assessments.
  • Analyze vulnerabilities, threats, likelihood, and impact to determine organizational risk.
  • Provide risk mitigation recommendations aligned with NIST guidance and industry best practices.
  • Evaluate configuration management processes supporting secure system operation.
  • Support contingency planning and disaster recovery planning activities.
  • Collaborate with Information System Owners, Information System Security Officers, developers, project teams, and IT operations personnel.
  • Coordinate assessment activities with organizational stakeholders while working independently.
  • Provide technical guidance regarding security engineering and RMF implementation.
  • Support implementation of cybersecurity best practices across the enterprise.
  • Assist organizational stakeholders in understanding security assessment findings and remediation priorities.
  • Provide multidisciplinary security support across: Physical Security, Computer Security, Personnel Security, Information Security, Administrative Security, Operational Security, Communications Security.
  • Support strategic implementation of security controls across enterprise information systems.
  • Participate in process improvement initiatives supporting cybersecurity maturity.
  • Maintain awareness of emerging cybersecurity threats, technologies, and federal regulatory changes.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service