Security Engineer

Alert IT SolutionsSpringfield, MO
Remote

About The Position

The Security Engineer will be responsible for ensuring the Environmental Information Management System (EIMS) is designed, implemented, and maintained in full compliance with applicable state and federal security, privacy, and environmental data regulations. This role requires an experienced security professional with deep knowledge of NIST 800-53, FISMA, CROMERR, FedRAMP, and DoIT security standards, as well as hands-on experience with SSP and POA&M development and audit coordination. The Security Engineer will work closely with project leadership, technical teams, and compliance stakeholders to protect sensitive environmental data and ensure ongoing regulatory compliance across all EIMS implementations.

Requirements

  • deep knowledge of NIST 800-53, FISMA, CROMERR, FedRAMP, and DoIT security standards
  • hands-on experience with SSP and POA&M development and audit coordination

Responsibilities

  • Configure and validate EIMS security controls to ensure alignment with required state and federal security and privacy standards.
  • Ensure the solution adequately protects sensitive and regulated environmental data.
  • Validate secure system configurations across infrastructure, application, and data layers.
  • Ensure full compliance with applicable security frameworks and regulations, including NIST SP 800-53, FISMA, CROMERR, FedRAMP, and State DoIT security requirements.
  • Verify that all system implementations comply with relevant environmental data standards and regulatory requirements.
  • Support Authority to Operate (ATO) activities, as applicable.
  • Conduct regular security assessments, vulnerability evaluations, and compliance audits.
  • Develop, maintain, and manage security documentation, including System Security Plans (SSP), Plans of Action and Milestones (POA&M).
  • Coordinate and support internal, state, and federal security audits.
  • Track remediation activities and ensure closure of identified findings.
  • Identify, assess, and mitigate security risks throughout the system lifecycle.
  • Support ongoing continuous monitoring activities and reporting.
  • Advise project and technical teams on security best practices and remediation strategies.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service