Security Compliance Engineer

The Opportunity

NTS is seeking an experienced Security Compliance Engineer with deep expertise in Linux system security, DISA STIG implementation, and regulated-environment compliance frameworks including FedRAMP and CMMC. You will own the technical execution of our compliance program—translating control requirements into hardened system configurations, automated scanning pipelines, and auditable evidence packages—while partnering with engineering teams to maintain secure-by-default infrastructure. This is a hands-on engineering role. You will be expected to read STIGs, write Ansible playbooks, triage CVEs, and operate scanning tooling—not just manage checklists.

Key Responsibilities (Principal Duties and Accountabilities *Essential Functions)

STIG Implementation & System Hardening

  • Apply and maintain DISA STIGs across various Linux distributions (RHEL, Ubuntu, SUSE, etc) using OpenSCAP, Ansible STIG roles and/or manual remediation
  • Develop and maintain automated hardening pipelines that produce STIG-compliant OS images via bootc+bib, KIWI/EIB and/or Packer for bare-metal, VM, and cloud deployment targets
  • Configure and tune host-based security controls: SELinux (enforcing/targeted/MLS), auditd rules, fapolicyd application whitelisting, firewalld, and PAM
  • Implement and validate CIS Benchmark controls as a complement to STIG baselines
  • Maintain STIG checklists (CKL/CKLB) and produce POA&M artifacts for findings requiring waivers or scheduled remediation

Vulnerability Management

  • Operate and maintain authenticated scanning infrastructure using Tenable Nessus / Security Center or equivalent; schedule, tune, and triage scan results at scale
  • Perform continuous CVE triage using NVD, CVSS v3/v4, and EPSS scores to drive prioritized remediation workflows with engineering teams
  • Track open vulnerabilities through full lifecycle: discovery, ticket creation, remediation verification, and closure evidence
  • Develop metrics and dashboards for vulnerability posture reporting to technical and executive audiences
  • Coordinate patch cadence with platform teams; validate patched images against scan baselines before promotion to production

FedRAMP Authorization & Continuous Monitoring

  • Support FedRAMP authorization activities (Low, Moderate, or High baselines) including SSP development, control implementation statements, and evidence collection
  • Operate and maintain ConMon programs: monthly vulnerability scanning, POA&M updates, significant change requests (SCRs), and annual assessments
  • Collaborate with Third Party Assessment Organizations (3PAOs) during assessments; prepare technical staff and produce assessment-ready evidence packages
  • Map NIST SP 800-53 Rev 5 controls to technical implementation across infrastructure, applications, and organizational processes
  • Maintain the SSP, CIS, SAR, and SAP documentation sets through authorization lifecycle

CMMC & DoD Compliance

  • Implement and assess CMMC Level 1–3 practices against NIST SP 800-171 and NIST SP 800-172 requirements
  • Maintain the System Security Plan (SSP) and associated artifacts (FIPS boundaries, network diagrams, data flow documentation) for CUI-handling environments
  • Support DIBCAC assessments and internal readiness reviews; manage corrective action tracking through resolution
  • Define and enforce CUI handling procedures, labeling, and access control policies across systems and workflows
  • Implement DoD RMF steps (Categorize ? Select ? Implement ? Assess ? Authorize ? Monitor) for new and existing systems

Supply Chain & SBOM Security

  • Generate and maintain Software Bill of Materials (SBOM) artifacts in CycloneDX and SPDX formats for all platform components
  • Integrate SBOM generation (Syft) and vulnerability correlation (Grype, Dependency-Track) into CI/CD pipelines
  • Enforce software supply-chain controls: artifact signing with cosign / Sigstore, digest pinning, and provenance attestation
  • Evaluate third-party components against supply-chain risk criteria prior to onboarding

PKI, Identity & Cryptography

  • Manage PKI infrastructure for internal certificate issuance, renewal, and revocation; integrate with CAC/PIV authentication for privileged accessEnforce FIPS 140-2/3 validated cryptographic module usage across system components, TLS configurations, and disk encryption
  • Configure and maintain SSSD, LDAP/AD integration, and PAM stacks for centralized identity and MFA enforcement
  • Audit and harden SSH configurations, sudo policies, and privileged access management (PAM/PIM) controls

SIEM, Audit & Incident Response

  • Maintain centralized logging pipelines (Splunk, Elastic/OpenSearch, or Wazuh) ingesting auditd, syslog, and application events
  • Develop correlation rules and alerts for STIG-required audit events, authentication anomalies, and integrity violations
  • Support incident response activities including evidence preservation, log analysis, and post-incident documentation
  • Conduct file integrity monitoring (AIDE or equivalent) and respond to integrity alerts within defined SLAs
  • Fluency in English (written and spoken)
  • Must meet eligibility requirements to obtain US Security clearance; Active DoD Secret or TS/SCI security clearance preferred

Required Skills, Experience & Abilities

  • 5+ years in an information security, system hardening, or security compliance engineering role
  • Hands-on DISA STIG experience across RHEL/CentOS and at least one other OS (Ubuntu, Windows Server)
  • Demonstrated experience operating OpenSCAP, SCAP Workbench, or STIG Viewer for assessment and remediation
  • Proficiency with Ansible for automated configuration management and compliance remediation at scale
  • Direct involvement in at least one FedRAMP authorization or continuous monitoring program
  • Working knowledge of NIST SP 800-53 Rev 5 control families and their technical implementation patterns
  • Experience with authenticated vulnerability scanning using Nessus or equivalent; CVE triage and prioritization
  • Strong Linux systems administration skills: SELinux, auditd, PAM, systemd, firewalld, package management on RPM and DEB systems
  • Ability to read and interpret compliance requirements and translate them into concrete, testable technical controls

Core Technology Stack

A baseline level of fluency across the technologies listed below is expected. Candidates are not required to be fully proficient in every technology on day one but should be able to quickly build proficiency as needed based on task requirements.

  • Compliance Frameworks: FedRAMP (Low/Moderate/High), CMMC L1–L3, NIST SP 800-53, NIST SP 800-171, DISA STIGs, DoD RMF
  • STIG & Hardening: DISA STIG Viewer, OpenSCAP / oscap, Ansible STIG roles, CIS Benchmarks, fapolicyd, auditd
  • Vulnerability Mgmt: Tenable Nessus / Security Center, Rapid7, OpenVAS, CVE / NVD, CVSS scoring, EPSS
  • OS Platforms: RHEL 8/9, AlmaLinux, Rocky Linux, Ubuntu 22.04/24.04 LTS
  • Image & Config Mgmt: Packer (QEMU, Hyper-V, vSphere), Ansible, Chef InSpec, Puppet, cloud-init, bootc
  • PKI & Identity: RHCS / Dogtag, Active Directory / LDAP, SSSD, CAC / PIV, FIPS 140-2/3, SELinux
  • SBOM & Supply Chain: Syft, Grype, Dependency-Track, cosign, Sigstore, trivy, CycloneDX / SPDX
  • SIEM & Monitoring: Splunk, Elastic / OpenSearch, Wazuh, AIDE, auditd, syslog-ng, Graylog
  • Automation & IaC: Ansible / AWX, Terraform / OpenTofu, GitLab CI, Bash, Python
  • Cloud & Virtualization: AWS GovCloud, Azure Government, GCP Assured Workloads, VMware vSphere, Hyper-V, QEMU/KVM

Preferred Qualifications

  • CMMC Registered Practitioner (RP), Certified Professional (CP), or equivalent CMMC assessment experience
  • One or more of: CompTIA Security+, CISSP, CISM, GIAC GCED, RHCSA/RHCE, or equivalent certification
  • Experience with cloud-native FedRAMP environments in AWS GovCloud, Azure Government, or GCP Assured Workloads
  • Familiarity with container and Kubernetes security hardening: Pod Security Standards, Kyverno / OPA policies, CIS Kubernetes Benchmark
  • Experience with FIPS boundary documentation, cryptographic module validation (CMVP), and FIPS-mode OS configuration
  • Prior 3PAO, ISSO, ISSM, or Authorizing Official (AO) support experience
  • Scripting proficiency in Python or Go for tooling automation beyond Bash/Ansible

Physical Demands & Work Environment

The physical demands and work environment described are representative of those that an employee encounters while performing the essential functions of this job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.

  • Prolonged periods of sitting at a desk and working on a computer.
  • Frequent use of hands and fingers for typing, writing, and handling documents.
  • Clear vision and hearing required for meetings, presentations, and communication.
  • Ability to travel up to 20% of the time, which may include extended periods of standing, walking, or navigating airports and government facilities.
  • Some customer site visits, no expectation of OCONUS

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available