freehire launches on Product Hunt on 26 August.

Follow →

Senior /Principal Federal Security Engineer

Open 68d reposted 2×
Saviynt's AI-powered identity platform manages and governs human and non-human access to all of an organization's applications, data, and business processes. Customers trust Saviynt to safeguard their digital assets, drive operational efficiency, and reduce compliance costs. Built for the AI age, Saviynt is today helping organizations safely accelerate their deployment and usage of AI. Saviynt is recognized as the leader in identity security, with solutions that protect and empower the world’s leading brands, Fortune 500 companies and government institutions. For more information, please visit .

The Senior/Principal Federal Security Engineer reports into Federal Information Security leadership, and will specialize in detection, response, and vulnerability triage. They will also serve as a high-level technical authority responsible for the end-to-end lifecycle of threat management. This hands-on engineering role will own the systems that identify and mitigate organizational risk as they relate primarily to the FedRAMP Program (FedRAMP Moderate and FedRAMP High).

The candidate should be familiar with policy and compliance requirements, including policy documentation and system requirements to successfully respond to potential audits as well as prior experience operating in Federally regulated environments.

CORE RESPONSIBILITIES

  • Design and maintain high-fidelity detection rules and analytics across the security stack (SIEM, EDR, CNAPP/CSPM) and cloud environments (AWS, GCP, Azure).
  • Ability to run vulnerability scans, triage results, establish exploitability of reported vulnerabilities, recommend risk mitigation controls, and deploy controls where needed
  • Develop and refine automated response playbooks for Incident Response (IR) and orchestration (SOAR).
  • Lead the evaluation and integration of security technologies, ensuring scalability, resilience, and compliance. as it pertains to FedRAMP environments

WHAT YOU WILL BE DOING

Lead the Detection Lifecycle: Build and maintain our threat detection capabilities, from researching emerging TTPs to writing custom detection logic in our SIEM and EDR platforms.
Incident Response: Respond to alerts and triage findings coordinating across engineering, security, and leadership teams.
Modernize Vulnerability Management: Architect and maintain automation to prioritize vulnerabilities (from Code, to Containers, to Cloud) based on risk and : Operationalize security tasks by building, developing, and optimizing SOAR playbooks to automate containment and remediation.
Execute Proactive Threat Hunting: Design and lead hunt missions to identify threats that bypass traditional security controls, utilizing advanced forensics and log correlation techniques.
Industry Awareness: Incorporate industry news, events, IOCs, and other intelligence into our Detection and Response capabilities.

WHAT YOU BRING

  • U.S. Citizenship: Applicants must be United States citizens.
  • Bachelor's degree or equivalent experience with a minimum of 10 years of experience in Security Engineering, Security Architecture, Federal Security or similar
  • Knowledge of U.S. Federal Government security compliance, risk management processes and requirements, including NIST RMF and NIST SP 800-53 Rev 5 controls
  • Experience with vulnerability scanning, remediation, and continuous monitoring (ConMon)
  • Requires sufficient technical background to be able to interpret audit and compliance requirements, and be able to support basic evidence gathering needs in support of audits
  • Ability to provide excellent written and oral communications by email, presentations, and mobile communication platforms (including: experience facilitating discussions, briefing senior managers, and conducting project meetings).
  • Experience with continuous monitoring and Plans of Actions and Milestones (POA&Ms) is a plus
  • Knowledge of local legal and regulatory security requirements including HIPAA, FedRAMP, and GDPR/privacy
  • Flexible and collaborative approach to enabling and supporting the business
The Selected candidate must:
  • Meet US persons on US soil requirements
  • Undergo full background investigation/screening
  • Undergo IAL3 requirements (Identity proofing to include I-9 document verification, biometric collection, and mailing address confirmation)
If required for this role, you will:
- Complete security & privacy literacy and awareness training during onboarding and annually thereafter
- Review (initially and annually thereafter), understand, and adhere to Information Security/Privacy Policies and Procedures such as (but not limited to):

> Data Classification, Retention & Handling Policy
> Incident Response Policy/Procedures
> Business Continuity/Disaster Recovery Policy/Procedures
> Mobile Device Policy
> Account Management Policy
> Access Control Policy
> Personnel Security Policy
> Privacy Policy

Saviynt is an amazing place to work. We are a high-growth, Platform as a Service company focused on Identity Authority to power and protect the world at work. You will experience tremendous growth and learning opportunities through challenging yet rewarding work which directly impacts our customers, all within a welcoming and positive work environment. If you're resilient and enjoy working in a dynamic environment you belong with us!

Saviynt is an equal opportunity employer and we welcome everyone to our team. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.

What this application asks

lever

Resume/CV, Full name, Pronouns, Email, Phone, Current location, Current company, LinkedIn URL, Twitter URL, GitHub URL, Portfolio URL, Other website

  • Full Legal Name
  • Please provide your mailing home address
  • How did you find out about this position? choose one · optional
  • If Referral, Please List Name of Saviynt Employee optional
  • Are you legally authorized to work in The United States? choose one
  • Will you now, or in the future, require sponsorship to work in The United States? choose one
  • Are you currently employed? choose one
  • If no, please provide most recent employer optional
  • What is your desired salary?
  • I certify that all of the information furnished on this application and during the application process is true, complete and correct to the best of my knowledge. I understand that any misrepresentation or omission of facts called for may result in refusal to hire or, if hired, may result in my dismissal at any time regardless of when the false answer or omissions are discovered. choose one
  • Upon future offer acceptance, I hereby authorize, to the extent allowed by applicable federal state and local laws, Saviynt to conduct its own investigation of my references, employment history and education and, further, authorize the references and prior employers I have listed to disclose to Saviynt information related to my employment history and qualifications for the position for which I am applying, without giving me prior notice of such disclosure. choose one
  • I AGREE, AND IT IS MY INTENT, TO SIGN THIS EMPLOYMENT APPLICATION BY TYPING MY NAME IN THE BOX BELOW AND BY ELECTRONICALLY SUBMITTING THIS DOCUMENT TO THE COMPANY. I UNDERSTAND THAT MY SIGNING AND SUBMITTING THIS DOCUMENT IN THIS FASHION IS THE LEGAL EQUIVALENT OF HAVING PLACED MY HANDWRITTEN SIGNATURE ON THE SUBMITTED DOCUMENT. choose one
  • Full Name
  • Have you held a role as a Security Architect or Senior Security Engineer in your career? written answer
  • If yes, for how long have you worked in the capacity of Security Architect or Senior Security Engineer? written answer
  • Do you have hands-on security architecture engineering experience? written answer
  • Do you have experience working on FedRAMP programs? written answer
  • If yes, are you familiar with designing and implementing controls to meet FedRAMP requirements? written answer
  • Have you worked with FedRAMP Moderate, FedRAMP High, or both? choose one
  • Have you been responsible for developing a System Security Plan (SSP)? written answer
  • Have you led monthly Continuous Monitoring (ConMon) efforts from a technical perspective? written answer
  • Are you able to independently conduct vulnerability scans and triage the results? written answer
  • Do you have experience interpreting security alerts from a federal Security Information and Event Management (SIEM) system? written answer

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available