Zachary Piper Solutions is seeking an Information Security Engineer to support a mission-critical DHS USCIS cybersecurity program focused on Continuous Monitoring and enterprise risk reduction. This role is key in strengthening the security posture of nationwide immigration systems by identifying vulnerabilities and driving remediation efforts.
Responsibilities:
- Analyze Tenable.io vulnerability scan results to identify weaknesses across enterprise systems
- Correlate events and findings through Splunk dashboards to prioritize risks and remediation
- Support NIST RMF activities, including documenting findings and developing POA&Ms
- Recommend remediation strategies for cloud (AWS/Azure/GCP) and OS environments (Windows/Linux)
- Perform system evaluations across CentOS, RHEL, Ubuntu, and Windows platforms
- Collaborate with ISSOs, system owners, and engineering teams to drive timely remediation
- Identify process improvements for Continuous Monitoring and security tool effectiveness
- Prepare reports outlining risks, impacts, and recommended corrective actions
- Support enterprise-level security planning, process modeling, and vulnerability management improvements
Requirements:
- Bachelor's degree in Information Technology, Cybersecurity, or related field (required)
- 10+ years of experience in information security or security engineering
- Hands-on experience with Tenable.io, Nessus, ACAS, or similar scanning platforms
- Experience with Splunk Enterprise (v9.2+) for analysis and dashboarding
- Strong working knowledge of NIST SP 800-37 RMF, POA&M development, and risk assessments
- Experience administering or evaluating systems across Windows and Linux distributions
- Cloud administration experience in AWS (Azure/GCP also acceptable)
- Strong written and verbal communication skills, capable of translating complex findings
- Must be a U.S. Citizen and eligible for Public Trust
- Prior DHS experience preferred
- CISSP, CISM, CEH, or similar certifications preferred but not required