Booz Allen Hamilton is seeking a Virtru Security Engineer to play a critical role in the world of zero trust. The role involves supporting cyber architecture development, leading security compliance initiatives, and collaborating with teams to implement security controls across cloud environments.
Responsibilities:
- Support the cyber architecture development, implementation, and sustainment across multiple networks of different classification levels
- Interface with stakeholders and engineering teams to delve into the details and dependencies of critical processes and users’ roles within them
- Lead security compliance initiatives and automation of control validation across our cloud environments using Infrastructure as Code, including Terraform or Ansible
- Build security automation for CI/CD pipelines, including vulnerability scanning and compliance validation
- Conduct regular security reviews and risk assessments of cloud infrastructure and applications
- Collaborate with development and operations teams to implement security controls without impeding velocity
- Develop and maintain security monitoring solutions and respond to security events
- Create and maintain security documentation, training, and guidelines for engineering teams
Requirements:
- 3+ years of experience designing, deploying, and configuring data security solutions
- Experience with data security tools such as Virtru
- Experience with data-centric security models, including maintenance
- Experience designing, implementing, configuring, operating, or testing IT systems or security infrastructure
- Experience deploying and troubleshooting Kubernetes and Docker
- Experience with data tagging and classification
- Knowledge of Zero Trust principles and solutions
- Top Secret clearance
- HS diploma or GED
- Experience with Data Security Posture Management (DSPM) such as Varonis and BigID
- Experience working in federal, DoD, or IC agency environments
- Experience with Titus Data Classification
- Experience in security automation using Terraform or Ansible, and languages, such as Go, Python, or Node.js
- Experience with infrastructure scanning tools and security monitoring solutions, such as CNAP, SIEM, CSPM, and CWPP
- Knowledge of federal information security policies, standards, procedures, directives, frameworks, federal security authorizations, assessment, and risk management processes for enterprise systems