The Security Engineer will support the VA Data Modernization initiative by performing vulnerability remediation and providing cloud security guidance. They will also assist customers with the Security Impact Analysis process and ensure compliance across application and infrastructure layers.
GovCIO is hiring a Security Engineer to support the Department of Veterans Affairs (VA) Data Modernization initiative supporting VA environment vulnerability remediation. The Senior Security Engineer will provide guidance on cloud security, deliver surge support for data ingestion needs, and help customers efficiently navigate the Security Impact Analysis (SIA) process. This position is fully remote within the United States.
Responsibilities
Supports vulnerability identification, analysis, and remediation across UNIX/Linux systems , VMware infrastructures, and containerized workloads.
Apply security engineering best practices to cloud environments in AWS (EC2, IAM, VPC, S3, ECR, ES) and Azure (Key Vaults, Storage Accounts, Databricks).
Ensures secure configurations, compliance alignment, and mitigation of risks across application, infrastructure, and data layers.
Provides end‑to‑end security support for all aspects of the Data Modernization effort, including secure workspace provisioning, access configurations, and governance controls.
Deliver surge support to help customers ingest additional datasets securely, ensuring compliance with VA security and privacy requirements.
Guide users through the Security Impact Analysis (SIA) process.
Collaborate with intake, provisioning, and data engineering teams to ensure security requirements are integrated into automated workflows and common use‑case configurations.
Support the rapid provisioning goal by ensuring security checkpoints are met within required SLAs (1–2 days when applicable).
Coordinate with Databricks SMEs, CDW data teams, and VHA Data Lake stewards to validate security configurations and ensure secure data connectivity.
Maintain and update security documentation, standard operating procedures, security architecture diagrams, and onboarding guidance.
Support the “single front door” customer experience by contributing security-focused content related to onboarding, platform policies, and data access procedures.
Qualifications
Required Skills and Experience:
Bachelor’s degree plus 8 years experience in Cybersecurity, Information Technology, Computer Science, or a related field (or commensurate experience)
Experience in security engineering, cloud security, or cybersecurity compliance roles.
Strong understanding of security frameworks such as NIST, RMF, FedRAMP, or similar governance models.
Ability to work with cross-functional teams and communicate security requirements to both technical and non‑technical audiences.
Strong analytical, problem-solving, and communication skills.
Preferred Skills and Experience:
Experience conducting or supporting Security Impact Analyses (SIA), risk assessments, or security authorizations.
Proficiency with Azure cloud security tools, identity and access management (IAM), service principals, and role-based access controls.
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”