CybersecurityJobs.io
← Back to all jobs

Job Description

Contribute to the National Library of Medicine’s Security Compliance team by engineering security controls and compliance capabilities across hybrid on-prem and cloud environments.

Responsibilities

  • Enhance and automate security and compliance checks using scripting and available tools; evaluate emerging technologies, including AI capabilities, to expand security coverage and improve operational efficiency
  • Lead integration efforts for AI/ML-driven capabilities with current security tooling and operations to automate assessment and remediation using LLM within NLM
  • Implement and maintain security controls across on-prem and cloud environments (AWS, GCP, Azure), ensuring alignment with FISMA, NIH policy, and federal security requirements
  • Recommend and support security services for identity access, privileged access, vulnerability management, encryption, network micro-segmentation, and centralized log management across hybrid systems
  • Integrate and optimize enterprise security and SIEM solutions (e.g., Splunk, Tenable) for continuous monitoring, event correlation, and compliance visibility
  • Perform threat modeling and security assessments for cloud deployments; identify and mitigate vulnerabilities and support secure cloud migrations
  • Provide security guidance, best practices, and compliance support to developers, operations teams, and system owners to improve organizational security awareness
  • Analyze vulnerability and assessment data to identify systemic risks, remediation trends, and opportunities to improve processes or tools; collaborate with system administrators and security teams for risk-informed remediation
  • Contribute to and manage documentation, standard operating procedures, and technical guidance to support consistent execution across the security program

Requirements

  • Extensive experience securing on-premises and cloud environments (AWS, GCP, Azure) with strong working knowledge of cloud security models, logging, tagging strategies, ephemeral resource tracking, and cross-platform operations in federal, regulated settings
  • 10+ years securing information technology plus 7+ years in hands-on security engineering built on a systems administration foundation, including at least 3 years focused on cloud security and administration of Linux and Windows endpoints
  • Familiarity with AI/ML integration in security tooling and operations, supporting modern approaches to threat detection and remediation
  • Demonstrated expertise applying federal compliance frameworks including FISMA, NIST 800-53, FedRAMP, and RMF, including support for system authorization processes (ATO, POA&M)
  • Admin or engineering-level experience with at least two security tools such as Tenable, Checkmarx, or Splunk, plus strong understanding of vulnerability management, application security testing, and remediation workflows
  • Bachelor’s degree in computer science, cybersecurity, information technology, or related technical field (or equivalent technical experience)
  • CISSP certification (or ability to obtain within 6 months)
  • Ability to collaborate and guide multi-disciplinary teams managing servers, workstations, network and security appliances in regulated environments; ability to adapt to shifting priorities
  • Strong written and verbal communication skills, including producing clear security documentation and explaining technical concepts to technical and non-technical stakeholders

Technologies

  • AWS, GCP, Azure
  • Splunk, Tenable, Checkmarx
  • FISMA, NIST 800-53, FedRAMP, RMF
  • ATO, POA&M
  • AI/ML, LLM
  • PowerShell, Bash, Python
  • Linux, Windows, Linux and Windows endpoints
  • Docker, Kubernetes

Location & Employment Type

  • Bethesda, MD (onsite)
  • Onsite requirement: 3–5 days per week as needs change
  • Full-time

Desired Qualifications

  • Hands-on experience with AI/ML automation, security event correlation, asset inventory tracking, and SEIM management (preferably in Splunk), using scripting or programming such as PowerShell, Bash, Python (or equivalent) and APIs
  • Advanced Linux and Windows administration experience; certified in AWS/AZURE/GCP
  • Experience with container security (Docker & Kubernetes)
  • Master’s degree in computer science, cybersecurity, information technology, or a related technical field

Similar Jobs