Junior Security Engineer
Job Description
Tharros is seeking a Junior Security Engineer to support cybersecurity engineering for the Department of Homeland Security. This role is based on-site in a Government SCIF in Washington, DC, with responsibilities spanning enterprise audit support, cloud and compliance activities, and Zero Trust architecture enablement.
You will help maintain and automate security tooling, align work with DISA STIGs, and turn security and compliance data into dashboards and roadmaps that support governance and engineering teams.
Key Responsibilities
- Maintain and update cybersecurity tools, including ACAS/Nessus, SCAP, SonarQube, and GitLab.
- Update Security Technical Implementation Guides (STIGs) on a quarterly basis and manage Nessus plug-in IDs on a monthly cadence.
- Develop and troubleshoot scripts that automate STIG application and validation within the DevSecOps pipeline.
- Organize security tool data into near-real-time dashboards using a GRC or other approved platform.
- Support implementation of ICS 500-27 enterprise audit requirements and build audit review dashboards with ISSOs.
- Assist with Zero Trust capability gap analysis, contribute to the Zero Trust roadmap, and support Zero Trust dashboards.
- Maintain a tracking tool for network device end-of-life and end-of-service dates.
Requirements
- BS degree in Information Technology, Cybersecurity, Information Systems, or Computer Science, or minimum of 4 years of experience in IT or cybersecurity.
- At least 1 year of experience in security engineering, systems administration, or DevSecOps.
- Active TS/SCI clearance and U.S. citizenship; willingness to undergo a DHS counterintelligence-scope polygraph.
- Proficiency with automation tools, including Python, PowerShell, or shell scripting languages.
- Knowledge of DISA STIGs and configuration compliance scanning.
- Knowledge of audit logging concepts for Windows and Linux systems.
- Knowledge of Zero Trust architecture principles.
- Ability to use Nessus/ACAS or SCAP tools.
- Ability to troubleshoot tool and script issues.
- Proficiency with Microsoft Office Suite, including Teams or similar workplace chat and videoconferencing tools.
- Excellent written and oral communication skills.
Technologies
- ACAS/Nessus, SCAP, SonarQube, GitLab, Python, PowerShell, shell scripting languages
- Microsoft Office Suite, Teams, Nessus plug-in IDs, GRC, DevSecOps
- DISA STIGs, Windows, Linux, Zero Trust architecture principles
- CompTIA Security+, AWS, Azure, GitLab CI/CD, Splunk, ICS 500-27
Desired
- CompTIA Security+ or an AWS/Azure fundamentals certification.
- Experience with GitLab CI/CD or Splunk.
Location: Washington, DC (On-site in a Government SCIF)