Raft (https://TeamRaft.com) is a customer-obsessed non-traditional small business with a purposeful focus on Distributed Data Systems, Platforms at Scale, and Complex Application Development, with headquarters in McLean, VA. Our range of clients includes innovative federal and public agencies leveraging design thinking, cutting-edge tech stack, and cloud-native ecosystem. We build digital solutions that impact the lives of millions of Americans.
As an Information Systems Security Engineer (ISSE), you'll embed within a client team specializing in security engineering and leveraging DevSecOps methodology. Your daily responsibilities range from building and running an EKS cluster that houses our SIEM or analyzing data to find potential security issues to responding to incidents & working with teams to remediate after vulnerabilities are discovered. You'll rely on your knowledge of Kubernetes and AWS to provide ways forward for the client while also supporting teammates and empowering product teams across the client's portfolio.
Requirements:
- Five-plus years of hands-on experience with Terraform, SIEM, AWS, Single Sign On (SSO), IDP such as Okta, SAML, OIDC
- Five-plus years of working knowledge and experience in managing multiple AWS environments
- Solid working experience in designing secure network & system architectures, virtualization & cloud technologies, application security, encryption technologies, and IPS/IDS technologies
- Experience with planning and implementation of defense-in-depth security engineering and conducting security testing
- Deep understanding of DevSecOps methodologies & implementing security tooling within CI/CD pipelines
- Experience with containerization technologies such as Kubernetes & Docker and related scanning tools
- Experience hardening on-prem & cloud-based Linux & Windows systems using DISA STIGs & SRGs or other industry best practices
- Experience building & maintaining relevant security documentation
- Willing to occasionally work in a classified environment
- Stay current with industry trends
- Obtain CompTIA Security+ or other DoD 8570 IAT Level II or higher certification within the first 90 days of employment
Highly preferred:
- Expertise with the NIST RMF or other security/risk frameworks and the DoD ATO process
- Experience with DoD DevSecOps Reference Design Architecture
- Experience with DoD Software Factories & related platforms
- Previous participation in Security Working Groups or as part of Incident Response teams
- Passionate about building automation in languages like Python, GoLang, or Typescript
- Experience with Azure or Google Cloud offerings
- Industry Certifications (CKS, CKA, AWS certifications, CISSP, CCSP, SSCP)
- Master's degree in Information Security, Cybersecurity, Information Assurance, Computer Science, or similar field
Clearance Requirements: Ability to obtain and maintain a Top Secret security clearance
Work Type: Remote with up to 10% travel
We offer competitive salary, comprehensive benefits, flexible PTO, education & training benefits, and more. Join our team of high-impact problem solvers and work on digital solutions that impact millions of Americans.