NexTech Solutions LLC logo

Security Compliance Engineer

NexTech Solutions LLC

  • Tampa, FL
  • 19 days ago
  • Full-time

Highlights

Monitor) for new and existing systems Supply Chain & SBOM Security Generate and maintain Software Bill of Materials (SBOM) artifacts in CycloneDX and SPDX formats for all platform componentsIntegrate SBOM generation (Syft) and vulnerability correlation (Grype, Dependency-Track) into CI/CD pipelinesEnforce software supply-chain controls: artifact signing with cosign / Sigstore, digest pinning, and provenance attestationEvaluate third-party components against supply-chain risk criteria prior to onboarding PKI, Identity & Cryptography Manage PKI infrastructure for internal certificate issuance, renewal, and revocation; integrate with CAC/PIV authentication for privileged accessEnforce FIPS 140-2/3 validated cryptographic module usage across system components, TLS configurations, and disk encryptionConfigure and maintain SSSD, LDAP/AD integration, and PAM stacks for centralized identity and MFA enforcementAudit and harden SSH configurations, sudo policies, and privileged access management (PAM/PIM) controls SIEM, Audit & Incident Response Maintain centralized logging pipelines (Splunk, Elastic/OpenSearch, or Wazuh) ingesting auditd, syslog, and application eventsDevelop correlation rules and alerts for STIG-required audit events, authentication anomalies, and integrity violationsSupport incident response activities including evidence preservation, log analysis, and post-incident documentationConduct file integrity monitoring (AIDE or equivalent) and respond to integrity alerts within defined SLAs You will own the technical execution of our compliance programtranslating control requirements into hardened system configurations, automated scanning pipelines, and auditable evidence packageswhile partnering with engineering teams to maintain secure-by-default infrastructure.

Numbers & Facts

LocationTampa, FL
Job TypeFull-time
IndustryOther/Not Classified
Company Size50 to 99 employees
Year Founded2013
Websitehttp://www.nextechsol.com

Description

The Opportunity NTS is seeking an experienced Security Compliance Engineer with deep expertise in Linux system security, DISA STIG implementation, and regulated-environment compliance frameworks including FedRAMP and CMMC. You will own the technical execution of our compliance programtranslating control requirements into hardened system configurations, automated scanning pipelines, and auditable evidence packageswhile partnering with engineering teams to maintain secure-by-default infrastructure. This is a hands-on engineering role. You will be expected to read STIGs, write Ansible playbooks, triage CVEs, and operate scanning toolingnot just manage checklists. Key Responsibilities (Principal Duties and Accountabilities *Essential Functions) STIG Implementation & System Hardening Apply and maintain DISA STIGs across various Linux distributions (RHEL, Ubuntu, SUSE, etc) using OpenSCAP, Ansible STIG roles and/or manual remediationDevelop and maintain automated hardening pipelines that produce STIG-compliant OS images via bootc+bib, KIWI/EIB and/or Packer for bare-metal, VM, and cloud deployment targetsConfigure and tune host-based security controls: SELinux (enforcing/targeted/MLS), auditd rules, fapolicyd application whitelisting, firewalld, and PAMImplement and validate CIS Benchmark controls as a complement to STIG baselinesMaintain STIG checklists (CKL/CKLB) and produce POA&M artifacts for findings requiring waivers or scheduled remediation Vulnerability Management Operate and maintain authenticated scanning infrastructure using Tenable Nessus / Security Center or equivalent; schedule, tune, and triage scan results at scalePerform continuous CVE triage using NVD, CVSS v3/v4, and EPSS scores to drive prioritized remediation workflows with engineering teamsTrack open vulnerabilities through full lifecycle: discovery, ticket creation, remediation verification, and closure evidenceDevelop metrics and dashboards for vulnerability posture reporting to technical and executive audiencesCoordinate patch cadence with platform teams; validate patched images against scan baselines before promotion to production FedRAMP Authorization & Continuous Monitoring Support FedRAMP authorization activities (Low, Moderate, or High baselines) including SSP development, control implementation statements, and evidence collectionOperate and maintain ConMon programs: monthly vulnerability scanning, POA&M updates, significant change requests (SCRs), and annual assessmentsCollaborate with Third Party Assessment Organizations (3PAOs) during assessments; prepare technical staff and produce assessment-ready evidence packagesMap NIST SP 800-53 Rev 5 controls to technical implementation across infrastructure, applications, and organizational processesMaintain the SSP, CIS, SAR, and SAP documentation sets through authorization lifecycle CMMC & DoD Compliance Implement and assess CMMC Level 13 practices against NIST SP 800-171 and NIST SP 800-172 requirementsMaintain the System Security Plan (SSP) and associated artifacts (FIPS boundaries, network diagrams, data flow documentation) for CUI-handling environmentsSupport DIBCAC assessments and internal readiness reviews; manage corrective action tracking through resolutionDefine and enforce CUI handling procedures, labeling, and access control policies across systems and workflowsImplement DoD RMF steps (Categorize ? Select ? Implement ? Assess ? Authorize ? Monitor) for new and existing systems Supply Chain & SBOM Security Generate and maintain Software Bill of Materials (SBOM) artifacts in CycloneDX and SPDX formats for all platform componentsIntegrate SBOM generation (Syft) and vulnerability correlation (Grype, Dependency-Track) into CI/CD pipelinesEnforce software supply-chain controls: artifact signing with cosign / Sigstore, digest pinning, and provenance attestationEvaluate third-party components against supply-chain risk criteria prior to onboarding PKI, Identity & Cryptography Manage PKI infrastructure for internal certificate issuance, renewal, and revocation; integrate with CAC/PIV authentication for privileged accessEnforce FIPS 140-2/3 validated cryptographic module usage across system components, TLS configurations, and disk encryptionConfigure and maintain SSSD, LDAP/AD integration, and PAM stacks for centralized identity and MFA enforcementAudit and harden SSH configurations, sudo policies, and privileged access management (PAM/PIM) controls SIEM, Audit & Incident Response Maintain centralized logging pipelines (Splunk, Elastic/OpenSearch, or Wazuh) ingesting auditd, syslog, and application eventsDevelop correlation rules and alerts for STIG-required audit events, authentication anomalies, and integrity violationsSupport incident response activities including evidence preservation, log analysis, and post-incident documentationConduct file integrity monitoring (AIDE or equivalent) and respond to integrity alerts within defined SLAs

About Company

ABOUT NTS

NexTech Solutions is a team of experts and engineers who understand the challenges that Federal agencies face in finding and implementing the best technologies and IT solutions to meet mission requirements. We work with our government customers in the defense and civilian agencies to identify new technologies.

OUR MISSION

NTS empowers our people to solve difficult problems by challenging the status quo; delivering uncompromising technology, unrivaled services, and unwavering support to our clients.

OUR CORE VALUES

COMMITTED TO EXCELLENCE:

We believe that performing to the highest standards, encouraging and promoting excellence through innovation and creativity is fundamental to our ability as an organization.

INNOVATIVE:

We believe that challenging the status quo in a changing world demands embracing life-long learning, staying ahead of the curve, thinking outside of the box, and a dedication to growth.

CUSTOMER-FOCUSED PASSION:

We put our customers at the heart of everything we do. We believe that our people are our greatest asset and that our customers will never love our company until our people love it first. We strive to provide a talented workforce that is paid well, appreciated, listened to, promoted, involved in decisions, and challenged so they can enthusiastically and passionately deliver responsive, timely, quality work.

ETHICAL:

We promote honesty, integrity, and openness in all we do. We act with integrity and honesty in the work we do, the people we interact with, and in the decisions that we make. We are ethical in all interactions and maintain the highest ethical standards. We are accountable to one another and to our partner vendors and customers to whom we serve.

FAIRNESS IN ALL THAT WE DO:

We believe that our greatest potential can only be achieved in a collaborative solutions-oriented environment of common purpose and shared success where everyone is treated fairly.

Similar Jobs

See more jobs