Excentium is a Service-Disabled Veteran-Owned Small Business (SDVOSB) providing cybersecurity and IT services to federal agencies. We hold FedRAMP 3PAO accreditation, CMMC Level 2 certification, and maintain facility clearances supporting our mission-critical work across government. We take pride in building a workforce with strong Veterans focus.
Security/Compliance Engineer
Location
United States
Posted
1 day ago
Salary
Not specified
Job Description
Role Description
Lead security compliance and ATO activities for a major government healthcare organization's ServiceNow implementation. Ensure the solution meets FedRAMP High requirements and federal security standards.
- Lead Authority to Operate (ATO) package development and submission
- Coordinate FedRAMP compliance activities with ServiceNow as the CSP
- Implement and document customer responsibility matrix controls
- Conduct security assessments and vulnerability remediation
- Ensure compliance with federal security policies and NIST 800-53 controls
- Monitor and respond to security events and incidents
- Develop and maintain security documentation including SSP, POA&M, and contingency plans
- Coordinate with government ISSO and Security Operations Center
Qualifications
- 7+ years of information security experience, with 3+ years in federal environments
- FedRAMP and federal ATO experience required
- Experience with cloud security (AWS, Azure) and SaaS security models
- Knowledge of NIST 800-53, FISMA, and federal security requirements
Requirements
- Bachelor’s degree in computer science or related field
- CISSP, CISM, CISA or equivalent certification required
Company Description
Excentium is a Service-Disabled Veteran-Owned Small Business (SDVOSB) providing cybersecurity and IT services to federal agencies. We hold FedRAMP 3PAO accreditation, CMMC Level 2 certification, and maintain facility clearances supporting our mission-critical work across government.
We take pride in building a workforce with strong Veterans focus.
Job Requirements
- 7+ years of information security experience, with 3+ years in federal environments
- FedRAMP and federal ATO experience required
- Experience with cloud security (AWS, Azure) and SaaS security models
- Knowledge of NIST 800-53, FISMA, and federal security requirements
- Bachelor’s degree in computer science or related field
- CISSP, CISM, CISA or equivalent certification required
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Chief Information Security Officer
Nsight HealthAt Nsight Health, you’ll be part of a fast-growing organization that sits at the intersection of healthcare, technology, and compassion. We’re looking for people who care deeply about improving patient lives and building the future of connected care. Our team culture is collaborative, agile, and purpose-driven. Every role—from clinical operations and customer success to marketing, technology, and leadership—directly contributes to improving how healthcare organizations care for their patients.
We are seeking a visionary yet pragmatic Chief Information Security Officer (CISO) to build and own Nsight Health’s security and compliance function from the ground up. As we scale our AI-powered healthcare platform, we require a leader who views security not as a blocker, but ...
Senior Cloud Security Engineer
Sift HealthcareSift transforms healthcare payments through advanced data science.
Sift Healthcare is seeking a Senior Cloud Security Engineer to join our growing team. The Senior Cloud Security Engineer will be responsible for designing, implementing, and maintaining secure cloud infrastructure, platforms, and applications for Sift and will work closely with c...
cFocus Software seeks a Sr. Cybersecurity Engineer / Architect to join our program supporting the National Institutes of Health (NIH). This position is remote and requires a Public Trust clearance. Lead security engineering and architecture activities Implement NIST 800-53 contro...
Sr. Network Security Engineer (Hybrid)
CrowdStrikeCrowdStrike has redefined security with the world’s most advanced cloud-native platform that protects and enables the people, processes and technologies that drive modern enterprise. Tested and proven, the world's largest organizations trust CrowdStrike to stop breaches with unparalleled protection against the most sophisticated cyberattacks. The CrowdStrike culture has been built upon our Core Values since the day we began. We are Fanatical About the Customer, Relentlessly Focused on Innovation and believe that our Limitless Passion drives Unlimited Potential for every CrowdStriker. As a purpose-built remote-first company, we believe cultivating a connected culture for every employee, no matter where they are in the world, is a key ingredient in building a high-performing, diverse team. We don’t have a mission statement. We’re on a mission—to stop breaches. Ready to join a mission that matters?
The role involves developing and deploying network security measures, managing DDoS defenses, and improving security practices across the organization's hybrid cloud network.