Security Compliance Engineer
The Opportunity NTS is seeking an experienced Security Compliance Engineer with deep expertise in Linux system security, DISA STIG implementation, and regulated-environment compliance frameworks including FedRAMP and CMMC.
You will own the technical execution of our compliance programtranslating control requirements into hardened system configurations, automated scanning pipelines, and auditable evidence packageswhile partnering with engineering teams to maintain secure-by-default infrastructure.
This is a hands-on engineering role.
You will be expected to read STIGs, write Ansible playbooks, triage CVEs, and operate scanning toolingnot just manage checklists.
Key Responsibilities (Principal Duties and Accountabilities
*Essential Functions) STIG Implementation & System Hardening Apply and maintain DISA STIGs across various Linux distributions (RHEL, Ubuntu, SUSE, etc) using OpenSCAP, Ansible STIG roles and/or manual remediationDevelop and maintain automated hardening pipelines that produce STIG-compliant OS images via bootc+bib, KIWI/EIB and/or Packer for bare-metal, VM, and cloud deployment targetsConfigure and tune host-based security controls: SELinux (enforcing/targeted/MLS), auditd rules, fapolicyd application whitelisting, firewalld, and PAMImplement and validate CIS Benchmark controls as a complement to STIG baselinesMaintain STIG checklists (CKL/CKLB) and produce POA&M artifacts for findings requiring waivers or scheduled remediation Vulnerability Management Operate and maintain authenticated scanning infrastructure using Tenable Nessus / Security Center or equivalent; schedule, tune, and triage scan results at scalePerform continuous CVE triage using NVD, CVSS v3/v4, and EPSS scores to drive prioritized remediation workflows with engineering teamsTrack open vulnerabilities through full lifecycle: discovery, ticket creation, remediation verification, and closure evidenceDevelop metrics and dashboards for vulnerability posture reporting to technical and executive audiencesCoordinate patch cadence with platform teams; validate patched images against scan baselines before promotion to production FedRAMP Authorization & Continuous Monitoring Support FedRAMP authorization activities (Low, Moderate, or High baselines) including SSP development, control implementation statements, and evidence collectionOperate and maintain ConMon programs: monthly vulnerability scanning, POA&M updates, significant change requests (SCRs), and annual assessmentsCollaborate with Third Party Assessment Organizations (3PAOs) during assessments; prepare technical staff and produce assessment-ready evidence packagesMap NIST SP 800-53 Rev 5 controls to technical implementation across infrastructure, applications, and organizational processesMaintain the SSP, CIS, SAR, and SAP documentation sets through authorization lifecycle CMMC & DoD Compliance Implement and assess CMMC Level 13 practices against NIST SP 800-171 and NIST SP 800-172 requirementsMaintain the System ...
- Rate: Not Specified
- Location: Tampa, US-FL
- Type: Permanent
- Industry: Finance
- Recruiter: NexTech Solutions LLC
- Contact: Not Specified
- Email: to view click here
- Reference: 621248261
- Posted: 2026-08-21 09:30:19 -
- View all Jobs from NexTech Solutions LLC
More Jobs from NexTech Solutions LLC
- Power and Utilities Area Technical Assistant
- Electronic Assembler - 1st Shift
- Electronic Assembler - 2nd Shift
- Electronic Assembler - 2nd Shift
- Manufacturing Shift Leader
- Electronic Assembler - 1st Shift
- Electronic Assembler - 2nd Shift
- Production Operator - 2nd Shift
- Production Operator - 1st Shift
- Production Operator - 3rd Shift
- Production Operator - 3rd Shift
- Electronic Assembler - 2nd Shift
- Production Operator - 2nd Shift
- Quality Coordinator - Owosso, MI
- Project Manager, Transportation Solutions
- Assembler - 2nd Shift
- Production Operator - 1st Shift
- Electrical Foreman
- Assembler - 1st Shift
- Construction Performance Engineer