IT Senior Security Engineer

Bethesda, MD
Full Time
Engineering
Experienced
Senior Security Engineer

Location: Bethesda, MD (Requires Onsite 3–5 days per week as needs change)
Employment Type: Full-time


The National Library of Medicine (NLM) is seeking an IT Senior Security Engineer to join our Security Compliance team. In this role, you will work closely with the NLM Information Systems Security Office and play a critical part in safeguarding NLM’s IT infrastructure.

The Senior Security Engineer plays a hands-on role in a multi-disciplined security team, focusing on the implementation of security controls, ensuring compliance with the federal cybersecurity framework (FISMA), and supporting secure cloud adoption across multiple platforms. Collaborating closely with endpoint owners, infrastructure and network security teams, as well as enterprise security teams to meet NIH mandates, this engineer actively works across vulnerability management, application security, cloud security, SIEM, and bringing in new AI-based tooling to strengthen the organization's overall security posture. Receiving day-to-day technical direction from the ISSO and collaborating with tool owners and system administrators—rather than managing any single platform outright—the ideal candidate brings a strong foundation in systems administration, deep hands-on security engineering experience, and the ability to optimize the effectiveness of existing security tools. As part of a broader IT program providing end-to-end support including network, incident response, and security services, this role is critical in ensuring the availability, integrity, and confidentiality of mission-critical systems.

Responsibilities
  • Enhance and automate security and compliance checks using scripting and available tools; evaluate emerging technologies, including AI capabilities, to improve security coverage and operational efficiency. Lead team efforts to integrate AI/ML-driven capabilities with the current security tools and operations to enhance and automate assessment and remediation using LLM within NLM
  • Implement and maintain security controls for on-prem and cloud environments (AWS, GCP, Azure), ensuring compliance with FISMA, NIH policy, and federal security requirements.
  • Recommend and support security services for identity access, privileged access, vulnerability management, encryption, network micro-segmentation, and centralized log management in both cloud and on-premises systems.
  • Integrate and optimize enterprise security and SIEM solutions (e.g., Splunk, Tenable) for continuous monitoring, event correlation, and compliance visibility in hybrid environments.
  • Conduct threat modeling and security assessments of cloud deployments, identifying and mitigating vulnerabilities and supporting secure cloud migrations.
  • Provide security guidance, best practices, and compliance support to developers, operations teams, and system owners, promoting security awareness across the organization.
  • Analyze vulnerability and assessment data to identify systemic risks, remediation trends, and opportunities for process or tool improvement, collaborating with system administrators and security teams for practical, risk-informed remediation.
  • Contribute and manage documentation, standard operating procedures, and technical guidance to support the broader security program and ensure consistent practices.
Required Qualifications
  • Extensive experience securing on-premises and cloud environments (AWS, GCP, Azure), with strong working knowledge of cloud security models, logging, tagging strategies, ephemeral resource tracking, and cross-platform operations; proven hands-on security engineering background in federal, regulated settings.
  • 10+ years in securing information technology, plus 7+ years in hands-on security engineering built on a systems administration foundation including at least 3 years focused on cloud security and administration of Linux and Windows endpoints
  • Familiarity with AI/ML integration in security tooling and operations, supporting modern approaches to threat detection and remediation.
  • Demonstrated expertise applying federal compliance frameworks (FISMA, NIST 800-53, FedRAMP, RMF), supporting system authorization processes (ATO, POA&M), and navigating complex governance and compliance requirements.
  • Admin or engineering-level experience with at least two security tools such as Tenable, Checkmarx, or Splunk, along with a strong understanding of vulnerability management, application security testing, and remediation workflows.
  • Bachelor’s degree in computer science, cybersecurity, information technology, or related technical field (or equivalent technical experience)
  • CISSP certification (or ability to obtain within 6 months).
  • Effective collaboration and guidance for multi-disciplinary teams managing servers, workstations, network and security appliances within regulated environments; ability to adapt to shifting priorities and contribute to team goals.
  • Strong written and verbal communication skills, with a proven ability to produce clear security documentation and explain technical concepts to both technical and non-technical stakeholders.
Desired Qualifications
  • Hands-on work experience with AI/ML automation, security event correlation, asset inventory tracking and SEIM management (preferably in SPLUNK), utilizing scripting or programming such as PowerShell, Bash, Python or equivalent and use of APIs
  • Advanced Linux and Windows administration experience, Certified in AWS/AZURE/GCP
  • Experience with container security (like Docker & Kubernetes)
  • Master’s degree in computer science, Cybersecurity, Information Technology, or a related technical field
Share

Apply for this position

Required*
We've received your resume. Click here to update it.
Attach resume as .pdf, .doc, .docx, .odt, .txt, or .rtf (limit 5MB) or Paste resume

Paste your resume here or Attach resume file

To comply with government Equal Employment Opportunity and/or Affirmative Action reporting regulations, we are requesting (but NOT requiring) that you enter this personal data. This information will not be used in connection with any employment decisions, and will be used solely as permitted by state and federal law. Your voluntary cooperation would be appreciated. Learn more.

Invitation for Job Applicants to Self-Identify as a U.S. Veteran
  • A “disabled veteran” is one of the following:
    • a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or
    • a person who was discharged or released from active duty because of a service-connected disability.
  • A “recently separated veteran” means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.
  • An “active duty wartime or campaign badge veteran” means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.
  • An “Armed forces service medal veteran” means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.
Veteran status



Voluntary Self-Identification of Disability
Voluntary Self-Identification of Disability Form CC-305
OMB Control Number 1250-0005
Expires 07/31/2029
Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Please check one of the boxes below:

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.

You must enter your name and date
Human Check*