Role Overview
Core One is hiring a entry-level Security Engineer. This is a full-time role in McLean. Part of Core One's Lifecycle hiring. Full responsibilities, required qualifications, and the apply link are listed in the description below.
Salary Context
Salary is not disclosed in this posting. Market median for Junior-level Lifecycle roles is $89k-$134k (based on 116 comparable listings). Many employers share specifics during the interview process or after an initial screen.
Resume Keywords to Include
Make sure these keywords appear in your resume to improve ATS scoring
Job description
Join our team at Core One! Our mission is to be at the forefront of devising analytical, operational and technical solutions to our Nation's most complex national security challenges. In order to achieve our mission, Core One values people first! We are committed to recruiting, nurturing, and retaining top talent! We offer a competitive total compensation package that sets us apart from our competition. Core One is a team-oriented, dynamic, and growing company that values exceptional performance!
Clearance Required: Active TS/SCI with Polygraph
Summary
We are seeking a Senior Security Engineer to support cybersecurity operations, compliance, and risk management for FedRAMP-authorized and Intelligence Community (IC) systems. This role is responsible for ensuring systems meet stringent federal security requirements while enabling secure, scalable, and compliant cloud and on-premises solutions.
The ideal candidate brings deep expertise in NIST frameworks, FedRAMP authorization processes, continuous monitoring (ConMon), cloud security, incident response, and ATO lifecycle management, along with the ability to operate effectively within classified and high-security environments.
The Senior Security Engineer serves as the primary cybersecurity technical authority supporting system engineering, cloud architecture, DevSecOps pipelines, compliance initiatives, and operational security monitoring.
Key Responsibilities
- Lead and support FedRAMP Moderate/High and IC ATO authorization efforts, ensuring compliance with NIST RMF, NIST 800-53, NIST 800-37, FedRAMP, and ICD 503 requirements.
- Conduct risk assessments, security control assessments, gap analyses, and security architecture reviews to identify and mitigate cybersecurity risks.
- Manage the full Risk Management Framework (RMF) lifecycle, including system categorization, control selection, implementation, assessment, authorization, and continuous monitoring.
- Develop and maintain security documentation such as SSPs, SARs, POA&Ms, and control traceability artifacts, while tracking remediation activities.
- Execute Continuous Monitoring (ConMon) programs through vulnerability assessments, compliance reviews, security control validation, and reporting.
- Lead vulnerability management activities using tools such as Nessus, ACAS, SCAP, and STIG Viewer, validating remediation and coordinating risk mitigation efforts.
- Support Security Operations and Incident Response, including threat monitoring, alert analysis, incident investigations, root cause analysis, and coordination with SOCs and government stakeholders.
- Design and assess security controls for AWS GovCloud, Azure Government, and other government cloud environments, implementing IAM, encryption, logging, and least-privilege access controls.
- Integrate security into DevSecOps and CI/CD pipelines through automated security testing, vulnerability scanning, compliance validation, and Infrastructure-as-Code security practices.
- Support audits and assessments, including 3PAO reviews, FedRAMP assessments, agency ATO reviews, and IG audits, while preparing evidence and coordinating with auditors and assessors.
- Administer and utilize governance, compliance, monitoring, and vulnerability management tools such as ServiceNow GRC, Splunk, and Azure.
- Collaborate with developers, engineers, cloud architects, ISSOs/ISSMs, compliance teams, and government stakeholders to provide cybersecurity guidance throughout system development and operations.
- Contribute to security governance, policy development, cybersecurity program maturity, and organizational security culture, while mentoring junior staff and promoting risk-informed decision-making.
Required Qualifications
- Active TS/SCI with Polygraph
- Bachelor's degree or higher in Cybersecurity, IT, or related field and 5+ years' experience in Cybersecurity in federal or IC environments
- OR Masters and 3+ years of experience in Cybersecurity in federal or IC environments
- Strong Knowledge of NIST RMF (800-37), NIST 800-53 controls, and FedRAMP requirements
- At least one of the following certifications: CISM or CISA, CompTIA Security+ (baseline), Certified Authorization Professional (CAP), CCSP (cloud security)
- Experience in the following tools: NIST 800-53, RMF, FedRAMP, ICD 503, ServiceNow GRC, Splunk, AWS GovCloud, Azure
Desired Qualifications
- Experience with cloud-native security tools
- Knowledge of Zero Trust Architecture
- Experience with cross-domain solutions
- Familiarity with DevSecOps pipelines in regulated environments
Core One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity, sexual orientation, national origin, or protected veteran status and will not be discriminated against on the basis of disability.
__PRESENT
__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT
About Core One
Core One
coreone.com
62 other open roles at Core One on TryApplyNow.
Frequently Asked Questions
How do I apply for the Security Engineer position at Core One?
Use the Apply button above to submit your application directly to Core One. Most applications take less than 5 minutes if your resume and contact details are ready, and you'll be routed to the employer's official application system to finish.
Where is the Security Engineer position at Core One located?
This position is based in McLean. Core One has not indicated remote or hybrid options for this role, so candidates should plan for on-site work.
What does a Security Engineer at Core One earn?
Core One has not disclosed a salary range in this posting. Many employers share specifics later in the interview process; you can also ask during a recruiter screen if compensation transparency is important to you.
When was the Security Engineer role at Core One posted?
This role was posted on June 2, 2026 (50 days ago). It's still listed as actively hiring; we re-confirm openings against the source system multiple times per day and remove closed roles.
Is the Security Engineer role at Core One entry-level?
Yes. This is an entry-level position. Strong candidates typically have 0-2 years of relevant work experience, internships, or significant project work. Read the full description for any specific qualification requirements Core One has listed.
Similar Jobs
Corporate Recruiter
HITT Contracting Inc
Customer Success Manager II - Dallas, TX
Opengov
Customer Success Manager II - San Francisco, CA
Opengov
Helix AI Engineer, Modeling
Figureai
Security Engineer, Vulnerability Management and Automation
Figureai
More Jobs at Core One
View all →AI-powered job search
Get every job scored to your resume
Upload your resume and get jobs ranked, your resume tailored, and employee contacts found automatically.
Get started freeNo credit card to start