Senior Information Security Engineer

4 weeks ago


Washington, United States C2 Labs, Inc. Full time

Senior Information Security Engineer / Vulnerability Manager C2 Labs, Inc. www.c2labs.com C2 Labs partners with clients on their IT transformation journey via our industry-leading capabilities in full stack development, hyper-automation/DevOps, and cybersecurity compliance. We provide specialized products and services that enable clients to innovate with speed and scale while maintaining a robust and effective security posture. As digital transformation partners, we address the most urgent needs holding back our clients, including proactively addressing cultural change, quantifying risk, automating compliance, and closing critical skill gaps. Job Duties As a Senior Information Security Engineer / Vulnerability Manager, you will lead efforts to identify, assess, and mitigate security vulnerabilities across complex enterprise IT environments. Responsibilities include: Vulnerability & Threat Management Manage enterprise vulnerability management platforms (e.g., Tenable, Qualys, Rapid7) and ensure timely scanning, reporting, and remediation tracking. Perform risk-based analysis of vulnerabilities, develop mitigation plans, and escalate issues requiring urgent remediation. Integrate threat intelligence to prioritize vulnerabilities based on exploitability, industry trends, and business impact. Establish and maintain vulnerability KPIs, metrics, and executive reporting dashboards. Security Engineering Design, implement, and maintain security controls and safeguards across networks, endpoints, and cloud environments (AWS, Azure, or hybrid). Automate security operations tasks using scripts or tools (Python, PowerShell, Bash, or AWS Lambda). Collaborate with IT and DevOps teams to integrate vulnerability management into CI/CD pipelines and cloud workloads. Conduct regular security assessments, penetration test remediation support, and continuous monitoring activities. Governance, Risk, & Compliance Support compliance with federal frameworks (FedRAMP, NIST SP 800-53, NIST SP 800-171/CMMC, FISMA, etc.). Document processes, remediation plans, and compliance evidence in alignment with client requirements. Provide recommendations for continuous improvement of security posture and policy enforcement. Collaboration & Leadership Partner with cross-functional teams (IT, Development, Operations, and Compliance) to ensure vulnerabilities are remediated in a timely, risk-based manner. Provide technical leadership and mentorship to junior security engineers and analysts. Participate in client-facing meetings and presentations as a subject matter expert in vulnerability and threat management. Education, Training, Qualifications, and Certifications Required: U.S. Citizenship and ability to obtain/maintain Public Trust clearance Bachelors degree in Computer Science, Cybersecurity, or related field OR 5+ years of equivalent hands-on experience Proven experience in vulnerability management, security engineering, or penetration testing Strong knowledge of IT infrastructure, networking, and cloud environments (AWS preferred) Familiarity with security automation, scripting (Python, PowerShell, Bash), and infrastructure-as-code principles Excellent analytical, problem-solving, and communication skills Background check and unannounced drug testing required. This position is onsite in Washington, DC, with occasional travel (up to 25%) for client meetings and work assignments. Preferred: Professional certifications such as CISSP, CISM, OSCP, CEH, Security+, or AWS Security Specialty Experience with compliance frameworks (FedRAMP, NIST 800-53, CMMC) Background in DevSecOps practices, continuous monitoring, and automation EOE STATEMENT: We are an equal opportunity employer. All qualified applicants will be considered without discrimination based on race, color, religion, sex, national origin, age, disability, or protected veteran status. Employment offers will be contingent on passing a pre-employment drug screen. #J-18808-Ljbffr



  • Washington, United States General Dynamics Information Technology Full time

    Senior Network Engineer Transform technology into opportunity as a Senior Network Engineer with GDIT. A career in enterprise IT means connecting and enhancing the systems that matter most. At GDIT you'll be at the forefront of innovation and play a meaningful part in improving how agencies operate. At GDIT, people are our differentiator. As a Senior Network...


  • Washington, United States MANTECH Full time

    MANTECH seek a motivated, career and customer-oriented Senior Information System Security Engineer to join our team Washington, DC.Responsibilities include, but are not limited to:Define IS and Network Environment security requirements in accordance with applicable cybersecurity requirements.Design security architectures for use within the IS and Network...


  • Washington, United States ManTech Full time

    MANTECH seek a motivated, career and customer-oriented Senior Information System Security Engineer to join our team Washington, DC. Responsibilities include, but are not limited to: Define IS and Network Environment security requirements in accordance with applicable cybersecurity requirements. Design security architectures for use within the IS and Network...


  • Washington, United States General Dynamics Information Technology Full time

    Information Security Analyst Advisor (Azure Security Senior Engineers) DC Metro Area Your Impact Own your opportunity to work alongside federal civilian agencies. Make an impact by providing services that help the government ensure the wellbeing of U.S. citizens. Job Description We are seeking a qualified, motivated individual to join GDIT as an Information...


  • Washington, DC, United States ManTech Full time

    MANTECH seek a motivated, career and customer-oriented Senior Information System Security Engineer to join our team Washington, DC. Responsibilities include, but are not limited to: Define IS and Network Environment security requirements in accordance with applicable cybersecurity requirements. Design security architectures for use within the IS and Network...


  • Washington, DC, United States ManTech Full time

    MANTECH seek a motivated, career and customer-oriented Senior Information System Security Engineer to join our team Washington, DC. Responsibilities include, but are not limited to: Define IS and Network Environment security requirements in accordance with applicable cybersecurity requirements. Design security architectures for use within the IS and Network...


  • Washington, DC, United States ManTech Full time

    MANTECH seek a motivated, career and customer-oriented Senior Information System Security Engineer to join our team Washington, DC. Responsibilities include, but are not limited to: Define IS and Network Environment security requirements in accordance with applicable cybersecurity requirements. Design security architectures for use within the IS and Network...


  • Washington, DC, United States ManTech Full time

    MANTECH seek a motivated, career and customer-oriented Senior Information System Security Engineer to join our team Washington, DC. Responsibilities include, but are not limited to: Define IS and Network Environment security requirements in accordance with applicable cybersecurity requirements. Design security architectures for use within the IS and Network...


  • Washington, DC, United States ManTech Full time

    MANTECH seek a motivated, career and customer-oriented Senior Information System Security Engineer to join our team Washington, DC. Responsibilities include, but are not limited to: Define IS and Network Environment security requirements in accordance with applicable cybersecurity requirements. Design security architectures for use within the IS and Network...


  • Washington, DC, United States ManTech Full time

    MANTECH seek a motivated, career and customer-oriented Senior Information System Security Engineer to join our team Washington, DC. Responsibilities include, but are not limited to: Define IS and Network Environment security requirements in accordance with applicable cybersecurity requirements. Design security architectures for use within the IS and Network...