Summary
Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. The company seeks a Mid Security Engineer to protect agency networks and information by implementing, monitoring, and upgrading security measures, primarily in cloud environments. The role also supports security engineering, automation and AI-enabled capabilities, Zero Trust architecture, systems integration, and cybersecurity toolset enhancement.
Responsibilities
- Plan, implement, upgrade, and monitor security measures protecting agency networks, systems, and information
- Ensure appropriate security controls are in place to safeguard digital files and vital electronic infrastructure
- Design and develop security solutions for complex problems, system administration issues, and network concerns
- Perform systems management and integration functions, primarily in cloud environments
- Support the integration and development of automated and AI-based solutions in complex cloud environments
- Assist in designing interface standards, quality assurance standards, and performance standards, and perform cost-benefit analysis of modern, state-of-the-art information systems
- Analyze available technologies and recommend which to adopt and how best to apply them
- Support security engineering delivery to the agency's cybersecurity architecture and engineering function
- Maintain, research, enhance, and engineer the agency's cybersecurity environment and toolsets to improve overall security posture
- Contribute to the design and implementation of a resilient architecture that integrates Zero Trust principles, including secure deployment, validation, and continuous monitoring of security controls
- Support Security Impact Assessments and help maintain interconnection and data exchange security agreements for secure cloud service integration
Skills
- * Bachelor's degree in a technical or cybersecurity-related field
- * 2 to 3 years of professional experience in cybersecurity with a working understanding of security engineering functions and capabilities
- * Demonstrated experience implementing, upgrading, or monitoring security controls and security tooling
- * Hands-on experience performing systems management and integration in cloud environments (AWS, Azure, or GCP)
- * Experience designing or developing security solutions for complex system administration or network problems
- * U.S. Citizenship or Permanent Residency, with all work performed within the continental U.S
- * Ability to pass a federal agency suitability or background investigation
- * Cloud security engineering and cloud systems integration (AWS, Azure, or GCP)
- * Security control implementation, hardening, and configuration management
- * Security tooling administration: SIEM, vulnerability management, endpoint, and identity platforms
- * Automation and scripting (Python, PowerShell, Bash) and infrastructure-as-code concepts
- * AI-enabled and low-code/no-code security capability integration
- * Network and system architecture fundamentals, including segmentation and secure connectivity
- * Zero Trust principles and continuous monitoring of security controls
- * Technology evaluation, cost-benefit analysis, and standards development
- * Clear written and verbal communication with both technical and non-technical audiences
- * Ability to work independently and as a contributing member of a distributed team
- * Comfort operating in a fully remote setting with a camera-on meeting culture
- * Sound judgment about when to decide and when to escalate
- * Collaborative posture with system owners, business owners, developers, and assessors
- * Attention to documentation quality and follow-through on commitments
- * Prior federal contracting experience, particularly supporting a civilian agency cybersecurity program
- * Experience supporting or building automation, low-code/no-code, or AI-enabled security capabilities
- * Familiarity with Zero Trust architecture concepts and reference models
- * Familiarity with NIST SP 800-37 and NIST SP 800-53 control implementation from an engineering perspective
- * Experience with FedRAMP-authorized cloud services and the security agreements that govern their integration
- * Certifications such as Security+, CySA+, AWS Certified Security, Azure Security Engineer Associate, or GIAC equivalents
Qualifications
Must Haves
- * Bachelor's degree in a technical or cybersecurity-related field
- * 2 to 3 years of professional experience in cybersecurity with a working understanding of security engineering functions and capabilities
- * Demonstrated experience implementing, upgrading, or monitoring security controls and security tooling
- * Hands-on experience performing systems management and integration in cloud environments (AWS, Azure, or GCP)
- * Experience designing or developing security solutions for complex system administration or network problems
- * U.S. Citizenship or Permanent Residency, with all work performed within the continental U.S
- * Ability to pass a federal agency suitability or background investigation
- * Cloud security engineering and cloud systems integration (AWS, Azure, or GCP)
- * Security control implementation, hardening, and configuration management
- * Security tooling administration: SIEM, vulnerability management, endpoint, and identity platforms
- * Automation and scripting (Python, PowerShell, Bash) and infrastructure-as-code concepts
- * AI-enabled and low-code/no-code security capability integration
- * Network and system architecture fundamentals, including segmentation and secure connectivity
- * Zero Trust principles and continuous monitoring of security controls
- * Technology evaluation, cost-benefit analysis, and standards development
- * Clear written and verbal communication with both technical and non-technical audiences
- * Ability to work independently and as a contributing member of a distributed team
- * Comfort operating in a fully remote setting with a camera-on meeting culture
- * Sound judgment about when to decide and when to escalate
- * Collaborative posture with system owners, business owners, developers, and assessors
- * Attention to documentation quality and follow-through on commitments
Nice to Haves
- * Prior federal contracting experience, particularly supporting a civilian agency cybersecurity program
- * Experience supporting or building automation, low-code/no-code, or AI-enabled security capabilities
- * Familiarity with Zero Trust architecture concepts and reference models
- * Familiarity with NIST SP 800-37 and NIST SP 800-53 control implementation from an engineering perspective
- * Experience with FedRAMP-authorized cloud services and the security agreements that govern their integration
- * Certifications such as Security+, CySA+, AWS Certified Security, Azure Security Engineer Associate, or GIAC equivalents
Benefits
- Medical: Multiple POS health plan options including an HSA-compatible plan
- Dental: PPO coverage for preventive, basic, and major services
- Vision: Annual exam, frames, lenses, and contact lens allowance
- 401(k): Employer match up to 5% of eligible compensation
- Long-Term Disability: 100% employer-paid coverage at 50% of pre-disability earnings
- Life Insurance & AD&D: 100% employer-paid coverage valued at $10,000 each
- PTO: 15–25 days annually based on tenure, plus 16 hours of Floating PTO from day one
- Paid Federal Holidays: All 11 federal holidays observed