Location
US-FL-Orlando
ID
2026-11501
| Category |
Systems Engineer
|
Position Type |
Regular Full-Time
|
Application Open Date |
9/3/2026
|
Description
SRC is hiring a hands-on, Agile-embedded Security Engineer responsible for securing virtualized Modeling & Simulation (M&S) environments, automating compliance-as-code across a diverse infrastructure, and developing custom security tools and telemetry dashboards. This role bridges the gap between technical execution and security governance by advising security leadership, managing vulnerabilities, and ensuring continuous compliance with DoD directives.
Vulnerability & Patch Management
Implement, coordinate, and maintain patching procedures across diverse environments, including Linux, Windows, VMware virtual layers, and Cisco network systems.
- Design and deploy automated patching processes for Windows and Linux workloads to minimize manual intervention and reduce the overall attack surface.
- Execute and review regular vulnerability scans and DISA STIG compliance audits to assess system risk.
- Analyze vulnerability data to prioritize and execute remediation efforts across endpoints, networks, and software applications.
- Responsible for securing and hardening physical and virtual hardware, operating systems, and software configurations.
Governance, Risk & Compliance (GRC)
- Support the tracking, resolution, and milestone completion for the program's Plan of Action and Milestones (POA&M) items.
- Author, update, and maintain comprehensive program security policies, operational procedures, and technical security standards.
- Ensure all engineering and operational activities comply with relevant DoD standards, directives, regulations, and NIST frameworks.
- Conduct structured risk assessments and provide direct technical support for program audit activities.
- Serve as a key technical advisor to the ISSO (Information System Security Officer) and ISSM (Information System Security Manager) on the security, engineering, and monitoring of classified DoD networks.
- Create, update, and maintain detailed data flow and system boundary diagrams to support authorization packages.
- Remain continuously abreast of emerging technologies, cyber threats, vulnerabilities, and modern security tools.
Security Architecture & Engineering
- Design, implement, configure, and manage comprehensive security solutions, including SIEM (Splunk), EDR (Trellix), Host/Network IDS/IPS (Wazuh), firewalls, Identity & Access Management (IAM), and VPNs.
- Evaluate, test, and integrate new security technologies, tools, and SaaS/on-prem solutions into the existing environment.
- Embed directly within Agile software development squads, collaborating during sprint planning, story estimation, and retrospectives to ensure security engineering tasks keep pace with release cadence.
Requirements
- Active DoD 8570/8140 IAT Level II baseline credential (such as CompTIA Security+ CE, CySA+, or equivalent) required on day one.
- Active DoD Secret clearance with verified TS/SCI Eligibility (ability to pass a Single Scope Background Investigation).
- Bachelor's (BS) degree in Cybersecurity, Computer Science, Information Technology, or a related technical field (equivalent professional experience will be considered).
- Strong understanding of network protocols, security architecture patterns, and hands-on experience securing both Linux-based and Windows-based systems.
- Highly proficient in scripting and programming languages (e.g., Python, PowerShell, Bash) to build custom automated tools and utilities.
- Hands-on experience with modern automation and configuration management tools (such as Ansible, Terraform, Puppet, or Chef).
- Practical understanding of CI/CD concepts, including how to embed security controls, automated testing, and compliance-as-code into deployment pipelines.
- In-depth knowledge of modern threat landscapes, software vulnerabilities, threat mitigation techniques, and standard security processes.
- Strong familiarity with cybersecurity frameworks and control sets, specifically NIST SP 800-53, NIST SP 800-171, SOC 2, and/or ISO 27001.
- Proven ability to author clear, concise, and accurate cybersecurity guidance, standard operating procedures (SOPs), and program documentation.
Desired Skills
- Prior experience supporting cybersecurity operations for high-fidelity DoD modeling, simulation, and synthetic training networks.
- Experience conducting threat modeling, static code analysis (SAST), or dynamic code analysis (DAST) within software development lifecycles.
- Familiarity with securing containerized environments (Docker) and container orchestration platforms (Kubernetes).
Clearance Information
SRC IS A CONTRACTOR FOR THE U.S. GOVERNMENT, THIS POSITION WILL REQUIRE U.S. CITIZENSHIP AS WELL AS, A U.S. GOVERNMENT SECURITY CLEARANCE AT THE SECRET LEVEL WITH TOP SECRET / SCI ELGILIBILTY
Travel Requirements
About Us
Scientific Research Corporation is an advanced information technology and engineering company that provides innovative products and services to government and private industry, as well as independent institutions. At the core of our capabilities is a seasoned team of highly skilled engineers and scientists with multidisciplinary backgrounds. This team is challenged daily to provide cutting edge technology solutions to our clients. SRC offers a generous benefit package, including medical, dental, and vision plans, 401(k) with a company match, life insurance, vacation and sick paid time off accruals with amounts increasing based on role and years of service, 11 paid holidays, tuition reimbursement, and a work environment that encourages excellence and more. For positions requiring a security clearance, selected applicants will be subject to a government security investigation and must meet eligibility requirements for access to classified information.
EEO
Scientific Research Corporation is an equal opportunity employer that does not discriminate in employment. All qualified applicants will receive consideration for employment without regard to their race, color, religion, sex, age, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other protected characteristic under federal, state or local law. Scientific Research Corporation endeavors to make www.scires.com accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact jobs@scires.com for assistance. This contact information is for accommodation requests only and cannot be used to inquire about the status of applications.
|