Jobs · Information Technology · Virginia

ConMon Security Engineer

Telos Corporation · Tysons Corner, VA · 2 days ago
Information Technology$135k–$155k/yrFull-time

About the role

Telos is seeking a highly skilled Cybersecurity Professional to modernize and operate our Continuous Monitoring (ConMon) program for our customers. This role is designed for a strategic thinker capable of bridging the gap between operational compliance and scalable program development. The ideal candidate will leverage an extensive background as a ConMon practitioner, an Information System Security Officer (ISSO) and subject matter expertise in eMass to ensure mission-critical systems maintain their Authorization to Operate (ATO). We are looking for a professional who not only executes daily security mandates but also possesses the vision to automate complex workflows and standardize security procedures at an organizational scale.

Responsibilities

Continuous Monitoring Operations

  • Execute the end-to-end monthly government submission process, ensuring all required security documentation is accurate and delivered on schedule.
  • Manage and maintain system records within eMass, serving as the primary subject matter expert for data entry, reporting, and workflow management.
  • Perform comprehensive parsing and analysis of vulnerability scan files (e.g., Tenable, Qualys), comparing results against historical data to identify emerging risks.
  • Own the Plan of Action & Milestones (POA&M) lifecycle, including weekly tracking, stakeholder follow-up, and driving all identified vulnerabilities to remediation.
  • Coordinate the collection of compliance evidence (e.g., facility access reviews, audit logs) by building strong professional relationships with system owners and stakeholders.

Automation-Driven Operational Excellence

  • Spearhead the design and implementation of automated workflows to streamline recurring evidence collection and reporting tasks.
  • Orchestrate the development of scripts and utilization of advanced tools to modernize the tracking of ConMon activities and data workflows.
  • Conduct gap analyses on existing processes to modernize areas of improvement, particularly concerning the transition to updated regulatory frameworks such as NIST SP 800-53 Rev 5.
  • Standardize security procedures and compliance artifacts at an organizational scale to ensure consistency across all enclaves.
  • Author justification language and remediation instructions to provide engineering teams with clear, actionable guidance.

Stakeholder & Relationship Management

  • Build and cultivate strong professional relationships with ConMon owners to ensure alignment on security standards and evidence requirements.
  • Act as a trusted advisor to stakeholders, proactively negotiating acceptable evidence formats that can be standardized across all organizational ConMon programs.
  • Communicate compliance status and remediation expectations clearly to technical and non-technical stakeholders to ensure seamless operational continuity.

Qualifications

  • Bachelor's degree in computer science, engineering, information assurance, or a related discipline and has at least 5 or more years of experience in an information technology role. Additional experience may be substituted for a degree.
  • US Citizenship with an active Top Secret (TS) Clearance (Required).
  • Currently DoD 8140 compliant or possessing the necessary certifications for immediate certification (Required).
  • Extensive professional experience managing the full lifecycle of Continuous Monitoring (ConMon) programs and complex cybersecurity operations for enterprise systems.
  • Subject matter expertise in eMass, including advanced system administration, package management, and reporting functions.
  • Strong understanding of cloud security architecture and best practices.
  • Proven ability to design and implement automated security solutions or scripts (e.g., Python, SQL) to modernize data collection, vulnerability parsing, and reporting workflows.
  • Capability to institutionalize standardized security procedures and compliance artifacts at an organizational scale.
  • Exceptional stakeholder management skills, with the ability to cultivate relationships with system owners, negotiate evidence requirements, and provide authoritative guidance.
  • Strong analytical capability to translate complex vulnerability data into clear, actionable remediation plans for engineering teams.
  • High level of operational rigor, with demonstrated success in managing audit-ready documentation and complex project lifecycles.

Pay

The annual salary range for this position is $135,000 - $155,000.

Benefits

  • Generous paid time off
  • Medical, dental, and vision insurance
  • Tuition reimbursement
  • 401k

Schedule

This position will be based at Tysons, VA.

Similar jobs

Engineer - Security

Basis SetPhiladelphia, PA· 2 wk ago
Information Technologyapply on jobs.basisset.com

Security Engineer

Workers'​ Compensation Insurance Rating Bureau of California (WCIRB)San Francisco, CA· 2 wk ago
Information Technologyapply on wcirb.com

Security Engineer

ResilienceWashington, DC· 1 mo ago
RemoteEngineering$150k/yrapply on grnh.se

Security Engineer

BirdiPlymouth, MI· 2 mo ago
Information Technologyapply on birdiinc.rec.pro.ukg.net

Security Engineer

Check Point SoftwarePortland, OR· 1 wk ago
Business Development$122k–$248k/yrapply on careers.checkpoint.com