ConMon Security Engineer
About the role
Telos is seeking a highly skilled Cybersecurity Professional to modernize and operate our Continuous Monitoring (ConMon) program for our customers. This role is designed for a strategic thinker capable of bridging the gap between operational compliance and scalable program development. The ideal candidate will leverage an extensive background as a ConMon practitioner, an Information System Security Officer (ISSO) and subject matter expertise in eMass to ensure mission-critical systems maintain their Authorization to Operate (ATO). We are looking for a professional who not only executes daily security mandates but also possesses the vision to automate complex workflows and standardize security procedures at an organizational scale.
Responsibilities
Continuous Monitoring Operations
- Execute the end-to-end monthly government submission process, ensuring all required security documentation is accurate and delivered on schedule.
- Manage and maintain system records within eMass, serving as the primary subject matter expert for data entry, reporting, and workflow management.
- Perform comprehensive parsing and analysis of vulnerability scan files (e.g., Tenable, Qualys), comparing results against historical data to identify emerging risks.
- Own the Plan of Action & Milestones (POA&M) lifecycle, including weekly tracking, stakeholder follow-up, and driving all identified vulnerabilities to remediation.
- Coordinate the collection of compliance evidence (e.g., facility access reviews, audit logs) by building strong professional relationships with system owners and stakeholders.
Automation-Driven Operational Excellence
- Spearhead the design and implementation of automated workflows to streamline recurring evidence collection and reporting tasks.
- Orchestrate the development of scripts and utilization of advanced tools to modernize the tracking of ConMon activities and data workflows.
- Conduct gap analyses on existing processes to modernize areas of improvement, particularly concerning the transition to updated regulatory frameworks such as NIST SP 800-53 Rev 5.
- Standardize security procedures and compliance artifacts at an organizational scale to ensure consistency across all enclaves.
- Author justification language and remediation instructions to provide engineering teams with clear, actionable guidance.
Stakeholder & Relationship Management
- Build and cultivate strong professional relationships with ConMon owners to ensure alignment on security standards and evidence requirements.
- Act as a trusted advisor to stakeholders, proactively negotiating acceptable evidence formats that can be standardized across all organizational ConMon programs.
- Communicate compliance status and remediation expectations clearly to technical and non-technical stakeholders to ensure seamless operational continuity.
Qualifications
- Bachelor's degree in computer science, engineering, information assurance, or a related discipline and has at least 5 or more years of experience in an information technology role. Additional experience may be substituted for a degree.
- US Citizenship with an active Top Secret (TS) Clearance (Required).
- Currently DoD 8140 compliant or possessing the necessary certifications for immediate certification (Required).
- Extensive professional experience managing the full lifecycle of Continuous Monitoring (ConMon) programs and complex cybersecurity operations for enterprise systems.
- Subject matter expertise in eMass, including advanced system administration, package management, and reporting functions.
- Strong understanding of cloud security architecture and best practices.
- Proven ability to design and implement automated security solutions or scripts (e.g., Python, SQL) to modernize data collection, vulnerability parsing, and reporting workflows.
- Capability to institutionalize standardized security procedures and compliance artifacts at an organizational scale.
- Exceptional stakeholder management skills, with the ability to cultivate relationships with system owners, negotiate evidence requirements, and provide authoritative guidance.
- Strong analytical capability to translate complex vulnerability data into clear, actionable remediation plans for engineering teams.
- High level of operational rigor, with demonstrated success in managing audit-ready documentation and complex project lifecycles.
Pay
The annual salary range for this position is $135,000 - $155,000.
Benefits
- Generous paid time off
- Medical, dental, and vision insurance
- Tuition reimbursement
- 401k
Schedule
This position will be based at Tysons, VA.