Security Engineer

Rockville, MD
Full-Time

Job Description

We are Skyward.   That is, a love for people, for improvement, for human advancement through information technology. We are a people-centered business with a desire to serve others. We are diverse and unified; creative and collaborative; a collection of complementary, not competing talents. And though on the surface we remain relaxed, beneath, a torrent of energy links us to our civic tech mission.   We stand by our values, and we won’t compromise on any of them.   Integrity: We’re conscientious, intentional, and empathetic. Our words and actions align. That’s our character. Please don’t ask us to play another part, we’re poor actors.    Compassionate: If we may borrow a quote from Theodore Roosevelt: “No one cares how much you know until they know how much you care.” Because our team is thoughtful and supportive, caring deeply for each other, our clients, and our work, this comes naturally.  Inquisitive: We remain students by failing openly and turning lessons into solutions. Unconventional: For us, life isn’t what happens outside of work. Work happens inside of life and our culture erases the line often dividing the two.    Authentic: Made possible only because we embody the values listed above. We’re relaxed and fun yet intensely curious and driven. Team members are placed with thought, care, and precision to ensure that Trust, Truth, and Transparency continue to represent our brand.   Because of that, we continue Onward, Upward, and Skyward.

We need a Security Engineer.

Do your friends treat you as the go-to for their security questions, and do you get a little satisfaction from finding the vulnerability everyone else missed? Are you happiest with your hands on the tools, automating scans, hardening pipelines, and turning a wall of findings into a prioritized plan of attack? If you’d like to put your technical skills and security instincts to work protecting systems that matter, then stop thinking about it and apply!

Come join us if you're motivated to learn from others, to learn from mistakes, to be part of a future-looking and growth-oriented team.

Let's go Skyward together.

What you'll do:

  • Join the team supporting the Centers for Medicare & Medicaid Services (CMS) as it merges and modernizes its enterprise knowledge and data systems into a single, AI-driven platform, reducing manual effort, improving data accuracy, and enhancing transparency for stakeholders.
  • Find and prioritize what matters. Run vulnerability and security scans, then build a clear, prioritized list of weaknesses based on severity, known exploitation, and exploitation probability using intelligence sources like the CISA KEV catalog and EPSS.
  • Automate security into the pipeline. Embed security tooling such as Snyk, Trufflehog/GitLeaks, Tenable, and AWS Inspector into CI/CD so vulnerabilities are caught and reported before they ship.
  • Modernize compliance, hands-on. Help drive the move toward Continuous ATO (cATO) and near-real-time compliance monitoring using AWS Security Hub, Config, and Audit Manager, plus the CMS GRC system of record (CFACTS).
  • Build and feed continuous monitoring. Implement monitoring of production runtime environments for vulnerabilities and compliance drift, and make security and compliance reporting available on demand.
  • Track and close the gaps. Document vulnerabilities, misconfigurations, and compliance deviations, and support POA&M creation and remediation tracking to keep system ATOs healthy.
  • Keep us aligned to the standards. Support compliance with CMS and federal requirements such as NIST RMF, ARS, and IS2P2 within a FISMA Moderate boundary.
  • Harden access. Help implement least-privilege, role-based access controls aligned to Zero Trust objectives and support regular access reviews and audits.
  • Raise the flag early. Identify, document, and communicate security risks tied to modernization efforts so they get to the right stakeholders before they become problems.

What we'd like you to have:

  • A bachelor’s degree in computer science, information systems, cybersecurity, or a related field.
  • 3–5 years of experience in security engineering, cybersecurity, or a related role.
  • Hands-on experience with vulnerability scanning and management tools (e.g., Tenable, AWS Inspector, Snyk, Trufflehog, or GitLeaks).
  • Working knowledge of AWS security and compliance services (Security Hub, Config, Audit Manager) or comparable cloud-native tooling.
  • Familiarity with security compliance and the Authority to Operate (ATO) process, including POA&Ms and continuous monitoring.
  • Understanding of federal security frameworks such as NIST RMF, ARS, or IS2P2 (or a strong willingness to learn them quickly).
  • Comfort scripting and automating in Python or Bash and integrating tooling into CI/CD pipelines.
  • Solid problem-solving skills and the ability to collaborate across multiple stakeholders.

What would blow us away:

  • Previous experience supporting CMS.
  • Experience securing AI, NLP, or LLM-driven systems and the data behind them.

Even if you don’t meet 100% of the qualifications, we encourage you to apply. At Skyward, we’re focused on hiring individuals with the right skills and passion to grow, not just checking off every box.

And now the important part. What we offer you:

  • Medical, dental, vision insurance (fully paid for employees)
  • 15 days of paid leave
  • 7 days of sick leave
  • 2 days bereavement leave
  • 11 paid Federal holidays
  • Up to 40 hours for jury duty
  • 401K with 4% employer contribution (and no vesting period)
  • Up to 4 weeks of paid paternity and maternity leave
  • Company provided laptop
  • $5,000 per year for professional development
  • $600 per year for technical supplies and equipment
  • $2,000 referral bonus
  • Life and disability insurance
  • HSA and FSA
  • Legal Shield and ID Shield Voluntary Benefits
  • Opportunity to work in a collaborative, motivated team focused on modernizing government services with cutting-edge technology and innovative solutions. Who says government work can't be exciting!

We believe great work deserves great pay. That’s why we ensure our compensation is not only competitive but also fair and transparent, as required by Maryland law. Expect a salary that matches your skills, experience, and the value you bring to the table — because you’re worth it!

At Skyward, we support flexible working hours and remote opportunities to help maintain a healthy work-life balance for all employees.   Offers of employment with Skyward are contingent upon acceptable results of a background investigation. Applicants must have the ability to obtain and maintain a Public Trust security clearance due to the nature of our work as a government contractor.

VEVRAA Federal Contractor.
We request Priority Protected Veteran & Disabled Referrals for all of our locations within the state.

PDN-a20a9ff1-ab50-479f-ad6e-24df9e22d44a
We are Skyward.   That is, a love for people, for improvement, for human advancement through information technology. We are a people-centered business with a desire to serve others. We are diverse and unified; creative and collaborative; a collection of complementary, not competing talents. And though on the surface we remain relaxed, beneath, a torrent of energy links us to our civic tech mission.   We stand by our values, and we won’t compromise on any of them.   Integrity: We’re conscientious, intentional, and empathetic. Our words and actions align. That’s our character. Please don’t ask us to play another part, we’re poor actors.    Compassionate: If we may borrow a quote from Theodore Roosevelt: “No one cares how much you know until they know how much you care.” Because our team is thoughtful and supportive, caring deeply for each other, our clients, and our work, this comes naturally.  Inquisitive: We remain students by failing openly and turning lessons into solutions. Unconventional: For us, life isn’t what happens outside of work. Work happens inside of life and our culture erases the line often dividing the two.    Authentic: Made possible only because we embody the values listed above. We’re relaxed and fun yet intensely curious and driven. Team members are placed with thought, care, and precision to ensure that Trust, Truth, and Transparency continue to represent our brand.   Because of that, we continue Onward, Upward, and Skyward.

We need a Security Engineer.

Do your friends treat you as the go-to for their security questions, and do you get a little satisfaction from finding the vulnerability everyone else missed? Are you happiest with your hands on the tools, automating scans, hardening pipelines, and turning a wall of findings into a prioritized plan of attack? If you’d like to put your technical skills and security instincts to work protecting systems that matter, then stop thinking about it and apply!

Come join us if you're motivated to learn from others, to learn from mistakes, to be part of a future-looking and growth-oriented team.

Let's go Skyward together.

What you'll do:

  • Join the team supporting the Centers for Medicare & Medicaid Services (CMS) as it merges and modernizes its enterprise knowledge and data systems into a single, AI-driven platform, reducing manual effort, improving data accuracy, and enhancing transparency for stakeholders.
  • Find and prioritize what matters. Run vulnerability and security scans, then build a clear, prioritized list of weaknesses based on severity, known exploitation, and exploitation probability using intelligence sources like the CISA KEV catalog and EPSS.
  • Automate security into the pipeline. Embed security tooling such as Snyk, Trufflehog/GitLeaks, Tenable, and AWS Inspector into CI/CD so vulnerabilities are caught and reported before they ship.
  • Modernize compliance, hands-on. Help drive the move toward Continuous ATO (cATO) and near-real-time compliance monitoring using AWS Security Hub, Config, and Audit Manager, plus the CMS GRC system of record (CFACTS).
  • Build and feed continuous monitoring. Implement monitoring of production runtime environments for vulnerabilities and compliance drift, and make security and compliance reporting available on demand.
  • Track and close the gaps. Document vulnerabilities, misconfigurations, and compliance deviations, and support POA&M creation and remediation tracking to keep system ATOs healthy.
  • Keep us aligned to the standards. Support compliance with CMS and federal requirements such as NIST RMF, ARS, and IS2P2 within a FISMA Moderate boundary.
  • Harden access. Help implement least-privilege, role-based access controls aligned to Zero Trust objectives and support regular access reviews and audits.
  • Raise the flag early. Identify, document, and communicate security risks tied to modernization efforts so they get to the right stakeholders before they become problems.

What we'd like you to have:

  • A bachelor’s degree in computer science, information systems, cybersecurity, or a related field.
  • 3–5 years of experience in security engineering, cybersecurity, or a related role.
  • Hands-on experience with vulnerability scanning and management tools (e.g., Tenable, AWS Inspector, Snyk, Trufflehog, or GitLeaks).
  • Working knowledge of AWS security and compliance services (Security Hub, Config, Audit Manager) or comparable cloud-native tooling.
  • Familiarity with security compliance and the Authority to Operate (ATO) process, including POA&Ms and continuous monitoring.
  • Understanding of federal security frameworks such as NIST RMF, ARS, or IS2P2 (or a strong willingness to learn them quickly).
  • Comfort scripting and automating in Python or Bash and integrating tooling into CI/CD pipelines.
  • Solid problem-solving skills and the ability to collaborate across multiple stakeholders.

What would blow us away:

  • Previous experience supporting CMS.
  • Experience securing AI, NLP, or LLM-driven systems and the data behind them.

Even if you don’t meet 100% of the qualifications, we encourage you to apply. At Skyward, we’re focused on hiring individuals with the right skills and passion to grow, not just checking off every box.

And now the important part. What we offer you:

  • Medical, dental, vision insurance (fully paid for employees)
  • 15 days of paid leave
  • 7 days of sick leave
  • 2 days bereavement leave
  • 11 paid Federal holidays
  • Up to 40 hours for jury duty
  • 401K with 4% employer contribution (and no vesting period)
  • Up to 4 weeks of paid paternity and maternity leave
  • Company provided laptop
  • $5,000 per year for professional development
  • $600 per year for technical supplies and equipment
  • $2,000 referral bonus
  • Life and disability insurance
  • HSA and FSA
  • Legal Shield and ID Shield Voluntary Benefits
  • Opportunity to work in a collaborative, motivated team focused on modernizing government services with cutting-edge technology and innovative solutions. Who says government work can't be exciting!

We believe great work deserves great pay. That’s why we ensure our compensation is not only competitive but also fair and transparent, as required by Maryland law. Expect a salary that matches your skills, experience, and the value you bring to the table — because you’re worth it!

At Skyward, we support flexible working hours and remote opportunities to help maintain a healthy work-life balance for all employees.   Offers of employment with Skyward are contingent upon acceptable results of a background investigation. Applicants must have the ability to obtain and maintain a Public Trust security clearance due to the nature of our work as a government contractor.

VEVRAA Federal Contractor.
We request Priority Protected Veteran & Disabled Referrals for all of our locations within the state.

PDN-a20a9ff1-ab50-479f-ad6e-24df9e22d44a

About Skyward IT Solutions

We are Skyward.

That is, a love for people, for improvement, for human advancement through information technology. We are a people-centered business with a desire to serve others. We are diverse and unified; creative and collaborative; a collection of complementary, not competing talents. And though on the surface we remain relaxed, beneath, a torrent of energy links us to our civic tech mission.

Integrity: We’re conscientious, intentional, and empathetic. Our words and actions align. That’s our character. Please don’t ask us to play another part, we’re poor actors.

Compassionate: If we may borrow a quote from Theodore Roosevelt: “No one cares how much you know until they know how much you care.” Because our team is thoughtful and supportive, caring deeply for each other, our clients, and our work, this comes naturally.

Inquisitive: We remain students by failing openly and turning lessons into solutions.

Unconventional: For us, life isn’t what happens outside of work. Work happens inside of life and our culture erases the line often dividing the two.

Authentic: Made possible only because we embody the values listed above. We’re relaxed and fun yet intensely curious and driven. Team members are placed with thought, care, and precision to ensure that Trust, Truth, and Transparency continue to represent our brand. Because of that, we continue Onward, Upward, and Skyward.

Perfecting GovTech. Upgrading the public experience.

Related Jobs

Continue to Apply

Skyward IT Solutions would like you to finish the application on their website.

Apply For This Job
Skyward IT Solutions
Security Engineer
Skyward IT Solutions
Rockville, MD
Jun 17, 2026
$120,000 - $160,000 a year
Full-time
Your Information
First Name *
Last Name *
Email Address *
This email belongs to another account. Please use a diferent email address or Sign In.
Zip Code *
Password *
Confirm Password *
Create your Profile from your Resume
By clicking the Apply button, you agree to the terms of use and privacy policy and consent to receive emails from us about job opportunities, career resources, and other relevant updates. You can unsubscribe at any time.
Continue to Apply

Skyward IT Solutions would like you to finish the application on their website.

©2026 Alpha Phi Alpha Fraternity, Inc.
Powered by TalentAlly.