Information Security Sr. Principal (Azure Security Senior Engineer)
Skills
About the role
Clearance Level
Secret
Category
Cyber and IT Risk Management
Location
Washington, District of Columbia
(Hybrid Workplace)
Key Skills For Success
Microsoft Azure
Plan of Action and Milestones (POA&M)
Security Vulnerability Assessments
REQ#: RQ226806
Public Trust: None
Requisition Type: Pipeline
Your Impact
Own your opportunity to work alongside federal civilian agencies. Make an impact by providing services that help the government ensure the well being and support of U.S. citizens.
Job Description
Information Security Analyst Duties and Responsibilities:
Your Impact
Join a team supporting federal civilian agencies and contribute to protecting and enabling mission‑critical systems that serve U.S. citizens.
Information System Security Officer – Duties & Responsibilities:
Support government personnel in authorizing secure networks/applications in Azure Government Secret environments
Develop and submit A&A packages in eMASS
Configure and manage security controls, auditing, logging, vulnerability management, and CONMON activities across Microsoft Defender, Key Vault, Azure Policy, and other Azure security services
Provide guidance for SIEM/SOAR integrations (e.g., Microsoft Sentinel IL6) for monitoring, logging, and incident response
Support engineering teams in implementing remediations aligned with NIST 800‑53, DoD STIGs/SRGs, and CIS Benchmarks
Collaborate with mission owners, compliance teams, and developers to ensure secure DevSecOps pipelines
Support ATO processes by developing security documentation, gathering control evidence, and assisting with audits
Navigate federal systems through the authorization process to achieve and maintain ATO
Work closely with Program and DOC ITD IA teams to maintain required security authorizations
Develop System Security Plans (SSPs) documenting implementation of NIST 800‑53 Rev 5 and overlay controls
Coordinate with third‑party assessors for security assessments
Manage POA&Ms to address identified vulnerabilities
Ensure continuous monitoring plans meet agency requirements
Prepare authorization packages for government review
Maintain compliance through established change‑management processes
Serve as liaison between technical teams and authorizing officials
Translate security requirements into actionable technical tasks
Ensure all documentation meets federal information system requirements
Key Skills for Success
Microsoft Azure Security Stack (Sentinel, Defender, Auditing)
RMF for classified systems/applications
Plan of Action & Milestones (POA&M) management
Experience with GRC tools (CSAM, eMASS)
Requirements & Qualifications:
Bachelor’s degree in Information Systems Security, IT, or Networking
Active Secret clearance
5+ years of cloud security experience, including 2+ years in Azure Government or DoD environments
Strong knowledge of Azure-native security tools, IL6 data-handling, cloud networking, and architectural validation
Experience with DoD SRG/STIG/CIS Benchmarks
Hands-on experience with classified enclaves, hardened images, and enclave-to-enclave connectivity
Deep experience with auditing, logging, vulnerability management, and secure configuration management
Strong communication skills; customer-facing experience
Knowledge of Agile software development
Secret clearance required for start
Required Technical Skills:
SCAP, STIGs, patching, eMASS, and related RMF tools
Cybersecurity and A&A package development
Experience obtaining ATOs and navigating the assessment/authorization process
Experience across cybersecurity, information security, and IT security protocols and procedures
Experience:
5 years of relevant experience (may vary based on training, certifications, or degree)
Cloud security experience (Azure Government) and SIPRNet exposure
Experience with internet, web, application, and network security techniques
Experience working in federal environments
Ability to work independently and remotely
Certification Requirements:
Active DoW 8570 IAT Level II/III (Security+, CISSP, CISM)
Additional Details:
Travel: Up to 10% (may vary based on customer needs)
Location: Onsite at least 3 days per week; must reside in the DMV area
Citizenship: U.S. Citizenship required
Work Requirements
Years of Experience
10 + years of related experience
may vary based on technical training, certification(s), or degree
Certification
Travel Required
Less than 10%
Citizenship
U.S. Citizenship Required
Salary and Benefit Information
The likely salary range for this position is $148,750 - $201,250. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
Our Identity Verification Process
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.
About Our Work
We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.
Join our Talent Community to stay up to date on our career opportunities and events at gdit.com/tc.
Compensation
This Security Engineer role pays $149k-$201k/yr. Within typical range for security engineer roles in United States.
Questions about this role
Want AI Applyd to auto-apply to roles like this?
We tailor your resume per posting, fill the forms, and track replies for you.