DS
Sr. Security Engineer
Datum Software, Inc
- 🇺🇸 United States
- On-site
- Senior
- 4 hours ago
- Regulatory Compliance
- FedRAMP
- PCI DSS
- Risk Management
- Incident Response
- Disaster Recovery
- AI
- CISSP
- CISA
- CRISC
4 hours ago
Contract/ Contract to Hire
Atlanta, GA
Job Overview:
We are seeking an experienced Senior Information Security Compliance Engineer to support the organization's government compliance program, ensuring adherence to applicable U.S. and international regulatory requirements and alignment with mandated cybersecurity and IT compliance frameworks.
The ideal candidate will have a strong background in Information Security, IT Auditing, Governance, Risk & Compliance (GRC), security controls, and regulatory compliance.
This position is also responsible for supporting broader Information Security Compliance initiatives, including third-party risk assessments, audit readiness, regulatory research, policy development, security assessments, and special projects driven by evolving cybersecurity and compliance requirements.
Key Responsibilities:
Information Security Governance & Compliance
- Support and maintain the organization's government compliance program in accordance with applicable regulatory requirements.
- Ensure alignment with security frameworks, including NIST SP 800-171, NIST SP 800-53, ISO/IEC 27001/27002, FedRAMP, PCI DSS, and CIS Critical Security Controls.
- Define, implement, review, and maintain corporate information security policies, procedures, and standards.
- Research and interpret new regulatory requirements and provide clear, actionable recommendations to senior leadership.
- Develop and maintain documentation supporting compliance, operational consistency, and audit readiness.
- Identify compliance gaps and recommend appropriate corrective actions.
- Support third-party risk management activities, including reviewing and responding to security questionnaires.
- Evaluate emerging technologies and regulatory changes that may affect the organization's security and compliance posture.
- Conduct IT security audits, risk assessments, vulnerability assessments, and compliance reviews.
- Collect, review, and validate audit evidence to demonstrate compliance with regulatory and industry standards.
- Assess the effectiveness of existing security controls and recommend improvements.
- Identify security vulnerabilities and implement appropriate risk mitigation strategies.
- Develop and maintain security control frameworks and access management procedures.
- Support internal and external audits and regulatory assessments.
- Assist with the development and maintenance of System Security Plans (SSPs).
- Collaborate with stakeholders to address audit findings and track remediation activities.
- Support the design, implementation, testing, and maintenance of information security systems and controls.
- Configure, evaluate, and maintain security solutions, including firewalls, intrusion detection systems, encryption technologies, and access controls.
- Collaborate with technical teams to investigate security incidents, conduct forensic analysis, and coordinate incident response activities.
- Assist with data recovery and remediation following security incidents.
- Develop automation scripts and processes to improve security monitoring and incident tracking.
- Evaluate authentication, authorization, and encryption solutions.
- Support security testing and assessment activities throughout the project lifecycle.
- Design and recommend monitoring solutions to detect vulnerabilities and security threats.
- Establish and maintain security standards, policies, and procedures for systems, networks, facilities, and data protection.
- Support backup procedures, source code protection, and disaster recovery planning.
- Develop, test, and maintain network and IT disaster recovery plans.
- Assess data sensitivity and recommend appropriate security controls.
- Coordinate with IT, facilities, and business teams to strengthen physical and logical security.
- Provide security awareness training and guidance to employees and technical staff.
- Recommend cost-effective security enhancements, technologies, and solutions.
- Monitor changes in software, hardware, infrastructure, and business requirements to identify potential security risks.
- Communicate security incidents, regulatory concerns, and compliance findings to technical teams, management, and other stakeholders.
- Demonstrated experience in Information Technology auditing, including identifying, evaluating, and validating control evidence to demonstrate regulatory and industry compliance.
- Strong knowledge of NIST SP 800-171 or comparable security control frameworks, such as:
- NIST SP 800-53
- NIST Cybersecurity Framework (CSF)
- ISO/IEC 27001/27002
- FedRAMP
- PCI DSS
- CIS Critical Security Controls
- Previous experience working in a Governance, Risk & Compliance (GRC) function or a comparable information security compliance role.
- Ability to research, interpret, and apply government regulations and cybersecurity compliance requirements.
- Experience drafting, reviewing, and maintaining security policies, standards, and procedures.
- Strong understanding of security controls, control implementation, and compliance monitoring.
- Experience collecting, reviewing, and interpreting evidence and artifacts for internal and external audits.
- Solid knowledge of IT environments, including information security, network architecture, and cloud computing.
- Ability to identify security risks, assess compliance gaps, and recommend corrective actions.
- Excellent written and verbal communication skills, including the ability to present findings and recommendations to senior leadership.
- Strong analytical, organizational, and problem-solving skills.
- Ability to work independently, manage priorities, and deliver actionable results.
- Demonstrated interest in learning and applying government compliance standards.
- Previous experience with U.S. Government IT compliance requirements.
- Experience developing and maintaining System Security Plans (SSPs).
- Strong project management skills with the ability to coordinate activities across multiple functional teams.
- Foundational knowledge of artificial intelligence (AI) tools and emerging technologies, including:
- Evaluating AI applications for productivity and process automation.
- Identifying cybersecurity risks and potential misuse associated with AI technologies.
- Assessing the impact of AI adoption on organizational security and regulatory compliance.
- Previous experience working in the aviation industry.
One or more of the following professional certifications is highly desirable:
- CISSP – Certified Information Systems Security Professional
- CISA – Certified Information Systems Auditor
- CRISC – Certified in Risk and Information Systems Control
Work Environment
- The position is based at the *** Atlanta office.
- A hybrid work schedule may be available following the initial onboarding period, depending on business needs and individual performance.
- Hybrid arrangements are subject to management approval and may be adjusted at the manager's discretion.
- Additional onsite attendance may be required during audits, assessments, regulatory reviews, and other business-critical activities.
Recruitment Focus: The primary emphasis of this position is government cybersecurity compliance, IT auditing, GRC, and regulatory security controls. Security engineering and incident response responsibilities support the broader compliance function.
“All qualified applicants will be considered without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.”
Sr. Security Engineer · Datum Software, Inc