Security Engineer
7 days ago
Atlanta
Job Description POSITION SUMMARY Reporting to the VP of IT, Security, and Compliance, the Security Engineer is a hybrid technical and governance role responsible for designing, implementing, and scaling the organization’s governance, risk, and compliance (GRC) program. This role combines hands-on security engineering with strategic compliance program development, directly supporting Coreforce’s ability to meet rigorous regulatory requirements across frameworks including GovRAMP, SOC 2, CJIS, ISO 27001, and NIST SP 800-53. The Security Engineer will lead the automation of compliance workflows, build and maintain continuous control monitoring capabilities, conduct risk assessments leveraging advanced analytics and AI-driven insights, and serve as a trusted advisor to engineering, operations, and leadership teams on risk trends and mitigation strategies. This role partners closely with auditors, regulators, and business stakeholders to define and implement security requirements and controls that enable organizational growth while maintaining the highest security standards for government and law enforcement clients. 2 Main Functions: (A) Security Engineering & Compliance Operations, i.e. implementing and maintaining security controls, automating evidence gathering and continuous control testing, managing compliance monitoring and alerting systems, conducting security compliance reviews for new products, features, and vendors, and maintaining the organization’s security posture across AWS GovCloud and Microsoft 365 environments. (B) GRC Strategy & Risk Management, i.e. leading the development and maturity of GRC strategies aligned with GovRAMP, SOC 2, CJIS, ISO 27001, and NIST SP 800-53 requirements. This includes designing and executing risk assessment processes leveraging AI and advanced analytics for predictive risk modeling, maintaining corporate security policies mapped to relevant frameworks, generating security program KPIs, supporting customer security diligence, and driving company-wide security awareness and training programs. Working Conditions: Regular office/hybrid environment. ESSENTIAL DUTIES AND RESPONSIBILITIES · Design, implement, and continuously improve the GRC program across multiple compliance frameworks (GovRAMP, SOC 2, CJIS, ISO 27001, NIST SP 800-53). · Automate evidence gathering, continuous control testing, and compliance monitoring workflows to reduce manual effort and improve audit readiness. · Conduct enterprise-wide and targeted risk assessments to identify emerging risks, control gaps, and quantify risk exposure using advanced data analytics. · Develop dashboards, automated alerts, and reporting for security program KPIs and high-risk indicators. · Leverage AI and machine learning tools for predictive analytics, anomaly detection, and scenario modeling within the risk management framework. · Partner with auditors, regulators, and business stakeholders to define and implement security requirements and controls. · Conduct security compliance reviews for new products, features, vendors, and third-party integrations. · Maintain corporate security policies and map them to relevant compliance frameworks. · Support go-to-market teams by providing scalable processes to address customer security diligence requirements. · Draft security best practices documentation and drive company-wide security awareness and training programs. · Collaborate cross-functionally with engineering, IT, and operations teams to embed security and compliance practices across the organization. · Continuously evaluate and champion the adoption of emerging technologies and AI-driven tools to enhance GRC program maturity. · Manage and maintain the organization’s GRC platform for documenting risks, controls, assessments, and remediation tracking. · Serve as a trusted advisor to leadership on risk trends, mitigation strategies, and compliance posture. MINIMUM QUALIFICATIONS (EXPERIENCE AND EDUCATION) · Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, Computer Science, or related field; Master’s degree preferred. · 5+ years of experience in cybersecurity, GRC, risk management, or related fields with demonstrated exposure to compliance automation and security engineering. · Hands-on experience with GRC frameworks including SOC 2, ISO 27001, NIST SP 800-53, FedRAMP/GovRAMP, and CJIS. · Technical proficiency with cloud security in AWS and Microsoft Azure/M365 environments, preferably GovCloud and GCC High. · Experience with GRC platforms, compliance automation tools, and security monitoring solutions (e.g., Wiz, Vanta, Drata, or similar). · Familiarity with AI/ML platforms, predictive modeling, and data visualization tools as applied to risk assessment. · Excellent communication skills with the ability to translate complex technical and compliance requirements into actionable business insights. MINIMUM KNOWLEDGE, SKILLS, AND ABILITIES · Deep understanding of governance, risk, and compliance principles and their application in regulated government and law enforcement environments. · Strong analytical and problem-solving skills to identify control gaps, quantify risk, and develop remediation strategies. · Ability to design and implement automated compliance workflows integrated with engineering systems and CI/CD pipelines. · Working knowledge of cloud infrastructure security, identity and access management, and network architecture principles. · Strong cross-functional collaboration skills, especially with engineering, audit, legal, and go-to-market teams. · Ability to balance technical implementation with strategic program development and stakeholder communication. · Self-directed with the ability to manage multiple concurrent compliance initiatives and deadlines. · Innovative mindset with a drive to continuously improve processes through automation and emerging technologies. RECOMMENDED CERTIFICATIONS CompTIA Security+, Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), ISO 27001 Lead Implementer or Lead Auditor Preferred: Certified Information Systems Security Professional (CISSP), Certified Cloud Security Professional (CCSP), AWS Certified Security Specialty, Certified Analytics Professional (CAP) or equivalent AI/analytics certification Physical Demands and Work Environment This role requires the employee to maintain a stationary and upright position consistently. Employees must be able to move frequently within an office environment to utilize office machinery and other resources. The employee should be able to communicate information and concepts consistently and effectively for mutual understanding, including conveying precise details during these interactions. For accurate task execution, it is essential that the employee consistently maintains consistent specific vision abilities, especially the capability to discern close-up details within a few feet of the observer. Seldom does this role entail the transportation of items weighing up to 15 pounds to meet various demands. NOTE This job description in no way states or implies that these are the only duties to be performed by the employee(s) incumbent in this position. Employees will be required to follow any other job-related instructions and to perform any other job-related duties requested by any person authorized to give instructions or assignments. All duties and responsibilities are essential functions and requirements and are subject to possible modification to reasonably accommodate individuals with disabilities. To perform this job successfully, the incumbents will possess the skills, aptitudes, and abilities to perform each duty proficiently. Some requirements may exclude individuals who pose a direct threat or significant risk to the health or safety of themselves or others. The requirements listed in this document are the minimum levels of knowledge, skills, or abilities. This document does not create an employment contract, implied or otherwise, other than an “at-will” relationship. The companies in the Coreforce organization are innovative technology leaders, delivering groundbreaking digital systems tailored for frontline professionals who rely on speed, accuracy, easy-to-access data, and transparency in their work. Coreforce is an equal-opportunity employer that promotes justice, advances equity, values of diversity, and fosters inclusion. Coreforce is committed to hiring the best talent — regardless of race, creed, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship status, marital status, disability, gender identity, genetic information, veteran status, or any other characteristic protected by applicable laws, regulations, and ordinances. If you have a disability or special need that requires assistance or accommodation, please email