About the role
The Senior Security Engineer is a hands-on technical role responsible for rendering security and protection work in structured, machine readable form. This encompasses the artifacts the discipline produces, the processes and procedures that govern how the work is performed, the analytic evaluations practitioners conduct, and the review and approval sequences those evaluations pass through.
Security and protection practices across the defense sector remain predominantly document based. The same information is recorded in multiple artifacts maintained by different organizations on different revision cycles, and the procedures, criteria, and decision logic surrounding those artifacts exist largely as narrative guidance or as undocumented practitioner knowledge. This role establishes the structured foundation that makes both the information and the work itself accessible and reusable across programs.
The security discipline in this position is applied rather than administrative. Modeling a security process correctly requires understanding how that process actually functions, including the Risk Management Framework, control selection and assessment, and systems security engineering practice. Candidates are expected to bring that fluency and apply it directly to the data model and to the processes being represented.
What You'll Work On
Development of the Data Model
- Conduct requirements sessions with practitioners and subject matter experts
- Review existing artifacts and tools to establish which information is authoritative and which is restated
- Construct formal schemas expressing the relevant data objects, attributes, and relationships
- Standardize terminology so that participating organizations interpret the model consistently
- Maintain versioning and change control as the model matures
Modeling of Processes and Evaluations
- Model the processes and procedures governing how security and protection work is performed, including sequence, roles, handoffs, and approval authority
- Represent the states an artifact or assessment moves through and the conditions governing transition between them
- Express the criteria, inputs, and decision logic underlying practitioner evaluations and analyses in structured, inspectable form
- Distinguish determinations suitable for structured representation from those requiring practitioner judgment, and preserve the latter as such
- Identify where existing procedures conflict, duplicate effort, or lack a defined authority, and raise those findings for resolution
Application of Security Engineering Knowledge
- Ensure the data model reflects how the Risk Management Framework, control selection, and assessment activities are actually executed
- Align structures with established security and systems engineering practice so that outputs are usable by the organizations that will consume them
- Advise on where structured data can reduce redundant effort across security, engineering, and authorization activities
- Evaluate proposed structures against governing policy and technical standards, and identify divergence early
- Represent security engineering considerations in technical discussions with government stakeholders and development teams
Adoption and Operational Use
- Develop reference documentation, guidance, and training material supporting adoption
- Define how work proceeds across the model in operational practice
- Assess sequencing, distinguishing capability achievable immediately from capability dependent on further model maturity
- Support development teams integrating against the schema and process definitions
What You'll Do
- Conduct interviews and working sessions with domain experts and translate the results into rigorous models
- Design, document, and version data structures that other development teams will build against
- Develop the queries, transformations, and validation logic required to maintain data integrity
- Translate policy, procedural guidance, and control language into defined technical requirements
- Produce reference documentation and training material sufficient to support adoption
- Present technical work to mixed audiences of engineers, program staff, and government stakeholders
What We're Looking For
Must Haves
- Bachelor's degree in a STEM or information systems discipline, or equivalent professional experience
- Minimum 8 years of security experience, including hands-on application of the Program Protection or Risk Management Framework process to operational or developmental systems
- Working knowledge of systems security engineering and its relationship to broader systems engineering practice
- Demonstrated success converting unstructured material, established procedures, or expert practice into structured, defensible representations
- Experience with Cyber Data Schema, OSCAL or other machine readable control and catalog formats
Nice to Have
- Prior experience as a System Security Engineer, Program Protection Practictioner, or Information System Security Manager on a DoW program
- Familiarity with process and decision modeling notations such as BPMN or DMN
- Familiarity with semantic modeling technologies (OWL, RDF, SHACL) or background in knowledge graphs and taxonomy design
- Experience with MBSE tooling or digital engineering environments
- Familiarity with Git workflows for version controlling
- Familiarity with DoW or Air Force acquisition and life cycle management policy