• Skip to primary navigation
  • Skip to main content
  • Skip to footer

Side Hustles

Side Hustles

Side Hustles For All

  • Best Side Hustles
    • Woman sitting on a pile of coins and working on a laptop surrounded by icons representing different side hustle ideas

      31 Best Side Hustles to Earn Extra Money in 2026

    • Bicycle courier delivering food for their side hustle.

      What Is a Side Hustle?

    • Remote worker sitting at his desk making money from home

      18 Ways to Make Money from Home (Online and Offline Jobs)

    • By Category
      • Arts & Crafts
      • Business Services
      • Caregiving
      • Creative Services
      • Digital Freelance Services
      • View All
    • By Lifestyle
      • I’m introverted
      • I’m a man
      • I’m a woman
      • I’m a stay-at-home mom
      • I’m unique
      • View All
    • By Profession
      • Artists & Creatives
      • Musicians
      • Nurses
      • Physicians
      • Teachers
      • View All
    • By Age Group
      • College Students
      • Teens
      • Age 50+
      • Seniors
      • View All
    • By Skills & Interests
      • Get Paid to Lose Weight
      • Get Paid to Play Games
      • Get Paid to Read
      • Get Paid to Sleep
      • Get Paid to Travel
      • View All
  • Best Gig Apps
    • Freelance worker popping out of a phone screen and considering gig apps on the App Store and Google Play

      Top 6 Gig Apps to Make Real Cash in 2026

    • Smartphone surrounded by the icons of different money-making apps

      Top 10 Best Money-Making Apps to Try in 2026

    • two teenagers using job apps on a phone and laptop

      19 Job Apps for Teens to Find Jobs and Make Money

    • By Gig Type
      • Cashback
      • Data Entry
      • Delivery
      • Games
      • Product Testing
      • View All
    • By Payment Method
      • Bingo Games that Pay to Cash App
      • Games that Pay Real Money
      • Games that Pay to Cash App
      • Games that Pay via PayPal
      • Surveys that Pay to Cash App
      • View All
    • By Benefits
      • $20 Signup Bonuses
      • $25 Signup Bonuses
      • $50 Signup Bonuses
      • Best Signup Bonuses
      • Instant Signup Bonuses
      • View All
    • By Skills & Interests
      • Driving
      • Losing Weight
      • Playing Games
      • Product Testing
      • Watching Ads
      • View All
  • Job Hunting
    • Freelance worker browsing a job post on a freelance job board.

      23 Job Boards You Can Use to Find Remote Work

    • Freelance writer sitting at her laptop working on a project

      15 Best Remote Jobs That Require No Paid Work Experience

    • Teenager sitting at laptop working an online job

      14 Online Jobs for Teens (With No Experience)

    • Freelancing
      • Freelance Writing Sites
      • Freelance Writing Job Boards
      • Freelance Writing Platforms
      • View More
    • Gig & Shift Work
      • Gig Work Apps
      • On-Demand Work Apps
      • Shift Work Apps
      • View More
    • GPT (Get Paid To)
      • Microtasking
      • Product Testing
      • Survey Taking
      • View More
    • Remote Working
      • Best Remote Job Boards
      • Top 15 Remote Jobs
      • View More
  • Job Board
    • Work Schedule
      • Part-Time Jobs
      • Per-Diem Jobs
      • Go Search
    • Work Environment
      • Hybrid Jobs
      • Remote Jobs
      • Go Search
    • Employment Type
      • Contractor Jobs
      • Internship Jobs
      • Temporary Jobs
      • Go Search
    • Job Title
      • Accounting Jobs
      • Data Entry Jobs
      • Nursing Jobs
      • Online Teaching Jobs
      • Software Engineer Jobs
      • Go Search
    • State
      • California Jobs
      • Florida Jobs
      • New York Jobs
      • Pennsylvania Jobs
      • Texas Jobs
      • Go Search
    • City
      • Chicago, IL
      • Houston, TX
      • Los Angeles, CA
      • New York City, NY
      • Phoenix, AZ
      • Go Search

Home Flexible Job Board SECURITY RISK ENGINEER (SRE)

Salary Unstated 157d ago

SECURITY RISK ENGINEER (SRE)

Boost your chances before you apply.

  • ✨ Apply 10x Faster Free

    It takes 30+ tailored applications to land jobs like this one. We'll help you get that done in 1 hour.

    No Credit Card Required

  • Proceed to Application Go directly to the company's job page to apply.
Logo

Zermount, Inc

Arlington, VA, US

Full-time Permanent Remote

✨ Apply 10x Faster

Analyze your resume for missing keywords, then one-click optimize it. Don't be anything less than a 100% match candidate.

Free

No Credit Card Required

Summary

The Security & Risk Engineer will conduct technical security assessments and risk analysis to ensure federal information systems comply with cybersecurity standards. They are responsible for validating security controls, identifying exploitable vulnerabilities, and producing objective findings to support mission assurance and risk-based decision-making.

Job Description

ZERMOUNT POSITION DESCRIPTION (PD) SECURITY & RISK ENGINEER (SRE)

POSITION OVERVIEW

Zermount Inc. is seeking a System Risk Engineer (SRE) to support system risk analysis and ensure that federal information systems comply with Information Assurance and cybersecurity standards. The SRE exists to ensure organizational systems are secure, resilient, and defensible in real-world operating conditions, not simply compliant with security documentation. This role directly contributes to mission assurance by identifying, validating, and reducing cybersecurity risk through direct technical assessment, control validation, and risk-based decision support across enterprise environments.

Operating at the intersection of security engineering, risk assessment, and compliance, the SRE transforms federal mandates (e.g., NIST RMF, FISMA, EO 14028, OMB directives) into measurable security outcomes by validating the effectiveness of security controls within live systems. The role requires continuous evaluation of system posture through hands-on analysis of architectures, configurations, logs, vulnerability data, and control implementations across cloud, network, operating system, application, and database layers.

This position demands foundational technical expertise across multiple domains, enabling the SRE to assess complex enterprise environments, identify exploitable conditions, and determine whether implemented security controls effectively reduce risk. The SRE is expected to go beyond documentation review and verify findings through system-level evidence, testing, and analysis, ensuring the findings reflect actual operational risk.

The SRE is a core enabler of Zermount's Modern GRC mindset, which emphasizes:

  • Continuous, real-time risk identification during compliance assessments
  • Risk prioritization based on exploitability, exposure, and mission impact
  • Direct integration with engineering and operations teams to drive remediation
  • Elimination of "check-the-box" compliance in favor of validated security outcomes

You will be directly responsible for supporting system authorization and mission assurance by producing objective, defensible, and technically accurate findings that enable Authorizing Officials, ISSOs, and system owners to make informed risk decisions. This includes conducting security control assessments, validating Zero Trust implementation, analyzing architectural and configuration changes, and ensuring that remediation actions are both effective and sustainable to reduce risk.

DUTIES & RESPONSIBILITIES

General Duties

  • Execute Security Assessments (SA), Risk Assessments (RA), and Ongoing Authorization (OA) activities by validating security controls in live environments, not solely through documentation review
  • Conduct technical verification and validation of security controls across operating systems, applications, databases, cloud platforms, and network infrastructure
  • Identify real-world security risks, including exploitable vulnerabilities, misconfigurations, weak trust boundaries, and control failures
  • Perform continuous risk analysis using outputs from vulnerability scans, penetration testing, logging platforms, and configuration assessments
  • Develop risk-based findings and POA&M matrices, prioritizing remediation based on exploitability, exposure, and mission impact
  • Produce executive-quality artifacts (SARs, risk memos, ATO packages, executive briefings) with validated, evidence-backed findings
  • Conduct impact analysis for Requests for Change (RFCs), identifying security implications of architectural, configuration, or system modifications
  • Validate Zero Trust implementation and alignment across system architectures and capabilities
  • Perform technical assessments of system architecture, data flows, and trust boundaries to identify control gaps
  • Conduct compliance validation for TIC, FISMA, and federal cybersecurity mandates through technical inspection and testing
  • Ensure all deliverables meet accuracy standards with zero rework required and are aligned to program and client expectations
  • Provide weekly status reporting and briefings with clear articulation of risks, risk mitigation progress, and technical findings

SUBJECT MATTER EXPERTISE (SME)

SME Area #1 - Primary Expertise: Security Assessment & Technical Risk Validation

Expert-level means:

  • Deep knowledge of:
    • NIST RMF (800-37, 800-53, etc.)
    • FISMA, EO 14028, OMB M-21-31 / M-22-09
    • FIPS 199/200
    • TIC, Zero Trust principles (CISA ZT MM, NIST 800-207, etc.)
  • Ability to independently conduct:
    • Security Control Assessments (SCA)
    • Risk Assessments (RA)
    • ATO/OA activities
  • Capability to validate controls using:
    • System configurations
    • Logs and telemetry
    • Vulnerability scanning outputs
    • Conducting system interviews and demos
  • Ability to identify real-world attack vectors and control failures, and develop actionable remediation actions that the system teams can use to successfully remediate findings

Required Tools Experience:

  • Vulnerability scanning tools such as: Tenable, Qualys, CrowdStrike, etc.
  • Log analysis platforms such as: Splunk, Microsoft Sentinel, IBM QRadar, etc.
  • Configuration and system inspection tools such as: Ansible, Terraform, Puppet, etc.
  • GRC platforms such as: Archer, ServiceNow, etc.

SME Area #2 - Secondary Expertise: Multi-Domain Technical Depth

You must have deep knowledge of one or more of the following technical domains and must demonstrate the ability to leverage this experience to inform and complete compliance-related tasks.

Technical Domains

  • Cloud: AWS/Azure (IAM, logging, network security, misconfigurations)
  • Network: Segmentation, firewalls, boundary protections, Zero Trust enforcement points
  • Systems: Windows/Linux hardening, identity systems (AD, MFA)
  • Databases/Data: Access control, encryption, auditing

QUALIFICATIONS

Minimum Requirements

  • 7+ years of cybersecurity experience supporting U.S. Government systems
  • 4+ years performing RMF, ISSO, Assessment, or GRC functions with direct technical validation responsibilities
  • Demonstrated hands-on experience in at least two technical domains (cloud, network, systems, or databases)
  • Proven ability to analyze:
    • System configurations, ATOs, and other supporting security documentation
    • Logs/telemetry
    • Architecture documentation and data flow diagrams
  • Proven ability to conduct technical assessments across multiple domains

Preferred Qualifications

  • Experience with Zero Trust assessments and implementation validation
  • Experience with CDM, ISCM, and enterprise logging programs
  • Experience supporting DHS/FISMA environments
  • Familiarity with threat-informed defense and attack vector analysis

Competency

  • Advanced technical risk analysis and prioritization
  • Independent problem-solving in ambiguous environments
  • Strong collaboration with system teams, federal leads
  • Ability to translate complex technical findings into actionable recommendations
  • Clear communication with both engineers and leadership

Education & Certifications

  • Bachelor of Science (B.S.) in Computer Science, IT, Cybersecurity, or a related field, and a minimum of 7 years of IT cybersecurity experience, including direct support for the US Government and 4 years acting as an ISSO, Assessor, Compliance, RMF, or GRC with a technical validation role.
  • Without a B.S. in a relevant field - A minimum of 13 years of IT Cybersecurity experience, including direct support for the US Government, and 4 years acting as an ISSO, Assessor, Compliance, RMF, or GRC with a technical validation role.
  • At least one of the following security certifications is required:
    • Certified Authorization Professional (CAP)
    • Certified Information Security Auditor (CISA)
    • Certified Information Security Manager (CISM)
    • Certified Information Systems Security Professional (CISSP), or Certified Chief Information Security Officer (CCISO)
    • Governance Risk & Compliance Certification (CGRC)
    • Or alternatively approved certifications

Clearance Level

Minimum of active Secret Clearance and ability to obtain and maintain DHS suitability

WORK LOCATION

  • The position is primarily remote - Continental U.S only
  • Primary location when on site: Arlington, VA, and Springfield, VA
  • Must be willing to travel - Not to exceed 10% of the time

HOURS OF OPERATION

  • 8:00 am EST - 4:30 pm EST
    • Times may fluctuate based on client and business requirements

REPORTING STRUCTURE

  • Reports To: Security Risk Engineering Team Lead
  • Direct Reports: N/A

About the company

Zermount, Inc

Zermount, Inc., a Certified SDVOSB, was founded by Terry Butler a proven leader and Cybersecurity/Information Technology (IT) professional with over15 years’ experience supporting the Federal Government and commercial clients. Zermount provides client focused professional and consulting services in the discipline areas of Cybersecurity/Information Assurance, Information Technology (IT), and management and leadership to both government and commercial market spaces.

Zermount is dedicated to forming partnerships with our clients in order to assist them with supporting their customers, while protecting them against adversaries. Zermount is committed to providing cutting edge solutions and strategies with the right mix of professionals who are forward thinking and focused on client needs.

Our solutions and strategies are innovative designs for future growth and sustainably and not a point in time stop gap. We focus on the future and assisting clients in becoming leaders in their respective space, increasing their efficiencies and effectiveness while decreasing cost and being on the cutting edge of innovation and technology. Our services are based on proven methodologies, reliable practices, exceptional task execution, company wide business acumen and exceptional leadership

Company size

51-200 employees

Industry

Computer and Network Security

Org type

Privately Held

Headquarters

Arlington, Virginia

Apply Now

About the company

Zermount, Inc

Zermount, Inc., a Certified SDVOSB, was founded by Terry Butler a proven leader and Cybersecurity/Information Technology (IT) professional with over15 years’ experience supporting the Federal Government and commercial clients. Zermount provides client focused professional and consulting services in the discipline areas of Cybersecurity/Information Assurance, Information Technology (IT), and management and leadership to both government and commercial market spaces.

Zermount is dedicated to forming partnerships with our clients in order to assist them with supporting their customers, while protecting them against adversaries. Zermount is committed to providing cutting edge solutions and strategies with the right mix of professionals who are forward thinking and focused on client needs.

Our solutions and strategies are innovative designs for future growth and sustainably and not a point in time stop gap. We focus on the future and assisting clients in becoming leaders in their respective space, increasing their efficiencies and effectiveness while decreasing cost and being on the cutting edge of innovation and technology. Our services are based on proven methodologies, reliable practices, exceptional task execution, company wide business acumen and exceptional leadership

Company size

51-200 employees

Industry

Computer and Network Security

Org type

Privately Held

Headquarters

Arlington, Virginia

Footer

sidehustles.com
Facebook Twitter Instagram LinkedIn Reddit TikTok YouTube

Show Me The Money

  • Side Hustle Basics
  • Side Hustle Job Board (Remote & Part-Time Jobs)
  • Gig App Reviews
  • Job Hunting
  • Manage Your Money
  • The Gig Apple: News & Events

Company

  • About Us
  • Contact Us
  • Become a Contributor
  • Advertising & Sponsorships
  • Partner With Us
  • Editorial Guidelines

Side Hustles © All rights reserved

  • Privacy Policy
  • Terms of Service

Thanks for using our free job board

Your review would mean a lot to us.

If you love that we're just giving away remote jobs for free with no paywall, please spread the word. (You will need to create an account on Trustpilot, for which we'll be eternally grateful.) Good luck out there!

Leave a Review Not yet. Send me to the job post.