Security Tools Engineer Lead

Information Technology Washington, District Of Columbia


Description

Title: Security Tools Engineer Lead
Location: Hybrid – Washington, D.C. Metro Area
Terms: Full-Time
Clearance: Secret clearance
Travel: 0–10%


RESULTS. INNOVATION. VALUES. ACCOUNTABILITY.

That’s RIVA. Our employee-first approach has cultivated a culture that attracts the best and brightest. By investing in people first and providing a flexible work environment, our employees experience higher morale, increased productivity, and lower turnover. At RIVA, people are our #1 priority.


Program Overview:

The International Trade Administration (ITA) Office of the Chief Information Officer (OCIO) Customer Relationship Division (CRD) supports the strategic delivery of digital solutions, enterprise services, and technology alignment across ITA’s global footprint. The CRD plays a critical role in improving customer engagement, optimizing business processes, and enhancing digital service offerings. This project advances ITA’s modernization initiatives by delivering program management, process reengineering, customer experience analysis, and technical documentation services to streamline enterprise IT support and align service delivery with mission goals.

As part of this effort, RIVA supports ITA OCIO in enhancing internal service delivery frameworks, implementing performance metrics, and ensuring the seamless execution of IT modernization initiatives through collaborative project execution, robust documentation, and stakeholder communication.


Position Overview:

RIVA Solutions is seeking an experienced Security Tools Engineer Lead to manage and sustain ITA cybersecurity tools and lead technical activities supporting enterprise threat detection, vulnerability management, application security, incident response, web security, and AI platform protection. This role ensures security tools are configured, monitored, tuned, and supported to maintain effective enterprise protection and reliable service delivery.


 

Core Responsibilities:

  • Manage and sustain ITA cybersecurity tools, including user account provisioning, access controls, configuration, tuning, and ongoing tool performance.
  • Manage threat detection and response capabilities needed to protect the enterprise environment.
  • Resolve customer support tickets involving security tool functionality, access concerns, configuration requests, and performance issues in a timely and accurate manner.
  • Perform credentialed enterprise vulnerability scanning across all in-scope systems capable of supporting authenticated scans.
  • Perform vulnerability scanning of internet-facing and internal web applications to identify security weaknesses.
  • Conduct security reviews of new software before introduction into the environment and reassess previously authorized software receiving new drivers or major version updates.
  • Implement Web Application Firewall rule tuning and policy refinement in response to emerging threat patterns identified by the Enterprise Security Operations Center (ESOC).
  • Respond to and resolve ESOC-related incident response tickets according to established priorities.
  • Support secure configuration, monitoring, access restrictions, data protection, and ongoing security controls for approved AI platforms and services.
  • Integrate AI platform logging and telemetry into enterprise security monitoring and support detection of anomalous, unauthorized, or unapproved AI tool usage.
  • Provide technical security input on AI platform configurations, data handling, access controls, and enterprise AI governance objectives.
  • Produce regular reporting on tool capacity, performance, and the overall enterprise security posture.
  • Support the contractual security tool availability requirement and coordinate corrective action when service or performance issues arise.

Minimum Qualifications:

  • At least 7 years of experience in enterprise cybersecurity operations or a related IT security role
  • Proven experience supporting security operations, including threat detection, incident response, vulnerability assessment, and authenticated infrastructure and web application scanning.
  • Demonstrated experience managing and optimizing enterprise cybersecurity tools, including SIEM, EDR, vulnerability management platforms, and web application firewalls, with responsibility for configuration, tuning, monitoring, troubleshooting, and technical support.
  • Strong understanding of application and infrastructure security, including security impact reviews, change assessments, web application firewall policy management, and security control implementation to protect enterprise environments.
  • Ability to communicate technical findings, service status, capacity, performance, and security posture to technical and non-technical stakeholders.
  • U.S. Citizenship and Secret Clearance.

Preferred Qualifications:

  • Experience supporting federal civilian cybersecurity programs or Department of Commerce environments.
  • Experience securing, monitoring, or governing enterprise AI platforms.

Salary: $155K (flexible depending on experience)


RIVA Benefits:

  • Paid Time Off / Sick Leave
  • Health, Dental, and Vision Coverage
  • Life Insurance
  • Retirement Benefits / 401K with Company Matching
  • HSA/FSA Spending Accounts
  • Long- and Short-Term Disability
  • Pet Insurance
  • Wellness Program Initiatives
  • RIVA Flex
  • Additional Workplace Benefits

RIVA Solutions is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any protected class. If you need a reasonable accommodation to search for a job opening or to submit an online application, please email [email protected]. Only messages left for this purpose will be returned.