Job Requirements
Macdill Air Force Base, FL
Top Secret/SCI Polygraph Unspecified
Senior Level Career (10+ yrs experience)
Salary not specified
Join Premium to unlock estimated salaries
Job Description
<br><br>>
Data Security Engineer (DRM Specialist) – Senior, Zero Trust Program (USSOCOM)
<br><br><a>
<br>Athenix Solutions Group<br>
</a>
<br><br>Data Security Engineer (DRM Specialist) – Senior, Zero Trust Program (USSOCOM)
<br>
<br>
<a>MacDill Air Force Base, FL</a>
•
ASM <br><br>Description<br><br>Athenix Special Missions is seeking a<strong> Data Security Engineer (DRM Specialist) – Senior, Zero Trust Program (USSOCOM)</strong> in <strong>MacDill Air Force Base (Tampa), Florida!</strong> <br><br><em><strong>ASM Quality Policy: </strong></em><em>To meet or exceed our customers’ expectations for quality, delivery, and service through continual improvement, striving to meet our objectives, and committing to meeting all legal and statutory requirements</em><br><br><strong>Must be a U.S. Citizen</strong><br><br>Location: <strong>MacDill AFB, Florida</strong><br><br>Clearance Requirement: <strong>Must have an Active DoD TS/SCI Clearance</strong><br><br><strong>Position:</strong><br><br>We seeking a highly specialized Data Security Engineer (DRM Specialist) to serve as the subject matter expert for encryption standards and Digital Rights Management (DRM) within the USSOCOM Zero Trust program. While other engineers handle general labeling, your role is to ensure that the data itself is mathematically protected and self-defending, regardless of where it travels.<br><br>As the Senior DRM Specialist, you will be responsible for the configuration and enforcement of advanced encryption policies using <strong>Kiteworks</strong> (on SIPR and Top-Secret networks) and <strong>Microsoft Purview Information Protection</strong> (on NIPR). You will move the Command beyond simple file encryption to a granular, identity-aware protection model. You will design the “Data Policy Engine” rules that act as the Policy Decision Point (PDP), ensuring that a user’s ability to decrypt a file is dynamically brokered in real-time based on their “Trust Attributes” (clearance, role, and risk level). You will also manage the complex Key Management lifecycles required to maintain a seamless user experience in a high-security, hybrid environment.<br><br><strong>Responsibilities</strong><br><ul><li><strong>Enterprise DRM Architecture:</strong> Architect and configure the <strong>Kiteworks Private Content Network</strong> (SIPR/Top Secret) and <strong>Microsoft Purview</strong> (NIPR) to serve as the central Policy Decision Points (PDP) for file access.</li><li><strong>ABAC Policy Design:</strong> Translate NIST 8112 metadata attributes into concrete DRM policies (e.g., “Allow View ONLY if User.Clearance >= TopSecret AND Device.State = Compliant”).</li><li><strong>Key Management:</strong> Manage the lifecycle of encryption keys (Bring Your Own Key - BYOK, Customer Managed Keys) ensuring FIPS 140-2/3 compliance and availability across hybrid and air-gapped environments.</li><li><strong>Secure Collaboration:</strong> Configure advanced DRM features such as <strong>SafeVIEW </strong>and <strong>SafeEDIT</strong> in Kiteworks to allow users to view and edit sensitive documents in a secure, containerized stream without the data ever leaving the controlled repository.</li><li><strong>Policy Enforcement:</strong> Define and enforce “Rights Management” controls, specifically preventing actions like Copy/Paste, Screen Capture, and Printing for documents tagged with specific sensitivity labels (e.g., CUI, Secret/NoForn).</li></ul><br>
<br>Requirements<br><br><strong>Qualifications</strong><br><br><strong>Minimum Clearance Required to Start</strong><br><ul><li>Active Top-Secret clearance with SCI eligibility.</li></ul><br><strong>Education</strong><br><ul><li><strong>Senior Level:</strong> Master of Science (MS) degree in Cybersecurity, Computer Science, Mathematics (Cryptography focus), or a related technical field.</li></ul><br><strong>Required Experience & Skills (“Must-Haves”)</strong><br><ul><li><strong>Senior Level:</strong> 10+ years of related technical experience.</li><li><strong>DRM Expertise:</strong> Extensive hands-on experience (5+ years) designing and administering Enterprise Digital Rights Management (EDRM) or Information Rights Management (IRM) systems, specifically <strong>Kiteworks</strong>, <strong>Microsoft Azure Information Protection (AIP/RMS)</strong>, or <strong>Virtru</strong>.</li><li><strong>Encryption Standards:</strong> Deep understanding of cryptographic protocols (AES-256, RSA), Public Key Infrastructure (PKI), and Key Management Service (KMS) operations.</li><li><strong>Policy Logic:</strong> Proven ability to design complex Attribute-Based Access Control (ABAC) logic and Conditional Access policies.</li><li><strong>Cross-Domain Knowledge:</strong> Understanding of how encryption travels across Cross-Domain Solutions (CDS) and the challenges of key management in air-gapped networks.</li></ul><br><strong>Preferred Experience & Skills (“Nice-to-Haves”)</strong><br><ul><li>Experience with <strong>Hardware Security Modules (HSM)</strong> (e.g., Thales, Entrust).</li><li>Knowledge of <strong>NIST SP 800-53</strong> controls related to System and Information Integrity (SI) and Media Protection (MP).</li><li>Experience integrating DRM tools with <strong>SailPoint</strong> for identity attribute consumption.</li><li>Kiteworks Administrator Certification.</li></ul><br><strong>Certifications</strong><br><ul><li><strong>Required:</strong> CompTIA Security+ CE (or higher) to meet DoD 8570 IAT Level II requirements.</li><li><strong>Preferred:</strong> Microsoft Information Protection Administrator (SC-400).</li><li><strong>Preferred:</strong> Certified Information Systems Security Professional (CISSP).</li></ul><br><br><em><strong>Equal Opportunity Employer, including disability and protected veteran status</strong></em> <br><br><em>Powered by </em><br>
<a>
Privacy Policy
</a>
<a>
Payroll & HR Software
</a>
<br><br><!-- OneTrust Cookies Consent Notice -->
<br><br>By clicking “Accept All Cookies”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. <br><br>Cookies Settings Accept All Cookies<br><br><!-- Close Button --><br><br><!-- Close Button END--><br><br><!-- Close Button --><br><!-- Logo Tag --><br><br><!-- Close Button --><br><br>Privacy Preference Center<br><br>When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and change our default settings. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.
<br><a>More information</a><br>Allow All<br><br> Manage Consent Preferences<br><br><!-- Accordion header --><br><br>Targeting Cookies<br><br> Targeting Cookies <br><br><!-- accordion detail --><br><br>These cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.<br><br><!-- Accordion header --><br><br>Strictly Necessary Cookies<br><br>Always Active<br><br><!-- accordion detail --><br><br>These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.<br><br><!-- Accordion header --><br><br>Performance Cookies<br><br> Performance Cookies <br><br><!-- accordion detail --><br><br>These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies we will not know when you have visited our site, and will not be able to monitor its performance.<br><br><!-- Groups sections starts --><!-- Group section ends --><!-- Accordion Group section starts --><!-- Accordion Group section ends --><br><br>Performance Cookies<br><br>Clear<br><br>checkbox label label<br><br>Apply Cancel<br><br>Consent Leg.Interest<br><br>Switch Label label<br><br> Switch Label label<br><br> Switch Label label<br><br>Reject All Confirm My Choices<br><!-- Footer logo --><br><a></a><br><br><!-- Cookie subgroup container --><!-- Vendor list link --><!-- Cookie lost link --><!-- Toggle HTML element --><!-- Checkbox HTML --><!-- plus minus--><!-- Arrow SVG element --><!-- Accordion basic element --><!-- Vendor Service container and item template --><br><br>
Data Security Engineer (DRM Specialist) – Senior, Zero Trust Program (USSOCOM)
<br><br><a>
<br>Athenix Solutions Group<br>
</a>
<br><br>Data Security Engineer (DRM Specialist) – Senior, Zero Trust Program (USSOCOM)
<br>
<br>
<a>MacDill Air Force Base, FL</a>
•
ASM <br><br>Description<br><br>Athenix Special Missions is seeking a<strong> Data Security Engineer (DRM Specialist) – Senior, Zero Trust Program (USSOCOM)</strong> in <strong>MacDill Air Force Base (Tampa), Florida!</strong> <br><br><em><strong>ASM Quality Policy: </strong></em><em>To meet or exceed our customers’ expectations for quality, delivery, and service through continual improvement, striving to meet our objectives, and committing to meeting all legal and statutory requirements</em><br><br><strong>Must be a U.S. Citizen</strong><br><br>Location: <strong>MacDill AFB, Florida</strong><br><br>Clearance Requirement: <strong>Must have an Active DoD TS/SCI Clearance</strong><br><br><strong>Position:</strong><br><br>We seeking a highly specialized Data Security Engineer (DRM Specialist) to serve as the subject matter expert for encryption standards and Digital Rights Management (DRM) within the USSOCOM Zero Trust program. While other engineers handle general labeling, your role is to ensure that the data itself is mathematically protected and self-defending, regardless of where it travels.<br><br>As the Senior DRM Specialist, you will be responsible for the configuration and enforcement of advanced encryption policies using <strong>Kiteworks</strong> (on SIPR and Top-Secret networks) and <strong>Microsoft Purview Information Protection</strong> (on NIPR). You will move the Command beyond simple file encryption to a granular, identity-aware protection model. You will design the “Data Policy Engine” rules that act as the Policy Decision Point (PDP), ensuring that a user’s ability to decrypt a file is dynamically brokered in real-time based on their “Trust Attributes” (clearance, role, and risk level). You will also manage the complex Key Management lifecycles required to maintain a seamless user experience in a high-security, hybrid environment.<br><br><strong>Responsibilities</strong><br><ul><li><strong>Enterprise DRM Architecture:</strong> Architect and configure the <strong>Kiteworks Private Content Network</strong> (SIPR/Top Secret) and <strong>Microsoft Purview</strong> (NIPR) to serve as the central Policy Decision Points (PDP) for file access.</li><li><strong>ABAC Policy Design:</strong> Translate NIST 8112 metadata attributes into concrete DRM policies (e.g., “Allow View ONLY if User.Clearance >= TopSecret AND Device.State = Compliant”).</li><li><strong>Key Management:</strong> Manage the lifecycle of encryption keys (Bring Your Own Key - BYOK, Customer Managed Keys) ensuring FIPS 140-2/3 compliance and availability across hybrid and air-gapped environments.</li><li><strong>Secure Collaboration:</strong> Configure advanced DRM features such as <strong>SafeVIEW </strong>and <strong>SafeEDIT</strong> in Kiteworks to allow users to view and edit sensitive documents in a secure, containerized stream without the data ever leaving the controlled repository.</li><li><strong>Policy Enforcement:</strong> Define and enforce “Rights Management” controls, specifically preventing actions like Copy/Paste, Screen Capture, and Printing for documents tagged with specific sensitivity labels (e.g., CUI, Secret/NoForn).</li></ul><br>
<br>Requirements<br><br><strong>Qualifications</strong><br><br><strong>Minimum Clearance Required to Start</strong><br><ul><li>Active Top-Secret clearance with SCI eligibility.</li></ul><br><strong>Education</strong><br><ul><li><strong>Senior Level:</strong> Master of Science (MS) degree in Cybersecurity, Computer Science, Mathematics (Cryptography focus), or a related technical field.</li></ul><br><strong>Required Experience & Skills (“Must-Haves”)</strong><br><ul><li><strong>Senior Level:</strong> 10+ years of related technical experience.</li><li><strong>DRM Expertise:</strong> Extensive hands-on experience (5+ years) designing and administering Enterprise Digital Rights Management (EDRM) or Information Rights Management (IRM) systems, specifically <strong>Kiteworks</strong>, <strong>Microsoft Azure Information Protection (AIP/RMS)</strong>, or <strong>Virtru</strong>.</li><li><strong>Encryption Standards:</strong> Deep understanding of cryptographic protocols (AES-256, RSA), Public Key Infrastructure (PKI), and Key Management Service (KMS) operations.</li><li><strong>Policy Logic:</strong> Proven ability to design complex Attribute-Based Access Control (ABAC) logic and Conditional Access policies.</li><li><strong>Cross-Domain Knowledge:</strong> Understanding of how encryption travels across Cross-Domain Solutions (CDS) and the challenges of key management in air-gapped networks.</li></ul><br><strong>Preferred Experience & Skills (“Nice-to-Haves”)</strong><br><ul><li>Experience with <strong>Hardware Security Modules (HSM)</strong> (e.g., Thales, Entrust).</li><li>Knowledge of <strong>NIST SP 800-53</strong> controls related to System and Information Integrity (SI) and Media Protection (MP).</li><li>Experience integrating DRM tools with <strong>SailPoint</strong> for identity attribute consumption.</li><li>Kiteworks Administrator Certification.</li></ul><br><strong>Certifications</strong><br><ul><li><strong>Required:</strong> CompTIA Security+ CE (or higher) to meet DoD 8570 IAT Level II requirements.</li><li><strong>Preferred:</strong> Microsoft Information Protection Administrator (SC-400).</li><li><strong>Preferred:</strong> Certified Information Systems Security Professional (CISSP).</li></ul><br><br><em><strong>Equal Opportunity Employer, including disability and protected veteran status</strong></em> <br><br><em>Powered by </em><br>
<a>
Privacy Policy
</a>
<a>
Payroll & HR Software
</a>
<br><br><!-- OneTrust Cookies Consent Notice -->
<br><br>By clicking “Accept All Cookies”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. <br><br>Cookies Settings Accept All Cookies<br><br><!-- Close Button --><br><br><!-- Close Button END--><br><br><!-- Close Button --><br><!-- Logo Tag --><br><br><!-- Close Button --><br><br>Privacy Preference Center<br><br>When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and change our default settings. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.
<br><a>More information</a><br>Allow All<br><br> Manage Consent Preferences<br><br><!-- Accordion header --><br><br>Targeting Cookies<br><br> Targeting Cookies <br><br><!-- accordion detail --><br><br>These cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.<br><br><!-- Accordion header --><br><br>Strictly Necessary Cookies<br><br>Always Active<br><br><!-- accordion detail --><br><br>These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.<br><br><!-- Accordion header --><br><br>Performance Cookies<br><br> Performance Cookies <br><br><!-- accordion detail --><br><br>These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies we will not know when you have visited our site, and will not be able to monitor its performance.<br><br><!-- Groups sections starts --><!-- Group section ends --><!-- Accordion Group section starts --><!-- Accordion Group section ends --><br><br>Performance Cookies<br><br>Clear<br><br>checkbox label label<br><br>Apply Cancel<br><br>Consent Leg.Interest<br><br>Switch Label label<br><br> Switch Label label<br><br> Switch Label label<br><br>Reject All Confirm My Choices<br><!-- Footer logo --><br><a></a><br><br><!-- Cookie subgroup container --><!-- Vendor list link --><!-- Cookie lost link --><!-- Toggle HTML element --><!-- Checkbox HTML --><!-- plus minus--><!-- Arrow SVG element --><!-- Accordion basic element --><!-- Vendor Service container and item template --><br><br>
group id: 10327226