Security Tools Engineer Lead
RESULTS. INNOVATION. VALUES. ACCOUNTABILITY.
That’s RIVA.
We’re a mission-driven IT services company and systems integrator supporting digital transformation and modernization for federal government agencies. Since 2009, we’ve partnered with our customers to solve complex challenges through smart, practical innovation to deliver real outcomes where they matter most. Our teams are made up of industry-leading experts who are passionate about doing great work and making a difference. We don’t just develop solutions, we support efforts that strengthen communities and serve the public good.
RIVA’s culture is built on four core values: Results, Innovation, Values, and Accountability. They guide how we work, how we collaborate, and how we measure success. Our employee-first approach is rooted in trust, ownership, and meaningful work. By investing in our people and fostering a flexible, supportive environment, employees have the opportunity to grow their skills, contribute ideas, and make an impact from day one. all while supporting missions that matter.
POSITION OVERVIEW
RIVA Solutions is seeking an experienced Security Tools Engineer Lead to manage and sustain ITA cybersecurity tools and lead technical activities supporting enterprise threat detection, vulnerability management, application security, incident response, web security, and AI platform protection. This role ensures security tools are configured, monitored, tuned, and supported to maintain effective enterprise protection and reliable service delivery.
CORE RESPONSIBILITIES
- Manage and sustain ITA cybersecurity tools, including user account provisioning, access controls, configuration, tuning, and ongoing tool performance.
- Manage threat detection and response capabilities needed to protect the enterprise environment.
- Resolve customer support tickets involving security tool functionality, access concerns, configuration requests, and performance issues in a timely and accurate manner.
- Perform credentialed enterprise vulnerability scanning across all in-scope systems capable of supporting authenticated scans.
- Perform vulnerability scanning of internet-facing and internal web applications to identify security weaknesses.
- Conduct security reviews of new software before introduction into the environment and reassess previously authorized software receiving new drivers or major version updates.
- Implement Web Application Firewall rule tuning and policy refinement in response to emerging threat patterns identified by the Enterprise Security Operations Center (ESOC).
- Respond to and resolve ESOC-related incident response tickets according to established priorities.
- Support secure configuration, monitoring, access restrictions, data protection, and ongoing security controls for approved AI platforms and services.
- Integrate AI platform logging and telemetry into enterprise security monitoring and support detection of anomalous, unauthorized, or unapproved AI tool usage
- Provide technical security input on AI platform configurations, data handling, access controls, and enterprise AI governance objectives.
- Produce regular reporting on tool capacity, performance, and the overall enterprise security posture.
- Support the contractual security tool availability requirement and coordinate corrective action when service or performance issues arise.
MINIMUM QUALIFICATIONS
- At least 7 years of experience in enterprise cybersecurity operations or a related IT security role
- Proven experience supporting security operations, including threat detection, incident response, vulnerability assessment, and authenticated infrastructure and web application scanning.
- Demonstrated experience managing and optimizing enterprise cybersecurity tools, including SIEM, EDR, vulnerability management platforms, and web application firewalls, with responsibility for configuration, tuning, monitoring, troubleshooting, and technical support.
- Strong understanding of application and infrastructure security, including security impact reviews, change assessments, web application firewall policy management, and security control implementation to protect enterprise environments.
- Ability to communicate technical findings, service status, capacity, performance, and security posture to technical and non-technical stakeholders.
- U.S. Citizenship and Secret Clearance.
PREFERRED QUALIFICATIONS
- Experience supporting federal civilian cybersecurity programs or Department of Commerce environments.
- Experience securing, monitoring, or governing enterprise AI platforms.
Pay range
$155,000 - $165,000 USD
EQUAL EMPLOYMENT OPPORTUNITY & ACCOMMODATION
We believe great teams are built from different backgrounds, perspectives, and lived experiences, and we mean that beyond the buzzwords.
RIVA is an equal opportunity employer. We welcome applicants of every race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, and any other characteristic protected by law.
If you need an accommodation at any point in our process, send an email to talent@rivasolutionsinc.com, we'll be happy to help.
VETERAN SUPPORT & ACCESSIBILITY
As a federal contractor, RIVA follows the requirements of the Vietnam Era Veterans' Readjustment Assistance Act (VEVRAA) and Section 503 of the Rehabilitation Act, supporting the employment and advancement of protected veterans and individuals with disabilities. If you're a veteran, we encourage you to self-identify during the application process, it helps us track our hiring commitments and, in some cases, may support priority referral for open roles.
RIVA also invites applicants to voluntarily self-identify as having a disability during the application process, not because it affects your chances of being hired, but because it helps us measure how well we're living up to our commitments and identify where we can do better. Your response is confidential and entirely optional.
Apply for this job
*
indicates a required field