Tulzi Technologies, LLC (Tulzi) prides ourselves on an open, and honest culture in the workplace which builds a morale conducive to inspiring growth on our team, while balancing lifestyle by supporting personal and family goals with flexibility. Tulzi offers secure network systems and software engineering solutions in both public and private sectors. With certified expert consulting the team at Tulzi is able to address the customers mission, and follow through in the systems development life cycle.
- Lead RMF activities across the system lifecycle and maintain required security documentation.
- Ensure compliance with applicable security frameworks and support all ATO processes.
- Conduct security impact analysis for system, infrastructure, and application changes.
- Manage RMF packages in enterprise GRC platforms and drive timely POA&M closure.
- Implement and review security controls and hardening standards and participate in security design evaluations.
- Integrate defense-in-depth strategies across hybrid environments and perform enterprise vulnerability assessments.
- Validate, analyze, and coordinate remediation of vulnerabilities while maintaining visibility through dashboards and reporting.
- Embed security into CI/CD pipelines and support DevSecOps tools and processes.
- Provide container and Kubernetes security engineering, including image assurance, runtime protection, and policy enforcement.
- Conduct cloud security architecture reviews and implement controls for identity, encryption, networking, logging, and compliance.
- Secure enterprise Windows and Linux environments and enforce configuration, identity, and platform security standards.
- Manage patching and configuration compliance across enterprise platforms and automation tools.
- Build dashboards for continuous monitoring, compliance reporting, vulnerability trends, threat intelligence, and enterprise risk scoring.
- Provide mentorship and guidance to teams on cybersecurity best practices.
- Bachelor’s degree or equivalent experience (8+ years), or advanced degree with 5+ years of experience.
- TS/SCI eligibility.
- DoD 8570/8140 IAM/IAT Level III compliant certification(s).
- Strong understanding of the Risk Management Framework (RMF) and security governance principles.
- Knowledge of Linux/Unix operating systems and their administrative concepts.
- Familiarity with containerization and orchestration platforms (e.g., Docker, Kubernetes).
- Ability to interpret and apply DISA STIG requirements across traditional, cloud, and containerized environments.
- Proficiency in at least one scripting or automation language (e.g., Bash, Python, Go, Rust).
- Strong analytical and problem-solving capabilities with the ability to work effectively in dynamic environments.