Lead Security Engineer

Lead Security Engineer, #1073

Security Requirement: U.S. Citizenship required

Work Location: Suitland, MD

We are seeking a Subject Matter Expert (SME)–level Lead Security Engineer to lead application security across a large-scale, cloud-native federal modernization program. This role provides technical and management leadership on major security tasks, embedding security into every phase of the System Development Life Cycle (SDLC) using a DevSecOps methodology. The ideal candidate will architect and enforce Zero Trust principles, drive Authorization to Operate (ATO) activities, and direct application security testing, threat modeling, and vulnerability remediation across a System of Systems (SoS). This position interfaces with senior Government stakeholders and the Office of Information Security (OIS), and decision-making and domain knowledge may have a critical impact on overall program implementation. May supervise others.

What You'll be Doing:

  • Lead the design and implementation of application security solutions, frameworks, and processes across all phases of the SDLC
  • Implement Zero Trust (ZT) principles for applications, workloads, and data, aligned with EO 14028, OMB M-22-09, and NIST SP 800-207 (Zero Trust Architecture)
  • Integrate security into DevSecOps CI/CD pipelines, establishing security gates, automated code inspection, and supply-chain controls, including Software Bill of Materials (SBOM) generation
  • Direct Static and Dynamic Application Security Testing (SAST/DAST), vulnerability assessments, and penetration testing to identify, triage, and remediate security weaknesses
  • Lead threat modeling exercises to analyze application architecture, identify attack vectors, and document mitigation strategies throughout design, development, testing, and deployment
  • Support the Authorization to Operate (ATO) process, including security control assessment, artifact and evidence collection, Privacy Threshold Analysis/Privacy Impact Assessment support, and Plan of Action and Milestones (POA&M) management
  • Implement security controls in accordance with the NIST Cybersecurity Framework and NIST SP 800-53, and remediate identified vulnerabilities and compliance findings
  • Design and implement secure architecture patterns — secure API design, authentication/authorization, input validation, encryption, secure logging and monitoring (SIEM), and secure error/session/configuration management
  • Develop and maintain metrics, dashboards, and reporting to track application security posture, threat trends, and remediation progress over time
  • Support the development and management of Interagency Security Agreements (ISA), security playbooks, and incident response in accordance with current cybersecurity policies
  • Collaborate with application developers, data engineers, systems engineers, and OIS to identify and mitigate vulnerabilities, and provide expert security consultation to development teams
  • Assist in FedRAMP certification activities and the assessment/remediation of independent penetration testing results, as applicable

Required Education, Experience, and Skills:

  • Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or a related field
  • 15+ years of relevant IT/cybersecurity experience, providing technical and management leadership on major tasks or technology assignments (SME level)
  • Certified Information Systems Security Professional (CISSP)
  • Certified Cloud Security Professional (CCSP)
  • Demonstrated expertise in integrating security into a DevSecOps SDLC, including CI/CD security gates and automated security testing
  • Hands-on experience implementing Zero Trust Architecture and applying NIST SP 800-53 controls and the NIST Cybersecurity Framework
  • Proven experience leading vulnerability assessments, penetration testing, and threat modeling for enterprise applications
  • Experience supporting the ATO lifecycle and managing POA&Ms, security artifacts, and evidence collection
  • U.S. Citizenship required

Preferred Skills and Experience:

  • Certified Information Security Manager (CISM)
  • Certified Information Systems Auditor (CISA)
  • Experience generating Software Bill of Materials (SBOMs) and implementing software supply-chain security controls
  • Familiarity with SIEM deployment, container/image hardening, and secure baseline configuration
  • Experience in large-scale, multi-cloud federal environments and FedRAMP processes
  • Strong analytical, problem-solving, written, and verbal communication skills, including the ability to brief senior Government stakeholders

Our estimated salary range for this position is $120,000 - $190,000; this presented salary range is not a guarantee of compensation or salary. Offered salary is based on experience, geographic location, and possibly contractual requirements as appropriate to the role. *Salary could fall outside of this range.

Who We Are

Dev Technology is a growing IT company with an employee-centric culture that works on mission-critical projects for the federal government. We partner with our federal customers to deliver technology services and solutions, and to drive our client’s missions forward through innovation. We use Agile and DevSecOps principles to provide services including application development, biometrics and identity management, cloud and infrastructure optimization, IT and legacy modernization, and data management.

As a Washington Post Top Workplace award winner for the past THIRTEEN years in a row, the Top Workplaces USA for the past five years, and a recipient of the Companies As Responsive Employers (CARE) Award for the past six years, Dev Technology employees enjoy:

  • Generous and flexible time-off policy
  • Flexible work schedules and telework options, including remote work availability for eligible projects
  • Career development opportunities including a mentorship program, technical and management training through Dev University, hands-on learning through DevLab, tuition reimbursement, and paid training opportunities
  • Industry-leading benefits including a choice of two health plans that include dental and vision, flexible spending account, commuter benefits, life insurance, and more
  • 401K matching with a 5% matching contribution
  • Regular team and company social events including our annual party, happy hours, fitness challenges, and more
  • A focus on community engagement including company wide support activities, employer match for donations, and time off for volunteer efforts
  • To learn more about working at Dev Technology, visit Working At Dev Technology Group

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans

Dev Technology Group operates in the following states: AL, AR, AZ, CO, DC, FL, GA, ID, IL, IN, MD, MA, ME, MI, MN, MO, MS, NC, NJ, OH, OR, PA, SC, TN, TX, VA, WV.

What this application asks

greenhouse

First Name, Last Name, Email, Phone, Resume/CV, Cover Letter, Location

  • Preferred First Name optional
  • This position involves working on a contract for the US Government. The US Government requires US citizenship for this position. **NOTE: This position cannot support a Work Visa or Green Card status.  Providing false information regarding your US Citizenship status on this application will result in your application being rejected for this opportunity. Can you meet this requirement? choose one
  • What is your preferred name? (if different than your legal name) optional
  • This position is on site in Suitland, MD 5 days per week. Are you able to commute to this location? choose one
  • Do you have a minimum of a Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or a related field? choose one
  • Do you have 15+ years of relevant IT/cybersecurity experience, providing technical and management leadership on major tasks or technology assignments (SME level)? choose one
  • Do you have an active Certified Information Systems Security Professional (CISSP) and/or an active Certified Cloud Security Professional (CCSP) certification? choose one
  • Please list all your active professional certifications. written answer
  • Do you have experience integrating security into a DevSecOps SDLC, including CI/CD security gates and automated security testing? choose one
  • Do you have hands-on experience implementing Zero Trust Architecture and applying NIST SP 800-53 controls and the NIST Cybersecurity Framework? choose one
  • Do you have experience leading vulnerability assessments, penetration testing, and threat modeling for enterprise applications? choose one
  • Do you have experience supporting the ATO lifecycle and managing POA&Ms, security artifacts, and evidence collection? choose one
  • Please provide your salary expectations for this role.
  • LinkedIn and/or GitHub Profile URL
  • As part of our final interview and identity-verification process, candidates may be required to attend an in-person interview at Dev Technology’s headquarters in Reston, Virginia. Any travel reimbursement would be determined on a case-by-case basis and must be approved in advance. If selected for an in-person interview, are you willing and able to participate? choose one
  • Please acknowledge the following: All new hires are asked to come onsite to our Reston, VA headquarters for orientation. Are you able to meet this requirement? choose one
  • Street Address written answer
  • Street Address (Optional Second Line) optional
  • City
  • State choose one
  • Zip
  • By selecting YES, I consent to receive recruiting SMS messages from Dev Technology Group at the phone number provided on my job application. choose one
  • Pre-Employment Requirements Acknowledgment I understand that submitting an application does not constitute an offer of employment. If I receive an offer from Dev Technology, the offer will be contingent upon my successful completion of all applicable pre-employment requirements. These requirements may include a background check conducted through HireRight and the successful completion of any required government, agency, or client suitability, public trust, or security clearance process. I understand that I may not begin employment until all required pre-employment conditions have been satisfied and Dev Technology has confirmed that I am authorized to start work. I agree to provide accurate information and promptly complete any documentation or actions required to support these processes. I have read and understand the pre-employment requirements described above. choose one
  • Dev Technology requires all candidates who receive a verbal offer to successfully complete an identity verification before a written offer can be issued. Are you willing to complete this required step of the hiring process? choose one
  • If you currently hold a clearance, please indicate which security clearance you currently hold: choose any

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available