{"schemaVersion":"jobsearcher.job.v1","id":"cfd8ca31bd819acfdbc7f566","url":"https://jobsearcher.com/jobs/cfd8ca31bd819acfdbc7f566","canonicalUrl":"https://jobsearcher.com/jobs/cfd8ca31bd819acfdbc7f566","title":"Lead Security Engineer","description":"Overview\nAs Lead Security Engineer, you will translate federal security requirements into practical controls across a secure, on-premises data and AI platform. You’ll drive RMF activities, guide cross-functional teams, and shape the security architecture for data, APIs, and DevSecOps pipelines. Your work will reduce risk while enabling trusted delivery for government missions. This role offers a strategic impact in a fast-growing firm tackling complex regulatory and security challenges.\n\nCompensation / Benefitsbonusesemployer-paid health caretraining and development funds401k match\nResponsibilitiesTranslate FISMA Moderate and NIST SP 800-53 Rev. 5 requirements into actionable controls and evidenceSupport RMF activities, security planning, control implementation, assessment readiness, and remediation trackingEngineer access control, audit logging, authentication, encryption, configuration management, secure communications, and data-protection safeguardsIntegrate security scanning and compliance checks into the CI/CD processValidate read-only interaction with authoritative sources and safeguard against data modification or external actionSupport incident response, vulnerability management, secure configuration, and continuous monitoringCoordinate with security, CIO/CISO stakeholders, platform teams, and program leadership\nKey requirements8+ years in cybersecurity engineering, security architecture, information assurance, or related fieldExperience designing and implementing security controls for Federal information systems, preferably in FISMA/RMF environmentsStrong knowledge of FISMA, NIST SP 800-53 Rev. 5, RMF, and secure software development/DevSecOpsExperience securing enterprise infrastructure, applications, databases, APIs, networks, and on-premises or hybrid platformsHands-on Linux, Docker/containerization, and Kubernetes and/or RancherExperience implementing IAM, RBAC, privileged access, authentication, authorization, encryption, certificates, secrets, and key-management controlsExperience with vulnerability management, security scanning, patching, configuration management, and remediationExperience integrating security into CI/CD pipelines, preferably with Jenkins and/or self-hosted Azure DevOpsUnderstanding of application security, including SAST/SCA/DAST, dependency management, container security, secrets detection, and secure API designExperience with security logging, monitoring, alerting, audit trails, and incident responseExperience supporting security assessments, audits, POA&Ms, vulnerability assessments, and continuous monitoringAbility to conduct threat modeling and evaluate security risks with new technologies and architecturesStrong technical documentation, communication, and problem-solving skillsAbility to collaborate across platform, infrastructure, application, data, AI/ML, DevOps, and Government teamsU.S. citizenship and ability to obtain and maintain Top Secret eligibility; active Top Secret clearance preferredstrong communicationproblem-solvingcollaboration across cross-functional teamsFISMA/NIST SP 800-53 Rev. 5 RMFLinuxDocker","company":"Analytica","rawCompany":"analytica","city":"Silver Spring","state":"MD","isRemote":false,"isActive":false,"createdAt":"2026-09-22T03:33:14.240Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Lead Security Engineer","description":"Overview\nAs Lead Security Engineer, you will translate federal security requirements into practical controls across a secure, on-premises data and AI platform. You’ll drive RMF activities, guide cross-functional teams, and shape the security architecture for data, APIs, and DevSecOps pipelines. Your work will reduce risk while enabling trusted delivery for government missions. This role offers a strategic impact in a fast-growing firm tackling complex regulatory and security challenges.\n\nCompensation / Benefitsbonusesemployer-paid health caretraining and development funds401k match\nResponsibilitiesTranslate FISMA Moderate and NIST SP 800-53 Rev. 5 requirements into actionable controls and evidenceSupport RMF activities, security planning, control implementation, assessment readiness, and remediation trackingEngineer access control, audit logging, authentication, encryption, configuration management, secure communications, and data-protection safeguardsIntegrate security scanning and compliance checks into the CI/CD processValidate read-only interaction with authoritative sources and safeguard against data modification or external actionSupport incident response, vulnerability management, secure configuration, and continuous monitoringCoordinate with security, CIO/CISO stakeholders, platform teams, and program leadership\nKey requirements8+ years in cybersecurity engineering, security architecture, information assurance, or related fieldExperience designing and implementing security controls for Federal information systems, preferably in FISMA/RMF environmentsStrong knowledge of FISMA, NIST SP 800-53 Rev. 5, RMF, and secure software development/DevSecOpsExperience securing enterprise infrastructure, applications, databases, APIs, networks, and on-premises or hybrid platformsHands-on Linux, Docker/containerization, and Kubernetes and/or RancherExperience implementing IAM, RBAC, privileged access, authentication, authorization, encryption, certificates, secrets, and key-management controlsExperience with vulnerability management, security scanning, patching, configuration management, and remediationExperience integrating security into CI/CD pipelines, preferably with Jenkins and/or self-hosted Azure DevOpsUnderstanding of application security, including SAST/SCA/DAST, dependency management, container security, secrets detection, and secure API designExperience with security logging, monitoring, alerting, audit trails, and incident responseExperience supporting security assessments, audits, POA&Ms, vulnerability assessments, and continuous monitoringAbility to conduct threat modeling and evaluate security risks with new technologies and architecturesStrong technical documentation, communication, and problem-solving skillsAbility to collaborate across platform, infrastructure, application, data, AI/ML, DevOps, and Government teamsU.S. citizenship and ability to obtain and maintain Top Secret eligibility; active Top Secret clearance preferredstrong communicationproblem-solvingcollaboration across cross-functional teamsFISMA/NIST SP 800-53 Rev. 5 RMFLinuxDocker","datePosted":"2026-09-22T03:33:14.240Z","dateModified":"2026-09-22T03:33:14.240Z","hiringOrganization":{"@type":"Organization","name":"Analytica","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Silver Spring","addressRegion":"MD","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"cfd8ca31bd819acfdbc7f566"},"url":"https://jobsearcher.com/jobs/cfd8ca31bd819acfdbc7f566"}}