JOBSEARCHER

Lead Security Engineer

Overview As Lead Security Engineer, you will translate federal security requirements into practical controls across a secure, on-premises data and AI platform. You’ll drive RMF activities, guide cross-functional teams, and shape the security architecture for data, APIs, and DevSecOps pipelines. Your work will reduce risk while enabling trusted delivery for government missions. This role offers a strategic impact in a fast-growing firm tackling complex regulatory and security challenges. Compensation / Benefitsbonusesemployer-paid health caretraining and development funds401k match ResponsibilitiesTranslate FISMA Moderate and NIST SP 800-53 Rev. 5 requirements into actionable controls and evidenceSupport RMF activities, security planning, control implementation, assessment readiness, and remediation trackingEngineer access control, audit logging, authentication, encryption, configuration management, secure communications, and data-protection safeguardsIntegrate security scanning and compliance checks into the CI/CD processValidate read-only interaction with authoritative sources and safeguard against data modification or external actionSupport incident response, vulnerability management, secure configuration, and continuous monitoringCoordinate with security, CIO/CISO stakeholders, platform teams, and program leadership Key requirements8+ years in cybersecurity engineering, security architecture, information assurance, or related fieldExperience designing and implementing security controls for Federal information systems, preferably in FISMA/RMF environmentsStrong knowledge of FISMA, NIST SP 800-53 Rev. 5, RMF, and secure software development/DevSecOpsExperience securing enterprise infrastructure, applications, databases, APIs, networks, and on-premises or hybrid platformsHands-on Linux, Docker/containerization, and Kubernetes and/or RancherExperience implementing IAM, RBAC, privileged access, authentication, authorization, encryption, certificates, secrets, and key-management controlsExperience with vulnerability management, security scanning, patching, configuration management, and remediationExperience integrating security into CI/CD pipelines, preferably with Jenkins and/or self-hosted Azure DevOpsUnderstanding of application security, including SAST/SCA/DAST, dependency management, container security, secrets detection, and secure API designExperience with security logging, monitoring, alerting, audit trails, and incident responseExperience supporting security assessments, audits, POA&Ms, vulnerability assessments, and continuous monitoringAbility to conduct threat modeling and evaluate security risks with new technologies and architecturesStrong technical documentation, communication, and problem-solving skillsAbility to collaborate across platform, infrastructure, application, data, AI/ML, DevOps, and Government teamsU.S. citizenship and ability to obtain and maintain Top Secret eligibility; active Top Secret clearance preferredstrong communicationproblem-solvingcollaboration across cross-functional teamsFISMA/NIST SP 800-53 Rev. 5 RMFLinuxDocker