Dev Technology logo
Dev TechnologyPosted 1 month ago
EXPIRED

Lead Security Engineer

$120,000–$190,000 year

On-siteSuitland, Maryland, United States

Full TimeSenior LevelMediumInformation Technology

Job Summary

Lead the design and implementation of application security solutions, frameworks, and processes across all phases of the SDLC using a DevSecOps methodology. Enforce Zero Trust principles, drive Authorization to Operate (ATO) activities, and direct application security testing, threat modeling, and vulnerability remediation. Integrate security into CI/CD pipelines, establish security gates, and manage Software Bill of Materials generation. Collaborate with developers and the Office of Information Security to identify vulnerabilities, support FedRAMP certification, and maintain metrics on security posture. This SME-level role requires 15+ years of experience, CISSP and CCSP certifications, and U.S. Citizenship. Located in Suitland, MD, with a salary range of $120,000 - $190,000.

Required Qualifications

  • U.S. Citizenship
  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field
  • 15+ years of relevant IT/cybersecurity experience
  • Certified Information Systems Security Professional (CISSP)
  • Certified Cloud Security Professional (CCSP)
  • Demonstrated expertise in integrating security into a DevSecOps SDLC, including CI/CD security gates and automated security testing
  • Hands-on experience implementing Zero Trust Architecture and applying NIST SP 800-53 controls and the NIST Cybersecurity Framework
  • Proven experience leading vulnerability assessments, penetration testing, and threat modeling for enterprise applications
  • Experience supporting the ATO lifecycle and managing POA&Ms, security artifacts, and evidence collection

Desired Qualifications

  • Certified Information Security Manager (CISM)
  • Certified Information Systems Auditor (CISA)
  • Experience generating Software Bill of Materials (SBOMs) and implementing software supply-chain security controls
  • Familiarity with SIEM deployment, container/image hardening, and secure baseline configuration
  • Experience in large-scale, multi-cloud federal environments and FedRAMP processes
  • Strong analytical, problem-solving, written, and verbal communication skills, including the ability to brief senior Government stakeholders

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Find similar roles