Eccalon LLC logo
Eccalon LLCPosted 3 weeks ago
EXPIRED

Security Software Engineer

On-siteHanover, Maryland, United States

Full TimeBachelors DegreeSmall

Job Summary

Design and develop secure software with a security-first mindset embedded across the SDLC, from design and code review through CI/CD and cloud deployment. Automate security gates in pipelines for SAST, DAST, dependency scanning, and secrets detection while conducting architecture reviews to address OWASP Top 10 and DoD STIGs. Lead code reviews, triage vulnerabilities within POA&M timelines, and support incident response for application-layer events. Instrument applications with security logging and monitoring to satisfy audit and continuous monitoring requirements. Collaborate with DevOps teams to enforce secure IaC, WAF rules, and runtime monitoring across AWS and Azure environments.

Required Qualifications

  • Bachelor's degree in Computer Science, Engineering, or related field—or equivalent experience
  • 3+ years of software engineering experience with a strong focus on security
  • Proficiency in one or more programming languages (e.g., JavaScript/TypeScript, Python, Go, C#)
  • Experience with secure coding practices and frameworks
  • Strong understanding of application security principles, including: OWASP Top 10, Secure API/REST design, Cryptography fundamentals, Authentication/authorization patterns
  • Experience with code scanning tools (SAST/DAST), threat modeling, and penetration testing
  • Familiarity with NIST 800-171, CMMC, or FedRAMP security control requirements and evidence collection
  • Hands-on experience with AWS and/or Azure security services (IAM, WAF, Security Hub, Defender, Sentinel)
  • GCC High or GovCloud experience

Desired Qualifications

  • Experience with container security (Docker, ECS)
  • Working knowledge of Zero Trust Architecture principles
  • Experience building DevSecOps pipelines in regulated environments; familiarity with tools like Prisma, Checkov, Snyk, or Aqua
  • Relevant certifications (any of the following): CISSP, CSSLP, or CASP+
  • OSCP
  • CEH
  • GIAC (GWAPT, GSEC, GWEB) or CCP/CCA (UK Cyber Essentials equivalent)
  • Experience securing microservices or event-driven architectures on ECS
  • Background in federal or cleared environments

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Find similar roles