Senior Security Engineer (FedRAMP)
$237,800–$441,500 year
On-siteSan Jose, California, United States
Job Summary
Champion secure design patterns and supply chain security across VDC's Cloud environments to enable compliance-driven engineering for FedRAMP and regulated industries. Support the design, onboarding, and hardening of new workloads against baselines like STIGs and CIS benchmarks while overseeing vulnerability scanning and remediation tracking. Partner with engineering and SRE teams to review architecture changes, build reusable guardrails, and align roadmaps so controls scale cleanly across frameworks. Participate in a shared on-call rotation to triage and resolve alerts. This role shapes how security engineering scales across VDC's regulated footprint, requiring deep translation of NIST 800-53 controls into concrete architecture decisions.
Required Qualifications
- 8+ years in security engineering
- hands-on experience securing cloud environments
- Experience delivering cloud products to meet regulated compliance requirements such as government (FedRAMP, CMMC, IL2/IL4/IL5, sovereign cloud), financial services (PCI-DSS), and/or healthcare (HIPAA, HITRUST)
- Ability to translate specific compliance controls into concrete architecture and operational decisions
- Working knowledge of NIST 800-53, including continuous monitoring, vulnerability management, and configuration management standards
- Experience hardening infrastructure to secure baselines such as STIGs or CIS benchmarks
- Strong understanding of cloud security fundamentals in identity, network boundaries, encryption, and vulnerability remediation domains
- Ability to learn large, complex platforms quickly with limited guidance
- A collaborative, hands-on approach to partnering across engineering, product, security, compliance, and SRE
- Deep partner mindset: Ability to take a hands-on approach to enable engineering teams rather than serving as gatekeepers
- AI as a force multiplier: AI tools are woven into how we work, and we build security at AI-speed using these tools. We want engineers who treat AI as a force multiplier, not an afterthought
- US citizens
- Security clearance is not required, but there is a slight chance it maybe requested in the future
Desired Qualifications
- strong preference for experience in Azure and/or AWS
- Experience designing and working with controls to satisfy requirements across multiple compliance frameworks
- Hands-on experience with vulnerability scanning tools (e.g. Wiz, Nessus)
- Experience with IaC tools (e.g. Terraform)
- Experience using GitHub for configuration management and change control
- Exposure to supply chain security standards and secure-by-design practices
- Relevant certifications (e.g., CISSP, CCSP, or cloud provider security certs)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.