Staff Product Security Engineer
Core
Lead federal security strategy, maintain FedRAMP High and DoD IL5 Authority to Operate, and translate federal controls into engineering requirements for commercial developers.
Role type
Staff Product Security Engineer (AppSec)
Builds
Security automation, secure-by-design processes, and controls for containerized production environments.
Domain
Federal government compliance, Cloud Security, Product Security
Deliverable
production ML models | product features | infrastructure
Required skills
FedRAMP authorization process, NIST 800-53, DoD Cloud Computing Security Requirements Guide, Python or Go for security automation, Linux containers internals, threat modeling, SAST/DAST/SCA tooling
Preferred skills
Kubernetes orchestration, Semgrep, Trivy, Burp Suite
Responsibilities
Lead Federal security strategy and support acquisition and maintenance of Authority to Operate at FedRAMP High and DoD IL5 levels. Translate federal controls, including NIST 800-53, into actionable engineering requirements for commercial developers. Write and maintain security policies and procedures, including SSPs, and manage POA&Ms and third-party audit evidence. Build security automation and secure-by-design processes using Python or Go. Design and implement controls for containerized production environments. Deploy and manage SAST, DAST, and SCA security testing tools. Perform threat modeling, prioritize risks, and educate developers on secure coding practices. Engage directly with customer security teams to resolve CVE exposure and architecture concerns.