Security Engineer
Core
Security Engineer responsible for hardening cloud environments, managing ATO processes, and driving down the POAM backlog for federal software products.
Role type
Senior IC Security Engineer (DevSecOps)
Builds
Hardened cloud infrastructure and compliant federal software delivery pipelines
Domain
Federal government / Cloud Security / DevSecOps
Required skills
AWS cloud security, CI/CD pipeline automation, Infrastructure as Code (IaC), Zero Trust architecture, POAM management, Security Impact Analysis (SIA), ATO process navigation, Docker/containerization
Preferred skills
Serverless patterns, FISMA/NIST 800-53 framework expertise
Responsibilities
Deploy and automate CI/CD pipelines using serverless and Zero Trust patterns; Own the POAM process end-to-end including planning and remediation tracking; Assess security findings and develop LOEs for remediation; Conduct Security Impact Analyses (SIAs) to maintain ATO; Implement data tagging and sensitivity management; Maintain live dashboards for security findings and POAM status; Engage with engineers and stakeholders to drive remediation.
Seniority
Senior, hands-on IC