Lead Security Engineer

Dev Technology Group

Bowie (MD)

On-site

USD 120,000 - 190,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Dev Technology Group is seeking a Subject Matter Expert–level Lead Security Engineer to lead application security across a large-scale, cloud-native federal modernization program in Suitland, MD. You will architect Zero Trust, drive ATO activities, and oversee SAST/DAST testing, threat modeling, and remediation within a DevSecOps SDLC.

You will collaborate with senior government stakeholders and the Office of Information Security to embed security into every phase of development, and may

Qualifications

  • Lead security in DevSecOps SDLC with CI/CD gates.
  • Implement Zero Trust for apps, workloads and data.
  • Direct SAST/DAST and threat modeling activities.
  • Support ATO processes and POA&M management.
  • Experience with NIST CSF and NIST 800-53 controls.

Responsibilities

  • Lead design and implementation of application security across all SDLC phases.
  • Apply Zero Trust architecture for applications, data, and workloads.
  • Integrate security into DevSecOps pipelines with SBOM generation.
  • Oversee vulnerability testing and remediation (SAST/DAST).
  • Drive threat modeling and document mitigation strategies.
  • Support ATO activities, evidence collection, and POA&M tracking.
  • Collaborate with developers, data engineers, and OIS stakeholders.

Skills

SME leadership
Zero Trust
DevSecOps
Threat modeling
SAST/DAST
ATO/POA&M
NIST 800-53
NIST CSF
SBOM
FedRAMP
Cloud security

Education

Bachelor's degree in IT/CS/Cybersecurity

Tools

SIEM

Job description

Security Requirement: U.S. Citizenship required

Work Location:Suitland, MD

We are seeking a Subject Matter Expert (SME)–level Lead Security Engineer to lead application security across a large-scale, cloud-native federal modernization program. This role provides technical and management leadership on major security tasks, embedding security into every phase of the System Development Life Cycle (SDLC) using a DevSecOps methodology. The ideal candidate will architect and enforce Zero Trust principles, drive Authorization to Operate (ATO) activities, and directapplicationsecurity testing, threat modeling, and vulnerability remediation across a System of Systems (SoS). This positioninterfaces withsenior Government stakeholders and the Office of Information Security (OIS), and decision-making and domain knowledge may have a critical impact on overall program implementation. May supervise others.

What You'll be Doing:
  • Lead the design and implementation of a pplication security solutions, frameworks, and processes across all phases of the SDLC
  • Implement Zero Trust (ZT) principles for applications, workloads, and data, aligned with EO 14028, OMB M-22-09, and NIST SP 800-207 (Zero Trust Architecture)
  • Integrate security into DevSecOpsCI/CD pipelines , establishing security gates, automated code inspection, and supply-chain controls, including Software Bill of Materials (SBOM) generation
  • Direct Static and Dynamic Application Security Testing (SAST/DAST) , vulnerability assessments, and penetration testing toidentify, triage, and remediate security weaknesses
  • Lead threat modeling exercises to analyze application architecture,identifyattack vectors, and document mitigation strategies throughout design, development, testing, and deployment
  • Support the Authorization to Operate (ATO) process, including security control assessment, artifact and evidence collection, Privacy Threshold Analysis/Privacy Impact Assessment support, and Plan of Action and Milestones (POA&M) management
  • Implement security controls in accordance with the NIST Cybersecurity Framework and NIST SP 800-53 , and remediate identified vulnerabilities and compliance findings
  • Design and implement secure architecture patterns — secure API design, authentication/authorization, input validation, encryption, secure logging and monitoring (SIEM), and secure error/session/configuration management
  • Develop and maintain metrics, dashboards, and reporting to track application security posture, threat trends, and remediation progress over time
  • Support the development and management of Interagency Security Agreements (ISA) , security playbooks, and incident responsein accordance withcurrent cybersecurity policies
  • Collaborate with application developers, data engineers, systems engineers, and OIS to identify and mitigate vulnerabilities, and provide expert security consultation to development teams
  • Assist in FedRAMP certification activities and the assessment/remediation of independent penetration testing results, as applicable
Required Education, Experience, and Skills:
  • Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or a related field
  • 15+ years of relevant IT/cybersecurity experience, providing technical and management leadership on major tasks or technology assignments (SME level)
  • Certified Information Systems Security Professional (CISSP)
  • Certified Cloud Security Professional (CCSP)
  • Demonstrated expertise in integrating security into a DevSecOps SDLC, including CI/CD security gates and automated security testing
  • Hands‑on experience implementing Zero Trust Architecture and applying NIST SP 800-53 controls and the NIST Cybersecurity Framework
  • Proven experience leading vulnerability assessments, penetration testing, and threat modeling for enterprise applications
  • Experience supporting the ATO lifecycle and managing POA&Ms, security artifacts, and evidence collection
Preferred Skills and Experience:
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Auditor (CISA)
  • Experience generating Software Bill of Materials (SBOMs) and implementing software supply‑chain security controls
  • Familiarity with SIEM deployment, container/image hardening, and secure baseline configuration
  • Experience in large‑scale, multi‑cloud federal environments and FedRAMP processes
  • Strong analytical, problem‑solving, written, and verbal communication skills, including the ability to brief senior Government stakeholders

Our estimated salary range for this position is $120,000 - $190,000; this presented salary range is not a guarantee of compensation or salary. Offered salary is based on experience, geographic location, and possibly contractual requirements as appropriate to the role. *Salary could fall outside of this range.

Who We Are

Dev Technology is a growing IT company with an employee‑centric culture that works on mission‑critical projects for the federal government. We partner with our federal customers to deliver technology services and solutions, and to drive our client’s missions forward through innovation. We use Agile and DevSecOps principles to provide services including application development, biometrics and identity management, cloud and infrastructure optimization, IT and legacy modernization, and data management.

As a Washington Post Top Workplace award winner for the past THIRTEEN years in a row, the Top Workplaces USA for the past five years, and a recipient of the Companies As Responsive Employers (CARE) Award for the past six years, Dev Technology employees enjoy:

  • Generous and flexible time‑off policy
  • Flexible work schedules and telework options, including remote work availability for eligible projects
  • Career development opportunities including a mentorship program, technical and management training through Dev University, hands‑on learning through DevLab, tuition reimbursement, and paid training opportunities
  • Industry‑leading benefits including a choice of two health plans that include dental and vision, flexible spending account, commuter benefits, life insurance, and more
  • 401K matching with a 5% matching contribution
  • Regular team and company social events including our annual party, happy hours, fitness challenges, and more
  • A focus on community engagement including company wide support activities, employer match for donations, and time off for volunteer efforts

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans

Dev Technology Group operates in the following states: AL, AR, AZ, CO, DC, FL, GA, ID, IL, IN, MD, MA, ME, MI, MN, MO, MS, NC, NJ, OH, OR, PA, SC, TN, TX, VA, WV.
SMS Terms and Privacy Notice

Dev Technology Group offers you the option to engage in SMS text conversations about your job application. By participating, you also understand that message frequency may vary depending on the status of your job application, and that message and data rates may apply. Please consult your carrier for further information on applicable rates and fees. Carriers are not liable for delayed or undelivered messages. Reply STOP to cancel and HELP for help. By opting‑in to receiving SMS text messages about your job application, you acknowledge and agree that your consent data, mobile number, and personal information will be collected and stored solely for the purpose of providing you with updates and information related to your job application. No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All the above categories exclude text messaging originator opt‑in data and consent; this information will not be shared with any third parties.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Security Engineer
Lead Security Engineer

Dev Technology Group, Inc. • Suitland (MD)

On-site
USD 120,000 - 190,000
Lead Security Engineer
Lead Security Engineer

Dev Technology Group • Fort Washington (MD)

On-site
USD 120,000 - 190,000
Remote work options
401K matching
Generous PTO
+1
Lead Security Engineer
Lead Security Engineer

Dev Technology Group • Silver Spring (MD)

On-site
USD 120,000 - 190,000
Generous time off
Flexible work schedules / telework
Mentorship program
+5
Lead Security Engineer
Lead Security Engineer

Dev Technology • Suitland (MD)

On-site
USD 120,000 - 190,000
Generous time-off policy
Flexible work schedules
401K matching
+1
Senior Director
Senior Director

Dev Technology Group • Reston (VA)

On-site
USD 135,000 - 200,000
Generous time-off policy
Flexible work options / telework
Tuition reimbursement
+2
Senior Director
Senior Director

Socket.dev • Reston (VA)

Hybrid
USD 135,000 - 200,000
Telework options
401K matching
Generous time-off policy
+1
Lead Application Architect
Lead Application Architect

Dev Technology Group • Silver Spring (MD)

On-site
USD 120,000 - 180,000
Generous time-off policy
Telework options
Health plans
+2
Mid-Level Full Stack Developer (.Net and Azure)
Mid-Level Full Stack Developer (.Net and Azure)

Socket.dev • Herndon (VA)

Hybrid
USD 90,000 - 130,000
Flexible work schedules
Remote work options
Mentorship program
+2
Senior Technical Business Analyst
Senior Technical Business Analyst

Dev Technology Group, Inc. • Washington

Hybrid
USD 80,000 - 140,000
Flexible time-off policy
Flexible work schedules and remote-ops
Mentorship program
+6
Lead Application Architect
Lead Application Architect

Dev Technology Group • Maryland

On-site
USD 120,000 - 180,000
Generous time-off policy
Flexible telework options (in eligible
401K matching