Mid-Level Security Engineer

RIVA Solutions, Inc.

Alexandria (VA)

On-site

USD 135,000 - 150,000

Full time

45 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

RIVA Solutions, Inc. seeks aSecurity Engineer to perform hands-on security analysis, vulnerability testing, and DevSecOps integration in a large Kubernetes environment for a federal program. You’ll embed automated security gates and coordinate with ServiceNow and SIEM tooling.

The role requires strong GitLab CI/CD, SAST/DAST, Kubernetes security, and collaborative Agile work in a government setting. Salary reflects federal contractor standards and offers growth in a mission-driven team.

Qualifications

  • Bachelor’s degree with 5+ years of cybersecurity experience or Master’s degree with 3+ years of relevant experience.
  • Hands‑on experience with GitLab CI/CD security, SAST/DAST, container image scanning, and IaC security analysis.

Responsibilities

  • Operate and maintain Wiz Code within the USPTO GitLab CI/CD software factory and ensure production is gated by review gates.
  • Run Snyk Agent Scan on AI-native artifacts and triage findings for ServiceNow remediation queue.
  • Maintain and tune Kubernetes security posture across the USPTO container estate and escalate findings through remediation workflow.
  • Correlate DSPM findings with Axonius and Tenable inputs to prioritize remediation.
  • Monitor XSIAM and QRadar SIEM telemetry and contribute to evidence chain for reporting.
  • Perform security audits, risk analysis, and reviews for DSPM and AI platforms such as AWS Bedrock.

Skills

GitLab CI/CD security
SAST/DAST tooling
Container image scanning
IaC security analysis
Kubernetes security
RBAC
Python or Bash
REST API interaction

Education

Bachelor’s degree in cybersecurity
Master’s degree in cybersecurity

Tools

Wiz Code/Defend/DSPM
Snyk Agent Scan
Netskope CASB
Axonius
Tenable
XSIAM
QRadar
ServiceNow

Job description

RESULTS. INNOVATION. VALUES. ACCOUNTABILITY.

That’s RIVA.

We’re a mission-driven IT services company and systems integrator supporting digital transformation and modernization for federal government agencies. Since 2009, we’ve partnered with our customers to solve complex challenges through smart, practical innovation to deliver real outcomes where they matter most. Our teams are made up of industry-leading experts who are passionate about doing great work and making a difference. We don’t just develop solutions, we support efforts that strengthen communities and serve the public good.
RIVA’s culture is built on four core values: Results, Innovation, Values, and Accountability. They guide how we work, how we collaborate, and how we measure success. Our employee-first approach is rooted in trust, ownership, and meaningful work. By investing in our people and fostering a flexible, supportive environment, employees have the opportunity to grow their skills, contribute ideas, and make an impact from day one. all while supporting missions that matter.

POSITION OVERVIEW

This role performs hands‑on security analysis, vulnerability testing, and DevSecOps integration work within the RIVA GitLab CI/CD software factory and the USPTO's approximately 4,000‑container Kubernetes environment. The Security Engineer operates under the guidance of senior security personnel and is a primary contributor to the AI Artifact Security objective (SOO 4.1.3), embedding automated security gates into the pipeline and ensuring findings flow through the ServiceNow SMP remediation workflow.

CORE RESPONSIBILITIES
  • Operate and maintain Wiz Code within the USPTO GitLab CI/CD software factory: configure container image scanning and infrastructure-as-code (IaC) template analysis gates, triage findings, and ensure no code reaches production on a contractor‑only path—every enforcement change ships through USPTO's GitLab review gates
  • Run Snyk Agent Scan on AI‑native artifact types—Markdown prompt files, cursor rules, GitHub Copilot instruction files, and Model Context Protocol (MCP) configuration files—within the GitLab pipeline; triage scan results and route confirmed findings into the ServiceNow SMP remediation queue with appropriate severity tags
  • Maintain and tune Kubernetes security posture across the USPTO container estate: configure admission controls, monitor runtime alerts from Wiz Defend, and escalate container‑level findings through the defined remediation workflow
  • Correlate DSPM findings with Axonius asset context and Tenable vulnerability data to prioritize remediation backlogs; maintain and update the risk‑scored source inventory in coordination with the DSPM SME
  • Monitor XSIAM and QRadar SIEM telemetry for security events correlated to DSPM findings; triage alerts, update the POA&M, and contribute structured findings to the three‑tier evidence chain (operational, compliance, executive reporting)
  • Perform security audits, risk analysis, application‑level vulnerability testing, and security code reviews for the DSPM implementation and integrated AI platforms including AWS Bedrock and UGAP API service broker endpoints
  • Support ATO (Authority to Operate) documentation, system security plan (SSP) maintenance, and FISMA reporting; contribute security evidence to the compliance reporting and dashboard package
  • Participate in Agile sprint ceremonies; contribute to security user stories, acceptance criteria, and definition‑of‑done security checks within the two‑week sprint cadence
MINIMUM QUALIFICATIONS
  • Bachelor’s degree and 5 years of relevant experience, or Master’s degree and 3 years of relevant experience in cybersecurity, information assurance, or a related technical field
  • Hands‑on experience with GitLab CI/CD pipeline security, including SAST/DAST tooling, container image scanning, and IaC security analysis within a DevSecOps software factory
  • Working knowledge of Kubernetes security: admission controllers, runtime scanning, container vulnerability management, and RBAC in a multi‑cloud environment
  • Familiarity with SIEM platforms (XSIAM, QRadar, or equivalent) and ITSM remediation workflows (ServiceNow or equivalent) for security finding triage and POA&M tracking
  • Knowledge of NIST SP 800-53 security controls, FedRAMP requirements, and federal ATO processes; ability to produce structured security evidence for compliance reporting
  • Scripting and automation skills for security engineering: Python or Bash, Git‑based workflows, REST API interaction, GitLab CI YAML pipeline configuration, and the ability to parse and query JSON‑formatted findings for triage and reporting
PREFERRED QUALIFICATIONS
  • Prior experience with Wiz (Code, Defend, or DSPM), Snyk Agent Scan, or Netskope CASB in a federal or FedRAMP-authorized environment
  • Familiarity with Axonius asset management and Tenable vulnerability management as inputs to security risk scoring
  • Experience securing AI serving infrastructure—AWS Bedrock, SageMaker, or API gateway brokering patterns—and understanding of AI artifact security risks (prompt injection, MCP configuration exposure)
  • Additional certifications such as CKS (Certified Kubernetes Security Specialist), AWS Security Specialty, CEH, OSCP, or CompTIA Security+
  • Prior federal civilian agency experience on a cybersecurity, data governance, or DevSecOps program
  • Familiarity with policy‑as‑code and Kubernetes admission control tooling (OPA/Gatekeeper or Kyverno), secrets detection tooling, and SBOM/dependency analysis in CI pipelines

The salary or salary range for this role reflects an estimated range informed by multiple compensation factors. Final offers may vary based on considerations such as relevant experience, education and training, critical skillsets, and overall business needs.

Pay range

$135,000 - $150,000 USD

EQUAL EMPLOYMENT OPPORTUNITY & ACCOMMODATION

We believe great teams are built from different backgrounds, perspectives, and lived experiences, and we mean that beyond the buzzwords.

RIVA is an equal opportunity employer. We welcome applicants of every race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, and any other characteristic protected by law.

If you need an accommodation at any point in our process, send an email to talent@rivasolutionsinc.com, we'll be happy to help.

VETERAN SUPPORT & ACCESSIBILITY

As a federal contractor, RIVA follows the requirements of the Vietnam Era Veterans' Readjustment Assistance Act (VEVRAA) and Section 503 of the Rehabilitation Act, supporting the employment and advancement of protected veterans and individuals with disabilities. If you're a veteran, we encourage you to self‑identify during the application process, it helps us track our hiring commitments and, in some cases, may support priority referral for open roles.

RIVA also invites applicants to voluntarily self‑identify as having a disability during the application process, not because it affects your chances of being hired, but because it helps us measure how well we're living up to our commitments and identify where we can do better. Your response is confidential and entirely optional.

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self‑identification survey.Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiringprocess or thereafter. Any information that you do provide will be recorded and maintained in aconfidential file.

As set forth in RIVA Solutions, Inc.’s Equal Employment Opportunity policy,we do not discriminate on the basis of any protected group status under any applicable law.

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection.As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measurethe effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categoriesis as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Subject Matter Expert (SME) - Data Security & DSPM Implementation
Senior Subject Matter Expert (SME) - Data Security & DSPM Implementation

Riva Solutions Inc • Alexandria (VA)

On-site
USD 175,000 - 200,000
Mid-Level Quality Assurance Specialist
Mid-Level Quality Assurance Specialist

RIVA Solutions, Inc. • Alexandria (VA)

On-site
USD 95,000 - 120,000
Sr. Data Security Solution Architect
Sr. Data Security Solution Architect

Riva Solutions Inc • Alexandria (VA)

On-site
USD 175,000 - 185,000
Mid-Level Security Engineer
Mid-Level Security Engineer

Riva Solutions Inc • Alexandria (VA)

On-site
USD 135,000 - 150,000
Senior Subject Matter Expert (SME) - Data Security & DSPM Implementation
Senior Subject Matter Expert (SME) - Data Security & DSPM Implementation

RIVA Solutions, Inc. • Alexandria (VA)

On-site
USD 175,000 - 200,000
Senior Technical Writer
Senior Technical Writer

RIVA Solutions, Inc. • Alexandria (VA)

On-site
USD 100,000 - 120,000
Senior Technical Writer
Senior Technical Writer

Riva Solutions Inc • Alexandria (VA)

Hybrid
USD 100,000 - 120,000
Mid-Level Quality Assurance Specialist
Mid-Level Quality Assurance Specialist

Riva Solutions Inc • Alexandria (VA)

On-site
USD 95,000 - 120,000
Senior Subject Matter Expert (SME) - AI Governance & Security Policy
Senior Subject Matter Expert (SME) - AI Governance & Security Policy

RIVA Solutions, Inc. • Alexandria (VA)

On-site
USD 175,000 - 200,000
Corporate IT Associate
Corporate IT Associate

Riva Solutions Inc • Reston (VA)

On-site
USD 70,000 - 80,000