Security Development Engineering

FSR, LLC.

Herndon (VA)

Hybrid

USD 90,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

FSR, LLC. is looking for a Senior Security Development Engineer to bridge the gap between security and engineering. In this hybrid role, you will serve as a technical contact for security activities that require engineering focus. Your responsibilities will include assisting security teams with vulnerability assessments and ensuring effective communication across various groups.

The ideal candidate will possess a Bachelor's Degree in Computer Science and have experience with vulnerability remediation, cloud environments, and security scanning tools. Strong coding skills and problem-solving capabilities are essential.

Qualifications

  • Experience with best practice identification and response to vulnerabilities.
  • Ability to communicate complex vulnerabilities to varied audiences.
  • Systematic problem-solving approach with strong communication skills.

Responsibilities

  • Serve as senior-level security development engineer interfacing with engineering teams.
  • Assist GRC Control Assurance and SOC Vulnerability Management teams.
  • Participate in assessments/audits, managing escalations and providing guidance.

Skills

Security vulnerability communication
Vulnerability remediation
Cloud environment experience
Code debugging and optimization
Metrics tracking

Education

Bachelor’s Degree in Computer Science / MIS / Information Technology

Tools

Nessus
WebInspect
JIRA
Service Now
Kubernetes

Job description

Job Description

SecDevOps exists to bridge the gap between Security and Engineering. The position serves as the technical points of contact for security related activity that needs engineering or development focus. This position will be a hybrid position, and will require on-site attendance as required (i.e., training, assessment participation, team meetings, etc.).

This role serves as a “hands‑on” senior‑level security development engineer who will be responsible for interfacing with security engineering, operations, security and build teams. This individual will assist the GRC Control Assurance and SOC Vulnerability Management teams with the initial triage of vulnerabilities, using knowledge and experience to produce actionable items for operations, or as necessary, and be point for escalations to Product or Cloud teams. This individual will review other team member responses and use in consideration of the final list. Additionally, this individual will be supporting the various assessments/audits by participating in interviews, managing operation and engineering escalations in support of assessment / audit activities. This can include, but not limited to, providing assistance and guidance on how the security controls are being addressed through automation, configuration or build as well as gathering evidence for the assessors. As required, this individual will also shepherd vulnerabilities and/or findings through the remediation process. This individual is expected to be able to begin work almost immediately based on experience, once provided the environments, procedures and processes. Oversight and guidance will be provided as needed.

Qualifications
  • Bachelor’s Degree in Computer Science / MIS / Information Technology, or equivalent experience in Information Security, Information Technology, or related technical discipline
  • Experience with best practice identification and response to operating system and web application vulnerabilities, such as patching or otherwise mitigating known security issues.
  • Ability to communicate complex security vulnerabilities to various audiences ranging in technical knowledge.
  • Experience with various scanning tools including but not limited to Nessus, WebInspect and/or container scanners such as Clair, Trivy, Grype
  • Exposure to information security standards such as DISA STIGs or CIS. Previous work with immutable image deployments/architecture.
  • Experience leading efforts across multiple groups and security boundaries toward common goals.
  • Ability to debug and optimize code and automate routine tasks.
  • Systematic problem‑solving approach coupled with strong communication skills and a sense of ownership and drive.
  • Experience in tracking and creating various metrics, KPIs or OKRs.
  • Experience with SDLC and Release processes
  • Knowledge with patching and vulnerability remediation processes
  • Ability to adapt to a high‑paced environment and workload
Experience with one or more of the following:
  • C, C ++, Java, Python, Go, Perl, Ruby, or shell scripting.
  • Experience working in a Cloud Environment – AWS, Azure, GCP
  • Experience with JIRA Ticketing System Information Technology
  • Experience with Service Now Ticketing System
  • Experience working with containers or Kubernetes
  • Experience with Unix / Linux/Windows operating system internals and administration (e.g., filesystems, inodes, system calls, hardening) and networking (e.g., TCP / IP, routing, DNS, network topologies, SDN).
  • Understanding and practice with security frameworks such as NIST 800-53, NIST 800-171, SOC 1 or SOC 2, or PCI
  • Knowledge of Best Practice and security guides (ex. NIST 800-53 rev 4, NIST 800-53, FedRAMP)
  • CompTIA Security+ or equivalent certification
Additional Information

Qualified applicants will receive consideration for employment without regard to race, color, religion, gender, national origin, sexual orientation, gender identity, disability or protected veteran status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Application Engineer, Cyber Security
Sr. Application Engineer, Cyber Security

inmar • Winston-Salem (NC)

On-site
USD 120,000 - 180,000
DevSecOps Engineer
DevSecOps Engineer

electro soft • Arlington (VA)

On-site
USD 140,000 - 190,000
DevSecOps Engineer – Information Security
DevSecOps Engineer – Information Security

Jobtailor • Town of Florida (NY)

On-site
USD 150,000 - 190,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Vytalize Health • Kansas (OH)

On-site
USD 120,000 - 160,000
DevSecOps Engineer
DevSecOps Engineer

Socket.dev • Arlington (VA)

On-site
USD 120,000 - 150,000
Security Software Engineer
Security Software Engineer

Eccalon, LLC • Hanover (MD)

On-site
USD 110,000 - 140,000
Security Software Engineer On-site
Security Software Engineer On-site

Eccalon, LLC • Detroit (MI)

On-site
USD 110,000 - 170,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

West Search Partners, LLC • Longmont (CO)

On-site
USD 100,000 - 140,000
Senior Application Security Engineer
Senior Application Security Engineer

Global Solutions Consulting LLC. • Baltimore (MD)

On-site
USD 120,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Hiring Our Heroes • Arlington (VA)

On-site
USD 120,000 - 150,000