Security Engineer

UNAVAILABLE

McLean (VA)

On-site

USD 120,000 - 170,000

Full time

8 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Steampunk is seeking a Security Engineer to support a government customer. You will be the technical expert guiding teams to resolve vulnerabilities, maintain security authorizations, and drive remediation across systems.

The role emphasizes DevSecOps collaboration, threat assessment, and adherence to DHS/FISMA/NIST standards, with opportunities to code and build automation tools for compliance. Strong communication and a customer-service mindset are essential.

Qualifications

  • Knowledge of security concepts, practices, and procedures for secure system operation.
  • Experience evaluating security controls against FISMA, FIPS, and NIST requirements.
  • Experience with vulnerability scanning execution, assessment, and analysis.

Responsibilities

  • Review the security architecture of new systems, applications, and technologies to identify and mitigate risks.
  • Recommend mitigation measures and advise on design trade-offs, balancing risk and cost.
  • Monitor DHS ISVM alerts and drive remediation with system teams.
  • Update POA&Ms and track weaknesses to scheduled closures.
  • Evaluate waivers and risk acceptance memos with practical technical judgment.
  • Monitor gates in the System Lifecycle Management process and brief customer on risks before system readiness.
  • Participate in DevSecOps activities to integrate security in Agile/DevOps processes.
  • Ensure security requirements are included throughout development lifecycles (Waterfall, Agile, DevSecOps).
  • Ensure CM processes to avoid introducing new risks.
  • Conduct annual DHS IS performance plan assessments and update security docs as needed.
  • Perform system self-assessments for the Ongoing Authorization program.
  • Provide audit support for systems (FISMA, DHS, OMB, etc.).
  • Maintain knowledge of hardware/software inventory within authorization boundaries.
  • Use DHS-mandated IA compliance tools.

Skills

Security concepts
Vulnerability assessment
Application security
Network security
Splunk
Cloud engineering
DevOps
Scripting
Risk management
Communication skills

Education

No degree, 8 years experience
Bachelor's degree + 4 years experience
Master's degree + 1 year experience

Tools

Splunk

Job description

Overview

Steampunk is searching for a Security Engineer to support a government customer. This role is a strong fit for hands‑on engineers, including software developers, system administrators, and technical subject matter experts, who want to apply their technical depth to cybersecurity. Your primary responsibility will be to ensure that the security posture documented in each system's security authorization is implemented and maintained at an acceptable level of risk. Success in this role takes initiative, organization, a customer-service mindset, and the flexibility to adapt in a fast‑paced, fluid environment. You'll communicate clearly and decisively with all levels of the organization, solve practical problems, and exercise sound judgment with sensitive and confidential information.As a Security Engineer, you'll be the technical expert that development and operations teams rely on to resolve vulnerabilities. Your experience building software or running systems is what makes you effective: you'll understand what a finding means in the code or configuration, separate real risk from noise, and recommend fixes that teams can realistically implement. Rather than performing remediation yourself, you'll typically guide teams through it, tracking issues to closure and keeping systems compliant with federal requirements. If you want to keep coding, you'll find regular opportunities to do so, from building tools that automate compliance work to reviewing code (including AI-generated code) for vulnerabilities and validating fixes. You'll also have access to the latest AI models to speed up development and vulnerability responses.

Responsibilities
  • Review the security architecture of new systems, applications, and technologies, drawing on your development and infrastructure experience to identify and mitigate potential risks
  • Recommend appropriate mitigation measures and advise on design trade-offs, weighing potential impact against cost and benefit
  • Monitor and respond to DHS Information Security Vulnerability Management (ISVM) alerts, working with system teams to analyze vulnerabilities and drive them to remediation
  • Proactively monitor and update Plans of Action and Milestones (POA&Ms), working with developers and administrators to resolve weaknesses by their scheduled completion dates
  • Evaluate waivers and risk acceptance memos, bringing technical judgment to the management of system risk
  • Monitor the gates in the System Lifecycle Management (SLM) process and brief the customer on outstanding issues and risks before concurrence on system readiness
  • Participate in DevSecOps activities for assigned systems, helping teams integrate security into their Agile and DevOps processes
  • Proactively ensure security requirements are included throughout the development lifecycle (Waterfall, Agile, or DevSecOps)
  • Ensure configuration management (CM) processes are followed so that changes do not introduce new security risks
  • Conduct an annual assessment in accordance with the DHS Information Security Performance Plan
  • Review and update security authorization documents as needed and on the required schedule
  • Perform system self‑assessments as part of the customer's Ongoing Authorization program
  • Provide audit support for assigned systems (financial, OMB Circular A-123, FISMA, DHS, internal, and others) before, during, and after each audit
  • Maintain knowledge of the hardware and software inventory within authorization boundaries
  • Use DHS‑mandated enterprise information assurance (IA) compliance tools
Qualifications
  • Ability to obtain a U.S. government Security Clearance
  • No degree and 8 years of relevant experience; OR
    • Bachelor's degree and 4 years of relevant experience; OR
    • Master's degree and 1 year of relevant experience
  • Must hold at least one professional certification relevant to the technical services provided
  • Demonstrated knowledge of security concepts, practices, and procedures that ensure the secure integration and operation of systems
  • Specialized knowledge and experience evaluating system, network, or infrastructure security controls against FISMA, FIPS, and NIST requirements
  • Knowledge and experience with vulnerability scanning execution, assessment, and analysis
  • Knowledge and experience with application security, database security, and network security
  • Knowledge and experience using Splunk in an enterprise environment
  • Ability to assess and weigh current and evolving security threats in an operational environment
  • Excellent communication and interpersonal skills, including the ability to explain technical risk to both engineers and non-technical stakeholders

Preferred

  • Hands‑on background in software development, system administration, or DevOps engineering
  • An information technology certification related to your subject matter expertise, such as a security certification (e.g., CISSP, CGRC, CSSLP, CCSP, CompTIA Security+ or SecurityX), a development certification (e.g., Oracle Certified Professional: Java SE Developer, AWS Certified Developer – Associate), or a systems or cloud certification (e.g., RHCE, CKA, AWS Certified Security – Specialty)
  • Proven experience as an Information Security Engineer, including current experience providing security support to DHS
  • In-depth knowledge of federal cybersecurity regulations and standards
  • Experience with scripting and automation (e.g., Python, PowerShell, or Bash)
  • Strong understanding of security infrastructure, risk management, and compliance
  • Proficiency in security tools, technologies, and best practices
  • Extensive specialized knowledge of cloud engineering or application design and development, with experience supporting systems hosted in cloud environments
  • Knowledge and experience with operating systems and network engineering (e.g., LAN and WAN)
  • Experience supporting systems and applications in Agile and DevOps environments
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Engineer
Information Security Engineer

eTrepid • Mechanicsville (MD)

On-site
USD 90,000 - 130,000
Principal Information Systems Security Officer
Principal Information Systems Security Officer

UNAVAILABLE • McLean (VA)

On-site
USD 140,000 - 190,000
Senior Security Engineer
Senior Security Engineer

Zermount, Inc. • United States Virgin Islands

On-site
USD 100,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Hiring Our Heroes • Arlington (VA)

On-site
USD 120,000 - 150,000
Systems Engineer with Security Clearance
Systems Engineer with Security Clearance

Executive Management Services, Inc. • Union City (OH)

On-site
USD 110,000 - 150,000
System Security Engineer
System Security Engineer

Cymertek Corporation • San Antonio (TX)

On-site
USD 110,000 - 150,000
Cyber Security Systems Engineer
Cyber Security Systems Engineer

VT Group (VTG) • Chantilly (VA)

On-site
USD 140,000 - 210,000
Cybersecurity/Technical Engineer
Cybersecurity/Technical Engineer

UNAVAILABLE • McLean (VA)

On-site
USD 120,000 - 170,000
Cyber Data Science Engineer
Cyber Data Science Engineer

TENICA and Associates LLC • Springfield (VA)

On-site
USD 80,000 - 100,000
ME00619-ISSE 2
ME00619-ISSE 2

Rippling, Inc. • Annapolis (MD)

On-site
USD 120,000 - 180,000
11 paid holidays
3 weeks PTO
Group medical plan
+1