Security Engineer

Socket.dev

Washington (District of Columbia)

On-site

USD 90,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Acuity, Inc. is looking for a Security Engineer to support federal agencies in Washington, DC. The role involves administering various security tools, overseeing incident responses, and ensuring compliance with security standards.

Candidates must possess hands-on technical expertise with Fortify SSC, hold an active security certification, and have at least five years of experience. A competitive salary and dynamic work environment await the successful applicant.

Qualifications

  • Hands-on expertise with Fortify SSC and other security tools.
  • Active certification such as CISSP or equivalent required.
  • Minimum five years of relevant experience in security engineering.

Responsibilities

  • Administer security tools and applications.
  • Field troubleshooting questions for developers and users.
  • Assist with incident response actions for cloud security.

Skills

Hands-on expertise with Fortify SSC
Cloud security understanding
API security knowledge
Container/orchestration tools knowledge
Programming languages knowledge (Python, Java)

Education

Active certification (CISSP, CEH, CISM, etc.)
Minimum of 5 years in security engineering

Tools

Jenkins
Ansible
Terraform
Excel and Access

Job description

Overview

Looking to make a difference, to help keep people safe, or even to save lives through your work with technology? Join Acuity’s team of experts to have an impact on our government’s critical missions. Acuity, Inc. is a consulting firm that supports federal agencies in the areas of IT Modernization, Data Enablement, and Hyperautomation. We are currently hiring for a Security Engineer.

Responsibilities
  • Provide hands‑on technical subject matter expertise with respect to setting up and administering Fortify SSC, Fortify Security Assistant IDE Plugin, OWASP ZAP, and Audit Workbench. Anticipate expanding to SonaType.
  • Administer applications and users.
  • Fieldtroubleshooting questions for developers (i.e., connections to pipelines)
  • Fieldtroubleshooting questions for front‑end users (testers, security analysts -- "is this a false positive?", etc)
  • Work with Project teams to review vulnerabilities.
  • Familiar with Windows Server.
  • Work autonomously in an area of specialization to analyze internal security and provide relevant information to internal and external customers, suppliers, and partners.
  • Have skill sets to perform computer incident response and remediation practices as outlined in NIST 800‑61 (Computer Security Incident Handling Guide) and DHS 4300A Sensitive Systems Policy Handbook, Attachment F Incident Response. The staff will assist the Security Operation Center (SOC) on incident response actions for security incidents affecting the Cloud environment.
  • Assist with the implementation of monitoring capabilities for various audiences – developers, business owners, security, and infrastructure; analyze all platform level, network changes and monitor impact and provide appropriate technical solutions to resolve issues efficiently; evaluate and document operating baseline according to required standards.
  • Perform other duties as assigned by the Government.
Qualifications
  • Must have hands‑on expertise with respect to setting up and administering Fortify SSC, Fortify Security Assistant IDE Plugin, OWASP ZAP, and Audit Workbench
  • Have and maintain at least one active certification such as CISSP, CCISSP, CEH, CISM, CISA, Cloud+, CCSP, or other comparable certification which must be approved in advance by the Government PM (on a case‑by‑case basis)
  • Minimum of five (5) years of experience in security engineering or security operations
  • Experience in security process mapping, security process analysis, security process improvement concepts, models, and best practices
  • Experience with cloud Platform as a Service (PaaS), Software as a Service (SaaS) and other cloud services
  • Experience with Continuous Integration (CI)/Continuous Delivery (CD) - Deployment pipeline experience (Jenkins, Ansible, Terraform)
  • Experience or a strong knowledge of Data at Rest Application Programing Interface (API) design
  • Experience or a strong knowledge of programming languages (Python, Java etc.)
  • Experience or a strong knowledge of container/orchestration tools (Kubernetes, Docker, Puppet, etc)
  • Have a deep understanding of API Security, Container Security, Cloud Security
  • Advanced Microsoft Excel and Access skills to perform extensive data mining, correlation, and reporting
  • Contractor shall be staffed in the Washington, DC metropolitan area, unless explicitly approved by the Government PM
  • Experience working with NIST SP 800‑53, RMF, FISMA, DHS and DoD policies
  • Some other tools besides Fortify that if they appear on the candidate’s experience could be reasonable substitutes:
    • CAST
    • Code Compare
    • CodeScene Behavioral Code Analysis
    • CodeSonar
    • Coverity
    • Embold
    • Fortify Static Code Analyzer
    • Parasoft
    • PVS‑Studio
    • Raxis
    • reshift
    • RIPS Technologies
    • SmartBear Collaborator
    • Understand
    • Visual Expert
    • Veracode
  • Excellent customer service, analytical, problem solving, team‑building, and interpersonal skills
  • Ability to work independently and function as an integral part of the team
  • Excellent oral and written communication skills; technical and business focused, with the ability to document and describe security process information collected
  • Listening skills, the ability to detect explicit and implicit needs and wants
  • Demonstrated ability to exercise good judgment, prioritize multiple tasks, and problem solve under pressure of deadlines and resource constraints
  • Proven experience in building consensus and managing cross‑functional teams
Clearance Requirements
  • Must have an Active Secret clearance or higher.

Acuity is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer
Senior Security Engineer

Hiring Our Heroes • Arlington (VA)

On-site
USD 120,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Zermount, Inc. • United States Virgin Islands

On-site
USD 100,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Zermount, Inc. • United States

On-site
USD 120,000 - 150,000
Security Engineer
Security Engineer

Linuxconfig • United States

On-site
USD 100,000 - 204,000
Principal Information Security Engineer
Principal Information Security Engineer

Clarity Innovations • Fort Meade (MD)

On-site
USD 117,000 - 292,000
Security Development Engineering
Security Development Engineering

FSR, LLC. • Herndon (VA)

Hybrid
USD 90,000 - 130,000
Information Security Engineer
Information Security Engineer

eTrepid • Mechanicsville (MD)

On-site
USD 90,000 - 130,000
Security Engineer
Security Engineer

Acuity, Inc. • Maryland

On-site
USD 108,000 - 221,000
Training & certification budget (up to
Degree-seeking support (up to $3,000)
Application Security Architect & Engineer
Application Security Architect & Engineer

Mbi Llc • Richmond (VA)

On-site
USD 120,000 - 150,000
Mid Cyber Security Engineer
Mid Cyber Security Engineer

Chenega Corporation • Vienna (VA)

On-site
USD 90,000 - 120,000