Security Engineer - Federal (FieldOps)

Socket.dev

Tysons (VA)

On-site

USD 134,000 - 167,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive compensation
Generous equity plan
Excellent benefits

Job summary

C3 AI in Tysons, Virginia, seeks an experienced Federal Security Engineer to own release-gate evidence and ConMon automation for our Federal deployments, ensuring compliance with security standards across the deployment lifecycle. The role requires US Citizenship or US Permanent Residence, with active security clearance preferred.

You will collaborate with product, engineering, and compliance teams to meet STIG, SCAP/OpenSCAP, and FedRAMP requirements while maintaining the integrity of the C3 AI

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • 5+ years of experience in information security, DevSecOps, or a related field.
  • Experience with vulnerability management activities (CVEs, IOCs, etc.).
  • Active DoD 8570 IAT II or above certification (e.g., CISSP or Security+), or ability to obtain.
  • Hands‑on experience with SCAP/OpenSCAP tooling and automated STIG scanning/remediation.

Responsibilities

  • Own per-release gate evidence across the 8 gates defined in the Federal Release-Gate Standard (image CVE disposition, allowlist, SCAP/STIG, FIPS validation, Federal BOM).
  • Work with cross-functional teams to build and maintain ConMon automation: BOM, POA&M classification, and a live ConMon metrics feed
  • Serve as the engineering-level interface with SMX on FedRAMP boundary-register items (image provenance, patch-uplift vs. CA-6, SCAP scope)
  • Address unique Federal customer security requirements without compromising core solution integrity
  • Support high-visibility defense and intelligence projects with stringent security requirements
  • Triage and resolve security vulnerabilities reported by Federal customers
  • Ensure solutions comply with technical security requirements for domain-specific programs (e.g., STIG, SCAP/OpenSCAP)
  • Manage hardened container registries (e.g., Iron Bank, Chainguard) for Federal deployments
  • Work with product, engineering, and compliance teams to upstream controls and resolve issues
  • Overlay customer-specific controls while maintaining C3 AI's standard security posture
  • Discover and remediate security vulnerabilities in Federal systems and applications
  • Collaborate with Information Security, Product, Engineering, and Operations to implement security best practices and ensure compliance with industry standards
  • Stay up-to-date with the latest security trends, vulnerabilities, and technologies

Skills

Security principles
DevSecOps
Vulnerability management
Linux
Scripting
Problem solving
Communication
DoD 8570 IAT II+
SCAP/OpenSCAP tooling

Education

Bachelor's degree in CS/Info Security

Tools

SCAP/OpenSCAP tooling
Stig scanning
Container security tooling

Job description

C3 AI (NYSE: AI), is the Enterprise AI application software company. C3 AI delivers a family of fully integrated products including the C3 Agentic AI Platform, an end-to-end platform for developing, deploying, and operating enterprise AI applications, C3 AI applications, a portfolio of industry-specific SaaS enterprise AI applications that enable the digital transformation of organizations globally, and C3 Generative AI, a suite of domain-specific generative AI offerings for the enterprise. Learn more at: C3 AI

C3 AI is seeking an experienced Federal Security Engineer to serve as the named technical owner of release-gate evidence, Continuous Monitoring (ConMon) automation, and the security engineering interface with our FedRAMP and ATO boundary partner, for our Federal team in Tysons, Virginia. The ideal candidate will ensure Federal deployments meet C3 AI’s rigorous security standards and comply with Federal Security Requirements across the full deployment lifecycle.

This role requires US Citizenship or US Permanent Residence. Active security clearance (Secret or higher) is preferred.

Responsibilities
  • Own per-release gate evidence across the 8 gates defined in the Federal Release-Gate Standard (image CVE disposition, allowlist, SCAP/STIG, FIPS validation, Federal BOM) — no evidence, no GA
  • Work with cross-functional teams to build and maintain ConMon automation: generated Bill of Materials (BOM), automated drainable-vs-structural POA&M classification, and a live ConMon metrics feed
  • Serve as the engineering-level interface with SMX on FedRAMP boundary-register items (image provenance, patch-uplift vs. CA-6, SCAP scope)
  • Address unique Federal customer security requirements without compromising core solution integrity
  • Support high-visibility defense and intelligence projects with stringent security requirements
  • Triage and resolve security vulnerabilities reported by Federal customers
  • Ensure solutions comply with technical security requirements for domain-specific programs (e.g., STIG, SCAP/OpenSCAP)
  • Manage hardened container registries (e.g., Iron Bank, Chainguard) for Federal deployments
  • Work with product, engineering, and compliance teams to upstream controls and resolve issues
  • Overlay customer-specific controls while maintaining C3 AI's standard security posture
  • Discover and remediate security vulnerabilities in Federal systems and applications
  • Collaborate with Information Security, Product, Engineering, and Operations to implement security best practices and ensure compliance with industry standards
  • Stay up-to-date with the latest security trends, vulnerabilities, and technologies
Qualifications
  • Bachelor's degree in Computer Science, Information Security, or a related field
  • Minimum of 5+ years of experience in information security, DevSecOps, or a related field
  • Strong understanding of security principles, practices, and technologies
  • Experience with vulnerability management activities (CVEs, IOCs, etc.)
  • Experience with Linux and scripting languages such as JavaScript, Shell, and/or Python
  • Excellent problem-solving skills and attention to detail
  • Strong communication and collaboration skills
  • Active DoD 8570 IAT II or above certification (e.g., CISSP or Security+), or ability to obtain
  • Hands‑on experience with SCAP/OpenSCAP tooling and automated STIG scanning/remediation
Preferred Qualifications
  • Experience with cloud security and securing cloud-based applications
  • Familiarity with regulatory requirements and industry standards such as NIST 800-53, CMMC, and FedRAMP
  • Experience with security automation and orchestration tools
  • Experience with hardened container registries (e.g., Iron Bank, Chainguard), FIPS 140-2/3 validation, and SBOM generation/traceability tooling

Candidates must be authorized to work in the United States without the need for current or future company sponsorship.

C3 AI provides excellent benefits, a competitive compensation package and generous equity plan.

Virginia Base Pay Range

$134,000 — $167,000 USD

C3 AI is proud to be an Equal Opportunity and Affinity Action Employer. We do not discriminate on the basis of any legally protected characteristics, including disabled and veteran status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer - Federal (FieldOps)
Security Engineer - Federal (FieldOps)

C3.ai, Inc. • Tysons (VA)

On-site
USD 134,000 - 167,000
Federal Security Engineer: Release-Gate & ConMon Expert
Federal Security Engineer: Release-Gate & ConMon Expert

Socket.dev • Tysons (VA)

On-site
USD 134,000 - 167,000
Competitive compensation
Generous equity plan
Excellent benefits
Federal Security Engineer - ConMon & Release Gate Lead
Federal Security Engineer - ConMon & Release Gate Lead

C3.ai, Inc. • Tysons (VA)

On-site
USD 134,000 - 167,000
Senior/Lead Site Reliability Engineer - Federal
Senior/Lead Site Reliability Engineer - Federal

C3.ai, Inc. • Tysons (VA)

On-site
USD 159,000 - 230,000
Security Engineer
Security Engineer

Inadev • Reston (VA)

Hybrid
USD 120,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Peyton Resource Group • Bethesda (MD)

On-site
USD 150,000 - 210,000
Information Systems Security Engineer SME
Information Systems Security Engineer SME

ECS • Stafford (VA)

On-site
USD 120,000 - 150,000
Security Engineer
Security Engineer

Cogent People • Columbia (MD)

Hybrid
USD 100,000 - 140,000
Medical, Dental, and Vision Insurance
401(k) with company match
Company‑paid life insurance
+1
Cyber Security Engineer
Cyber Security Engineer

CACI International Inc • Austin (TX)

On-site
USD 108,000 - 228,000
Security Software Engineer On-site
Security Software Engineer On-site

Eccalon, LLC • Detroit (MI)

On-site
USD 110,000 - 170,000