Security Software Engineer

Eccalon, LLC

Detroit (MI)

On-site

USD 90,000 - 140,000

Full time

7 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Eccalon, LLC seeks a Security Software Engineer to build and harden software systems supporting DoD programs, complying with CMMC/NIST 800-171 and FedRAMP requirements. You will embed security across the SDLC in a cloud-native AWS/GovCloud and Azure environment.

Design secure software, apply threat modeling, perform code reviews and vulnerability remediation, and automate security gates in CI/CD. Collaboration with DevSecOps and IT teams is essential in this regulated landscape.

Qualifications

  • Bachelor’s degree in Computer Science, Engineering, or a related field (or equivalent experience).
  • 3+ years of software engineering with a security focus.
  • Experience with secure coding practices and frameworks.
  • Familiarity with NIST 800-171, CMMC, or FedRAMP security controls.
  • Hands-on AWS/Azure security services (IAM, WAF, Security Hub, Defender).

Responsibilities

  • Design and develop secure software with a security-first mindset across the SDLC.
  • Apply secure coding standards, threat modeling, and vulnerability mitigation aligned to NIST 800-53 and CMMC.
  • Conduct architecture reviews and code hardening against OWASP Top 10 and DoD STIGs.
  • Automate security gates in CI/CD pipelines (SAST, DAST, dependency scanning, secrets detection).
  • Lead code reviews and vulnerability triage with proper documentation.
  • Collaborate with DevOps to enforce secure IaC, WAF rules, and monitoring.

Skills

Software engineering
Secure coding practices
Threat modeling
Code review
AWS/Azure security

Education

Bachelor's degree in Computer Science or Engineering

Tools

SAST/DAST tools
Prisma
Checkov
Snyk
Aqua

Job description

We are seeking a Security Software Engineer to build and harden software systems supporting DoD programs operating under CMMC/NIST 800-171/FedRAMP compliance requirements. You will embed security across the SDLC—from design and code review through CI/CD and cloud deployment—working alongside engineering, DevSecOps, and IT teams in a regulated, cloud-native environment (AWS Commercial and GovCloud, Azure GCC High).

Responsibilities
Core Engineering & Secure Development
  • Design and develop secure software with a security-first mindset baked into every phase of the SDLC.
  • Apply secure coding standards, threat modeling, and vulnerability mitigation aligned to NIST 800-53 and CMMC Level 2/3 controls.
  • Conduct architecture reviews and code hardening to address OWASP Top 10 and DoD STIGs.
  • Automate security gates in CI/CD pipelines (SAST, DAST, dependency scanning, secrets detection).
Security Architecture & Controls
  • Design secure system and API architectures for multi-tenant cloud environments, including GCC High and FedRAMP-authorized platforms.
  • Implement IAM controls, JIT provisioning, SSO/SAML/OIDC flows, and least-privilege authorization frameworks (e.g., Cognito, Azure AD).
  • Instrument applications with security logging and monitoring that satisfies audit and continuous monitoring requirements (AU/SI control families).
Vulnerability Management & Response
  • Lead code reviews, SAST/DAST scans, and targeted penetration testing; document findings against control frameworks.
  • Triage and remediate vulnerabilities within POA&M timelines; maintain artifact evidence for compliance assessments.
  • Support incident response for application-layer events; contribute to after-action reports and corrective action plans.
Cross-functional Collaboration
  • Serve as the embedded security champion for engineering squads, raising the security bar through mentorship and code review culture.
  • Develop and deliver security training and runbooks tailored to engineering and DevOps team members.
  • Collaborate with DevOps/SRE to enforce secure IaC, WAF rules, network controls, and runtime monitoring across AWS and Azure environments.
Required Qualifications
  • Bachelor’s degree in Computer Science, Engineering, or related field—or equivalent experience.
  • 3+ years of software engineering experience with a strong focus on security.
  • Experience with secure coding practices and frameworks.
  • Strong understanding of application security principles, including:
  • OWASP Top 10
  • Cryptography fundamentals
  • Experience with code scanning tools (SAST/DAST), threat modeling, and penetration testing.
  • Familiarity with NIST 800-171, CMMC, or FedRAMP security control requirements and evidence collection.
  • Hands-on experience with AWS and/or Azure security services (IAM, WAF, Security Hub, Defender, Sentinel); GCC High or GovCloud experience a plus.
Preferred Qualifications
  • Experience with container security (Docker, ECS).
  • Working knowledge of Zero Trust Architecture principles.
  • Experience building DevSecOps pipelines in regulated environments; familiarity with tools like Prisma, Checkov, Snyk, or Aqua.
  • Relevant certifications (any of the following):
  • CISSP, CSSLP, or CASP+
  • OSCP
  • CEH
  • GIAC (GWAPT, GSEC, GWEB) or CCP/CCA (UK Cyber Essentials equivalent)
  • Experience securing microservices or event-driven architectures on ECS; background in federal or cleared environments preferred.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Engineer
Senior Security Engineer

Zermount, Inc. • United States Virgin Islands

On-site
USD 100,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Hiring Our Heroes • Arlington (VA)

On-site
USD 120,000 - 150,000
Security Software Engineer On-site
Security Software Engineer On-site

Eccalon, LLC • Detroit (MI)

On-site
USD 120,000 - 170,000
Benefits package
Cyber Security Engineer
Cyber Security Engineer

Qualibar • United States

Hybrid
USD 120,000 - 180,000
Cybersecurity/Technical Engineer
Cybersecurity/Technical Engineer

UNAVAILABLE • McLean (VA)

On-site
USD 120,000 - 170,000
Senior InfoSec Engineer (SecDevOps) / New York
Senior InfoSec Engineer (SecDevOps) / New York

DigitalXNode • New York (NY)

On-site
USD 180,000 - 240,000
Restaurant d'entreprise
Indemnités de stage/alternance
Cloud Security Engineer
Cloud Security Engineer

apex-technology-inc • Los Angeles (CA)

On-site
USD 180,000 - 240,000
Senior Security Engineer
Senior Security Engineer

Prestige Staffing • Georgia

On-site
USD 140,000 - 200,000
Security Software Engineer
Security Software Engineer

Eccalon LLC • Hanover (MD)

On-site
USD 110,000 - 170,000
Security Assurance Engineer
Security Assurance Engineer

Tier4 Group • Boston (MA)

On-site
USD 120,000 - 160,000