Security Software Engineer

Eccalon, LLC

Hanover (MD)

On-site

USD 110,000 - 140,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Eccalon, LLC is seeking a Security Software Engineer to design and harden software for DoD programs under CMMC/NIST 800-171 compliance. You will embed security across the SDLC—design, code review, and CI/CD—while collaborating with engineering, DevSecOps, and IT in AWS GovCloud and Azure GCC High environments.

You will lead vulnerability management, implement IAM and SSO, and contribute to incident response with a strong focus on secure architecture and compliance.

Qualifications

  • Bachelor’s degree in Computer Science, Engineering, or related field—or equivalent experience.
  • 3+ years of software engineering experience with a strong focus on security.
  • Experience with secure coding practices and frameworks.
  • Familiarity with NIST 800-171, CMMC, or FedRAMP security control requirements and evidence collection.
  • Hands-on experience with AWS and/or Azure security services (IAM, WAF, Security Hub, Defender, Sentinel); GCC High or GovCloud experience a plus.
  • Knowledge of OWASP Top 10 and threat modeling.

Responsibilities

  • Design and develop secure software with a security-first mindset across the SDLC.
  • Apply secure coding standards, threat modeling, and vulnerability mitigation aligned to NIST 800-53 and CMMC controls.
  • Conduct architecture reviews and code hardening to address OWASP Top 10 and DoD STIGs.
  • Automate security gates in CI/CD pipelines (SAST, DAST, dependency scanning, secrets detection).
  • Design secure system and API architectures for multi-tenant cloud environments including GCC High and FedRAMP platforms.
  • Implement IAM controls, SSO flows, least-privilege authorization; instrument apps for security logging and monitoring.

Skills

Security engineering
Secure coding
OWASP Top 10
Threat modeling
SAST/DAST tooling
Cloud security (AWS/Azure)
CI/CD security gates
Familiar with NIST 800-171/CMMC/FedRMP

Education

Bachelor’s degree in CS/Engineering or related field

Tools

AWS security services
Azure security services
GCC High/GovCloud
SAST/DAST tools (e.g., Snyk, Checkov, Prisma, Aqua)

Job description

We are seeking a Security Software Engineer to build and harden software systems supporting DoD programs operating under CMMC/NIST 800-171/FedRAMP compliance requirements. You will embed security across the SDLC—from design and code review through CI/CD and cloud deployment—working alongside engineering, DevSecOps, and IT teams in a regulated, cloud-native environment (AWS Commercial and GovCloud, Azure GCC High).

Responsibilities
Core Engineering & Secure Development
  • Design and develop secure software with a security-first mindset baked into every phase of the SDLC.
  • Apply secure coding standards, threat modeling, and vulnerability mitigation aligned to NIST 800-53 and CMMC Level 2/3 controls.
  • Conduct architecture reviews and code hardening to address OWASP Top 10 and DoD STIGs.
  • Automate security gates in CI/CD pipelines (SAST, DAST, dependency scanning, secrets detection).
Security Architecture & Controls
  • Design secure system and API architectures for multi-tenant cloud environments, including GCC High and FedRAMP-authorized platforms.
  • Implement IAM controls, JIT provisioning, SSO/SAML/OIDC flows, and least-privilege authorization frameworks (e.g., Cognito, Azure AD).
  • Instrument applications with security logging and monitoring that satisfies audit and continuous monitoring requirements (AU/SI control families).
Vulnerability Management & Response
  • Lead code reviews, SAST/DAST scans, and targeted penetration testing; document findings against control frameworks.
  • Triage and remediate vulnerabilities within POA&M timelines; maintain artifact evidence for compliance assessments.
  • Support incident response for application-layer events; contribute to after-action reports and corrective action plans.
Cross-functional Collaboration
  • Serve as the embedded security champion for engineering squads, raising the security bar through mentorship and code review culture.
  • Develop and deliver security training and runbooks tailored to engineering and DevOps team members.
  • Collaborate with DevOps/SRE to enforce secure IaC, WAF rules, network controls, and runtime monitoring across AWS and Azure environments.
Required Qualifications
  • Bachelor’s degree in Computer Science, Engineering, or related field—or equivalent experience.
  • 3+ years of software engineering experience with a strong focus on security.
  • Experience with secure coding practices and frameworks.
  • Strong understanding of application security principles, including:
  • OWASP Top 10
  • Cryptography fundamentals
  • Experience with code scanning tools (SAST/DAST), threat modeling, and penetration testing.
  • Familiarity with NIST 800-171, CMMC, or FedRAMP security control requirements and evidence collection.
  • Hands-on experience with AWS and/or Azure security services (IAM, WAF, Security Hub, Defender, Sentinel); GCC High or GovCloud experience a plus.
Preferred Qualifications
  • Experience with container security (Docker, ECS).
  • Working knowledge of Zero Trust Architecture principles.
  • Experience building DevSecOps pipelines in regulated environments; familiarity with tools like Prisma, Checkov, Snyk, or Aqua.
  • Relevant certifications (any of the following):
  • CISSP, CSSLP, or CASP+
  • OSCP
  • CEH
  • GIAC (GWAPT, GSEC, GWEB) or CCP/CCA (UK Cyber Essentials equivalent)
  • Experience securing microservices or event-driven architectures on ECS; background in federal or cleared environments preferred.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Software Engineer On-site
Security Software Engineer On-site

Eccalon, LLC • Detroit (MI)

On-site
USD 110,000 - 170,000
DevSecOps Engineer
DevSecOps Engineer

Socket.dev • Arlington (VA)

On-site
USD 120,000 - 150,000
SecDevOps Engineer
SecDevOps Engineer

Jobtailor • Colorado

On-site
USD 150,000 - 190,000
Sr. Application Engineer, Cyber Security
Sr. Application Engineer, Cyber Security

inmar • Winston-Salem (NC)

On-site
USD 120,000 - 180,000
Senior Security Engineer
Senior Security Engineer

Zermount, Inc. • United States Virgin Islands

On-site
USD 100,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Hiring Our Heroes • Arlington (VA)

On-site
USD 120,000 - 150,000
Security Development Engineering
Security Development Engineering

FSR, LLC. • Herndon (VA)

Hybrid
USD 90,000 - 130,000
Information Systems Security Engineer
Information Systems Security Engineer

Jobtailor • King of Prussia (PA)

On-site
USD 120,000 - 170,000
Senior Security Engineer
Senior Security Engineer

Zermount, Inc. • United States

On-site
USD 120,000 - 150,000
Security Architect
Security Architect

thyssenkrupp • Southfield (MI)

On-site
USD 130,000 - 185,000