Senior Product Security Engineer – Secure DevOps

Via Logic LLC

United States

Remote

USD 87,000 - 157,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Leidos is seeking a Senior Product Security Engineer to support a portfolio of shared software platforms across Ports & Borders and Aviation missions. This senior, hands-on contributor will work with Enterprise Products engineering and partner with cybersecurity leadership, software, DevOps, and infrastructure teams to implement secure-by-default solutions.

The role emphasizes translating standards into actionable security requirements, integrating security tooling into CI/CD pipelines, threat

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Computer Engineering, Software Engineering, Information Systems, or a related technical discipline with 8+ years of relevant experience; or a master's degree with 6+ years of relevant experience.
  • Experience integrating security into software development lifecycle activities, including requirements, architecture, implementation, testing, build, deployment, and sustainment.
  • Experience performing threat modeling, application or API security reviews, security architecture reviews, or secure design assessments.
  • Experience implementing or integrating security tooling into CI/CD pipelines, such as SAST, SCA, secret scanning, container scanning, or infrastructure-as-code analysis.
  • Experience securing Linux-based systems, containerized applications, or Kubernetes-based deployment environments.
  • Experience performing vulnerability assessments, analyzing findings, developing remediation guidance, and communicating technical risk.
  • Experience developing scripts or automation using Python, Bash, PowerShell, or another applicable programming language.
  • Working knowledge of OWASP application security risks and one or more security frameworks or baselines, such as NIST SP 800-53, NIST SP 800-171, CMMC, RMF, DISA STIGs, or CIS Benchmarks.
  • Ability to work independently across multiple technical disciplines while collaborating effectively with engineering, cybersecurity, program, and customer stakeholders.
  • Strong written and verbal communication skills, including the ability to document technical decisions and explain security risks, recommendations, and tradeoffs.
  • Ability to obtain and maintain the public trust or security clearance required by assigned programs.
  • Active certification meeting applicable DoD 8140 or customer requirements, or ability to obtain the required certification within 6 months of employment.

Responsibilities

  • Serve as a hands-on product security engineer for Enterprise products and collaborate with cybersecurity leadership, product owners, software engineers, DevOps engineers, infrastructure engineers, systems engineers, and program stakeholders.
  • Translate organizational policies, customer requirements, threat information, and compliance obligations into actionable product security requirements, implementation guidance, and engineering backlog items.
  • Perform threat modeling, attack-surface analysis, security architecture and design reviews, and targeted code or configuration reviews for applications, APIs, data flows, identity services, and distributed system components.
  • Design, integrate, and improve automated security controls within CI/CD pipelines, including static application security testing, software composition analysis, secret detection, container scanning, infrastructure-as-code scanning, software bill of materials generation, and security reporting.
  • Partner with platform and infrastructure teams to define, automate, and validate secure configurations for Linux operating systems, Kubernetes, containers, databases, identity services, networking components, and other common platform services.
  • Develop and validate hardened baselines using DISA STIGs and SRGs, CIS Benchmarks, customer requirements, and industry best practices; automate implementation and verification where practical.
  • Assess product and platform vulnerabilities, analyze technical risk, prioritize findings, provide actionable remediation guidance, coordinate with owning teams, and verify corrective actions.
  • Support secure implementation of authentication, authorization, role-based access control, encryption, secrets management, certificate management, audit logging, service-to-service communication, and data protection controls.
  • Develop reusable security tools, scripts, pipeline templates, configuration baselines, reporting capabilities, and secure implementation patterns that can be adopted across Enterprise products and other engineering teams.
  • Create and maintain security engineering documentation and technical evidence supporting applicable NIST, CMMC, RMF, DHS, TSA, DISA, customer-specific, and international requirements.
  • Perform security testing and technical validation of significant releases, architectural changes, and platform changes, including targeted penetration testing when appropriate.
  • Communicate findings, remediation options, residual risks, and technical tradeoffs to technical and nontechnical stakeholders, and promote secure development practices through guidance and reusable self-service capabilities.

Skills

Product security
Threat modeling
CI/CD security
Automation
Python
Linux
Kubernetes
Vulnerability assessment
Communication
DoD 8140 or equivalent certification

Education

Bachelor's degree in Cybersecurity or related field
Master's degree in a related discipline

Tools

SAST
SCA
Container scanning
Infrastructure-as-code analysis

Job description

Leidos is seeking a Senior Product Security Engineer to support a portfolio of shared software platforms across Ports & Borders and Aviation missions. This senior, hands-on contributor will work with Enterprise Products engineering and partner with cybersecurity leadership, software, DevOps, and infrastructure teams to implement secure-by-default solutions.

The role emphasizes translating standards into actionable security requirements, integrating security tooling into CI/CD pipelines, threat

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Product Security Engineer - Secure DevOps & Apps
Senior Product Security Engineer - Secure DevOps & Apps

Koitecc Solutions • Reston (VA)

Hybrid
USD 87,000 - 157,000
Remote Senior Product Security Engineer
Remote Senior Product Security Engineer

Leidos • United States

On-site
USD 87,000 - 157,000
Senior Product Security Engineer (Remote)
Senior Product Security Engineer (Remote)

Leidos • Virginia (IL)

Hybrid
USD 87,000 - 157,000
Senior Product Security Engineer (Remote)
Senior Product Security Engineer (Remote)

Leidos Inc • United States

On-site
USD 87,000 - 157,000
Sr Product Application Security Engineer
Sr Product Application Security Engineer

Koitecc Solutions • Reston (VA)

Hybrid
USD 87,000 - 157,000
Senior DevSecOps Platform Engineer
Senior DevSecOps Platform Engineer

Leidos • United States

On-site
USD 87,000 - 157,000
Senior Software Engineer: Cloud & DevOps Mission Security
Senior Software Engineer: Cloud & DevOps Mission Security

Leidos LLC • Brookmont (MD)

On-site
USD 108,000 - 195,000
Paid Time Off
Holidays
401K with company match
+5
Senior DevSecOps Platform Architect
Senior DevSecOps Platform Architect

Leidos Inc • Gaithersburg (MD)

On-site
USD 108,000 - 195,000
Sr Product Application Security Engineer
Sr Product Application Security Engineer

Leidos • Virginia (IL)

Hybrid
USD 87,000 - 157,000
Senior DevSecOps Platform Architect
Senior DevSecOps Platform Architect

Via Logic LLC • Eagan (MN)

On-site
USD 108,000 - 195,000