Dev Technology
Lead Security Engineer
Suitland, MD
No sponsorshipDetected 6 days ago
CI/CDAPI DevelopmentCybersecurityPenetration TestingSIEMIncident ResponseZero TrustLeadershipCISSP
About the role
- This role provides technical and management leadership on major security tasks, embedding security into every phase of the System Development Life Cycle (SDLC) using a DevSecOps methodology.
- This position interfaces with senior Government stakeholders and the Office of Information Security (OIS), and decision-making and domain knowledge may have a critical impact on overall program implementation.
Responsibilities
- Lead the design and implementation of application security solutions, frameworks, and processes across all phases of the SDLC
- Implement Zero Trust (ZT) principles for applications, workloads, and data, aligned with EO 14028, OMB M-22-09, and NIST SP 800-207 (Zero Trust Architecture)
- Lead threat modeling exercises to analyze application architecture, identify attack vectors, and document mitigation strategies throughout design, development, testing, and deployment
- Support the Authorization to Operate (ATO) process, including security control assessment, artifact and evidence collection, Privacy Threshold Analysis/Privacy Impact Assessment support, and Plan of Action and Milestones (POA&M) management
- Implement security controls in accordance with the NIST Cybersecurity Framework and NIST SP 800-53, and remediate identified vulnerabilities and compliance findings
- Design and implement secure architecture patterns - secure API design, authentication/authorization, input validation, encryption, secure logging and monitoring (SIEM), and secure error/session/configuration management
- Develop and maintain metrics, dashboards, and reporting to track application security posture, threat trends, and remediation progress over time
- Support the development and management of Interagency Security Agreements (ISA), security playbooks, and incident response in accordance with current cybersecurity policies
- Collaborate with application developers, data engineers, systems engineers, and OIS to identify and mitigate vulnerabilities, and provide expert security consultation to development teams
Nice to have
- Preferred Skills and Experience:
Skills
- Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field
- Certified Information Systems Security Professional (CISSP)
- Certified Cloud Security Professional (CCSP)
- Demonstrated expertise in integrating security into a DevSecOps SDLC, including CI/CD security gates and automated security testing
- Hands-on experience implementing Zero Trust Architecture and applying NIST SP 800-53 controls and the NIST Cybersecurity Framework
- Proven experience leading vulnerability assessments, penetration testing, and threat modeling for enterprise applications
- Experience supporting the ATO lifecycle and managing POA&Ms, security artifacts, and evidence collection
- U.S. Citizenship required
- Certified Information Security Manager (CISM)
- Certified Information Systems Auditor (CISA)
- Experience generating Software Bill of Materials (SBOMs) and implementing software supply-chain security controls
- Familiarity with SIEM deployment, container/image hardening, and secure baseline configuration
Benefits
- Required Education, Experience, and Skills:
Visa & Work Authorization
- Citizenship required
Apply directly at Dev Technology →Create a free account for alerts like thisView Dev Technology immigration profile
This listing is sourced directly from Dev Technology's careers page and normalized into a canonical job model.