A technology company is looking for a hands-on Platform Security Engineer to architect and maintain security solutions. You will work with teams to build secure services, respond to threats, and improve security posture. The role requires strong cloud security knowledge, experience with security tools, and excellent communication skills. This position is remote-friendly and encourages diverse applicants to apply.
#J-18808-Ljbffr
$129k-184k yearly est. 4d ago
Looking for a job?
Let Zippia find it for you.
AI Security Engineer - Red Team (United States, Remote)
Lakera Inc.
Remote manager, network & security job
We're looking for an AI Security Engineer to join our Red Team and help us push the boundaries of AI security. You'll lead cutting‑edge security assessments, develop novel testing methodologies, and work directly with enterprise clients to secure their AI systems. This role combines hands‑on red‑teaming, automation development, and client engagement. You'll thrive in this role if you want to be at the forefront of an emerging discipline, enjoy working on nascent problems, and like both breaking things and building processes that scale.
Key Responsibilities
This is a highly cross‑functional position. AI security is still being defined, with best practices emerging in real‑time. You'll be building the frameworks, methodologies, and tooling that scale our services while staying adaptable to rapid changes in the AI landscape. This role is ideal for someone who wants to take their traditional cybersecurity expertise and apply it to the new frontier of AI security and safety. Your focus will span several key areas:
Service Delivery & Client Engagement
Lead end‑to‑end delivery of AI red‑teaming security assessment engagements with enterprise customers
Collaborate with clients to scope projects, define testing requirements, and establish success criteria
Conduct comprehensive security assessments of AI systems, including text‑based LLM applications and multimodal agentic systems
Author detailed security assessment reports with actionable findings and remediation recommendations
Present findings and strategic recommendations to technical and executive stakeholders through report readouts
Tooling & Methodology Development
Build upon and improve our established processes and playbooks to scale AI red‑teaming service delivery
Develop frameworks to ensure consistent, high‑quality service delivery
Find the tedious, repetitive stuff and automate it - you don't need to be a world‑class developer, just someone who can build tools that make the team more effective
Research & Innovation
Develop novel red‑teaming methodologies for emerging modalities: image, video, audio, autonomous systems
Stay ahead of the latest AI security threats, attack vectors, and defense mechanisms
Translate cutting‑edge academic and industry research into practical testing approaches
Collaborate with our research and product teams to continuously level up our methodologies
Required Qualifications Technical Expertise
3+ years of experience in cybersecurity with focus on red‑teaming, penetration testing, or security assessments
Experience with web application and API penetration testing preferred
Deep understanding of LLM vulnerabilities including prompt injection, data poisoning, and jailbreaking techniques
Practical experience with threat modeling complex systems and architectures
Proficiency in developing automated tooling to enable and enhance testing capabilities, improve workflows, and deliver deeper insights
Professional Skills
Proven track record of leading client‑facing security assessment projects from scoping through delivery
Excellent technical writing skills with experience creating executive‑level security reports
Strong presentation and communication skills for diverse audiences
Experience building processes, documentation, and tooling for service delivery teams
AI Security Knowledge
Understanding of AI/ML model architectures, training processes, and deployment patterns
Familiarity with AI safety frameworks and alignment research
Knowledge of emerging AI attack surfaces including multimodal systems and AI agents
Preferred Qualifications
Relevant security certifications (OSCP, OSWA, BSCP, etc.)
Hands‑on experience performing AI red‑teaming assessments, with a strong plus for experience targeting agentic systems
Demonstrated experience designing LLM jailbreaks
Active participation in security research and tooling communities
Background in threat modeling and risk assessment frameworks
Previous speaking experience at security conferences or industry events
What You'll Gain
Opportunity to shape the future of AI security as an emerging discipline
Work with cutting‑edge AI technologies and novel attack methodologies
Lead high‑visibility projects with enterprise clients across diverse industries
Collaborate with world‑class research team pushing boundaries of AI safety
Platform to establish thought leadership in AI security community
Competitive compensation package with equity participation
❗To remove your information from our recruitment database, please email privacy@lakera.ai. #J-18808-Ljbffr
$114k-163k yearly est. 2d ago
Product Security Engineer
Workos
Remote manager, network & security job
WorkOS builds tools and services for developers to help them implement authentication, identity, authorization, and overall enterprise readiness. We're a fully distributed team with employees across North American time zones. We're well-funded, having raised $100m in funding from top investors including Greenoaks Capital, Lachy Groom, and Lightspeed Ventures. Our fast-growing customer base includes rapidly growing SaaS companies like OpenAI, Cursor, Perplexity, Vercel, Plaid, and hundreds of others.
About the role
WorkOS is growing rapidly and building out our team of engineers! We obsess over the developer experience, actively seeking out feedback and new perspectives to inform the products we build. We're searching for engineers who share this empathetic approach to solving problems.
We're looking for an experienced security engineer to join our team, responsible for defining and coordinating security efforts across the company. The role is both strategic and tactical, so we'll be looking to you to influence long-term strategy while delivering on key pieces during our next phase of company growth.
Successful candidates will love staying up to date on the latest in cloud product security, authentication and identity domains. You'll work across different teams to help make our products secure by design.
Responsibilities
Be the product security champion. You'll work closely with our product engineering teams to provide security guidance on all new and existing products
Collaborate with the product engineering team to perform regular product security assessments
Establish patterns and practices around application security
Advocate for, and lead security projects from inception through completion
Engage with security vendors as needed
Triage and elevate security issues
Qualifications
5+ years of experience as a Product Security engineer in a cloud product company
Proven experience performing security design reviews for complex applications, including distributed systems, APIs, and cloud services
Familiar with common security libraries,security controls, and common security flaws that apply to cloud services
Great written and verbal communication skills
Ability to complete rigorous security-focused code reviews in TypeScript
Bonus: Experience in Auth and Identity domain
Bonus: Experience writing production-level code, especially developing security features
Benefits (US Only)
At WorkOS, we offer resources that emphasize personal and familial well-being. We offer healthcare coverage for you and your family, including medical, dental, and vision. We offer parental leave, paid-time off and fully remote working arrangements.
Benefits include:
Competitive pay
Substantial equity grants
Healthcare insurance (Medical, Dental and Vision) for you and your family
401k matching
Wellness and fitness monthly allowances
PTO + paid holidays + unlimited sick leave
Autonomy and flexibility with remote work
Please inquire directly with our recruiting team for benefits available to those working outside the US.
Equal Opportunity Employer
WorkOS is an equal opportunity employer, committed to diversity and inclusiveness. We will consider all qualified applicants without regard to race, color, nationality, gender, gender identity or expression, sexual orientation, religion, disability or age.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
#J-18808-Ljbffr
$114k-163k yearly est. 3d ago
Information Systems Security Manager
Slope 4.0
Manager, network & security job in Washington, DC
Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century's most innovative companies to the defense industry, Anduril is changing how military systems are designed, built and sold. Anduril's family of systems is powered by Lattice OS, an AI-powered operating system that turns thousands of data streams into a realtime, 3D command and control center. As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the military in months, not years.
ABOUT THE TEAM
Anduril employs a variety of networks and networking infrastructures to support global operations. Information Systems SecurityManagers are in charge of directly supporting business lines that wish to deploy Anduril products in classified environments. Information Systems SecurityManagers lead lean teams of Information Systems Security Officers to enable the program personnel to create contract deliverables. Well versed in Information Technology and the Risk Management Framework, Information Systems SecurityManagers are the driving force of Anduril's classified deployments. Forward thinkers capable of managing Business Line needs as well as critical thinking skills in order to drive customer requirements are the best candidates for a Information Systems SecurityManager.
ABOUT THE JOB WHAT YOU'LL DO
Provide expertise in documenting security controls to reduce the administrative cost of deploying Anduril's products into operational environments.
Partner with program and security teams to coordinate security artifacts in support of classified deployments.
Apply technology standards from the commercial space in classified, air-gapped environments.
Collaborate with Information System Owners to understand key stakeholders' needs and provide complex technical solutions to meet contractual obligations.
Tailor NIST 800-53 controls to determine applicability to the network environment and oversee the implementation of Continuous Monitoring for respective programs.
Define, document, and conduct security scanning on Anduril's products and accredited information systems.
Scope, shape, and orchestrate the development of features to ensure products meet compliance goals.
REQUIRED QUALIFICATIONS
Design, develop, and implement secure systems and networks per NIST RMF, JSIG, and other industry standards.
Integrate security best practices into Anduril's Software Development Lifecycle (SDLC) and infrastructure design, collaborating with internal IT and engineering teams.
Conduct security risk assessments, vulnerability assessments, and audits to identify and mitigate threats.
Recommend and implement security solutions, such as IDS/IPS, encryption protocols, and secure communications technologies.
Develop and enforce access controls, encryption strategies, and other technical measures to safeguard systems.
Maintain and update System Security Plans (SSPs), POA&Ms, and other accreditation documentation.
SecurityManagement (ISSM):
Manage the organization's security posture, ensuring compliance with internal policies and external regulatory frameworks.
Oversee Authorization and Accreditation (A&A) processes to obtain/maintain system Authority to Operate (ATO).
Lead incident response efforts, including investigation, root cause analysis, containment, and reporting.
Conduct regular audits, continuous monitoring, and risk assessments to ensure ongoing compliance and system resilience.
Collaborate with government security officials, stakeholders, and teams to address security gaps and improve controls.
Develop and deliver security awareness training and ensure adherence to security best practices.
Provide leadership and mentorship to security team members, fostering a culture of cybersecurity excellence.
Currently possesses and is able to maintain an active U.S. Top Secret security clearance.
PREFERRED QUALIFICATIONS
Experience with application security paradigms such as Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA). As well as the tools needed to perform these actions.
Proven experience in securing micro-services architecture, including implementing best practices and compliance with DoD cybersecurity standards.
Experience with cybersecurity in unmanned and ground control system within DoD environments.
Experience with containerization and kubernetes along with the best practices for securing them.
Experience with Cloud Service Providers (CSPs) and the various tools they offer for implementing security and compliance best practices.
US Salary Range
$150,000 - $225,000 USD
The salary range for this role is an estimate based on a wide range of compensation factors, inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations. Highly competitive equity grants are included in the majority of full time offers; and are considered part of Anduril's total compensation package. Additionally, Anduril offers top-tier benefits for full-time employees, including:
The recruiter assigned to this role can share more information about the specific compensation and benefit details associated with this role during the hiring process.
Anduril is an equal-opportunity employer committed to creating a diverse and inclusive workplace. The Anduril team is made up of incredibly talented and unique individuals, who together are disrupting industry norms by creating new paths towards the future of defense technology. All qualified applicants will be treated with respect and receive equal consideration for employment without regard to race, color, creed, religion, sex, gender identity, sexual orientation, national origin, disability, uniform service, Veteran status, age, or any other protected characteristic per federal, state, or local law, including those with a criminal history, in a manner consistent with the requirements of applicable state and local laws, including the CA Fair Chance Initiative for Hiring Ordinance. We actively encourage members of recognized minorities, women, Veterans, and those with disabilities to apply, and we work to create a welcoming and supportive environment for all applicants throughout the interview process. If you are someone passionate about working on problems that have a real-world impact, we'd love to hear from you!
To view Anduril's candidate data privacy policy, please visit **********************************************
#J-18808-Ljbffr
$150k-225k yearly 2d ago
ISR Systems Network & Security Architect
Goldbelt, Inc. 4.5
Manager, network & security job in Washington, DC
A leading technology firm in Washington is seeking a Technical Architect to support the US Coast Guard's ISR systems. The role involves designing secure computer networks, ensuring compliance with cybersecurity standards, and collaborating with federal teams. Ideal candidates will have a strong background in networking and cloud technologies, along with relevant experience in federal IT environments. The salary range for this position is between $140,000 and $170,000 annually, alongside a comprehensive benefits package.
#J-18808-Ljbffr
$140k-170k yearly 5d ago
Senior AWS Network & Cloud Security Architect
Booz Allen Hamilton 4.9
Manager, network & security job in Washington, DC
A leading consulting firm in Washington, DC, is seeking a Senior AWS Network Architect to secure cloud environments for critical operations. The ideal candidate has over 5 years of experience in AWS architecture and managing Palo Alto firewalls. Responsibilities include developing security architectures and mentoring junior staff. This role offers a salary range of $86,800 to $198,000, with comprehensive benefits and flexibility in work arrangements.
#J-18808-Ljbffr
$86.8k-198k yearly 5d ago
Senior Backend Engineer - Remote API & Security (Java/Spring)
Knowledge Management, Inc. 3.9
Remote manager, network & security job
A technology solutions provider seeks a Senior Backend/Middleware Engineer to develop secure, high-performance API and middleware solutions. This remote role requires expertise in Java and Spring Boot, with responsibilities including designing RESTful APIs and implementing security protocols. Ideal candidates will have experience with OAuth 2.0, OpenID Connect, and authorization principles. Benefits include health insurance, 401(k), and paid time off.
#J-18808-Ljbffr
$109k-150k yearly est. 2d ago
Senior AWS Network & Cloud Security Architect
Phase2 Technology 3.9
Manager, network & security job in Washington, DC
A leading cloud security firm in Washington, DC is hiring a Senior AWS Network Architect. You will architect and manage complex AWS networks, ensuring cloud safety for critical operations. Candidates should have extensive experience in AWS, Palo Alto firewalls, and Zero Trust principles. The role includes mentoring junior experts and providing guidance on security architecture. Company offers competitive benefits and a flexible work model.
#J-18808-Ljbffr
$97k-130k yearly est. 3d ago
Federal Network Architect II: Cloud & Security Lead
Angsignal
Manager, network & security job in Washington, DC
A technology-focused company in Washington is seeking a Network Architect to lead network projects supporting the federal government. The ideal candidate will have extensive experience in network engineering and design, including a deep understanding of cloud security and various networking protocols. This role demands strong leadership and communication skills, alongside the ability to manage complex network solutions effectively. A competitive benefits package is offered, along with a commitment to diversity in the workplace.
#J-18808-Ljbffr
$94k-129k yearly est. 3d ago
Cloud Security Engineer
Meta 4.8
Manager, network & security job in Washington, DC
We are seeking a Security Engineer who specializes in designing and implementing new systems and tools to enhance the security of Meta's products and infrastructure. This role is ideal for individuals with deep security domain expertise who are passionate about building solutions and using AI to address evolving security requirements and use cases.
Cloud Security Engineer Responsibilities
Design, prototype, and implement AI-driven security systems and tools to protect Meta's products and internal infrastructure
Develop and maintain security-focused code, libraries, and frameworks for use by Security Engineers, Analysts, and engineering teams
Collaborate with cross-functional partners to deliver scalable,security solutions aligned with company objectives
Rapidly experiment with and iterate on specialized security technologies, leveraging AI to address emerging threats and requirements
Apply deep security expertise to solve complex challenges, mitigate risks, and mentor other engineers in advanced security domains
Minimum Qualifications
B.S. or M.S. in Computer Science or related field, or equivalent experience
5+ years of experience in designing and implementing security systems, tools, or frameworks
Extensive knowledge of attacker tactics, techniques, and procedures
Proficiency in coding with experience in languages such as Python, C/C++, Go, or equivalent
Experience collaborating with technical and non-technical stakeholders
Ability to rapidly prototype and iterate on security solutions
Preferred Qualifications
Experience on securing cloud deployments, IAC (Infrastructure as Code) deployments for cloud (terraform)
Experience addressing security problems by building scalable engineering solutions
Experience influencing software engineers building security products
Experience creating metrics to measure service and program effectiveness and consistency
Experience making contributions to the security or privacy community (public research, OSS, blogging, presentations, etc.)
Public Compensation
$147,000/year to $208,000/year + bonus + equity + benefits
Industry
Internet
Equal Opportunity
Meta is proud to be an Equal Employment Opportunity and Affia... (full statement)
Meta is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance or accommodations due to a disability, please let us know at accommodations-ext@fb.com.
#J-18808-Ljbffr
$147k-208k yearly 3d ago
Remote Senior IAM Engineer: Secure, Scalable Auth Systems
Whatnot
Remote manager, network & security job
A leading live shopping platform is seeking a Software Engineer in San Francisco to enhance their user account systems' security and integrity. This role involves working in cross-functional teams to ensure robust authentication and minimize risk. Candidates need 5+ years in infrastructure engineering, solid coding skills, and experience with large distributed systems. The position allows flexibility in working from home or attending global hubs. Competitive salary and generous benefits are offered.
#J-18808-Ljbffr
$117k-166k yearly est. 5d ago
Firewall Security Engineer
Novacoast 3.9
Manager, network & security job in Washington, DC
Novacoast Staffing is currently assisting a financial government institution in its search for an experienced Firewall Security Engineer that is experienced in Palo Alto Firewalls for a contract role that is expected to go a minimum of 2 years with option to extend. This is a hybrid role with a few days onsite in Alexandria VA and a pay range of 60-68/ hour. To qualify for this role, you must be able to pass an extensive federal background check.
Qualifications
To qualify for this position, you must have at least 5 years of experience with Palo Alto Next Generation firewalls, Zero Trust, and strong knowledge of advanced firewall features such as Wildfire, App-ID, User-ID, Global Protect,Security, and NAT policies, within Cloud environments.
Responsibilities
In this role, you will be responsible for the design, administrations, and management of Palo Alto Firewalls using Centralized Panorama Management. You will also be responsible for configuration and troubleshooting IPSEC site-to-site VPNs and SSL decryption on Palo Alto Firewalls.
Requirements
5+ years experience with Palo Alto next-generation Firewalls and working in cloud and Zero Trust environments
Strong knowledge of advanced firewall features such as Wildfire, App-ID, User-ID, Global Protect,Security and NAT policies
Expert level knowledge in the design, administration of Palo Alto Firewalls using Centralized Panorama Management
Expert level knowledge in configuration and troubleshooting IPSEC Site-to-Site VPNs
US Citizenship is required due to the position being with a Federal Client
If this role is aligned with your next career move, submit your resume today for immediate consideration!
Job Type: Contract
Pay: $60.00 - $68.00 per hour
#J-18808-Ljbffr
$60-68 hourly 2d ago
Senior Information Security Engineer / Vulnerability Manager
C2 Labs, Inc.
Manager, network & security job in Washington, DC
C2 Labs, Inc. - **************
C2 Labs partners with clients on their IT transformation journey via our industry-leading capabilities in full stack development, hyper-automation/DevOps, and cybersecurity compliance. We provide specialized products and services that enable clients to innovate with speed and scale while maintaining a robust and effective security posture. As digital transformation partners, we address the most urgent needs holding back our clients, including proactively addressing cultural change, quantifying risk, automating compliance, and closing critical skill gaps.
Job Duties
As a Senior Information Security Engineer / Vulnerability Manager, you will lead efforts to identify, assess, and mitigate security vulnerabilities across complex enterprise IT environments. Responsibilities include:
Vulnerability & Threat ManagementManage enterprise vulnerability management platforms (e.g., Tenable, Qualys, Rapid7) and ensure timely scanning, reporting, and remediation tracking.
Perform risk-based analysis of vulnerabilities, develop mitigation plans, and escalate issues requiring urgent remediation.
Integrate threat intelligence to prioritize vulnerabilities based on exploitability, industry trends, and business impact.
Establish and maintain vulnerability KPIs, metrics, and executive reporting dashboards.
Security Engineering
Design, implement, and maintain security controls and safeguards across networks, endpoints, and cloud environments (AWS, Azure, or hybrid).
Automate security operations tasks using scripts or tools (Python, PowerShell, Bash, or AWS Lambda).
Collaborate with IT and DevOps teams to integrate vulnerability management into CI/CD pipelines and cloud workloads.
Conduct regular security assessments, penetration test remediation support, and continuous monitoring activities.
Governance, Risk, & Compliance
Support compliance with federal frameworks (FedRAMP, NIST SP 800-53, NIST SP 800-171/CMMC, FISMA, etc.).
Document processes, remediation plans, and compliance evidence in alignment with client requirements.
Provide recommendations for continuous improvement of security posture and policy enforcement.
Collaboration & Leadership
Partner with cross-functional teams (IT, Development, Operations, and Compliance) to ensure vulnerabilities are remediated in a timely, risk-based manner.
Provide technical leadership and mentorship to junior security engineers and analysts.
Participate in client-facing meetings and presentations as a subject matter expert in vulnerability and threat management.
Education, Training, Qualifications, and Certifications
Required:
U.S. Citizenship and ability to obtain/maintain Public Trust clearance
Bachelor's degree in Computer Science, Cybersecurity, or related field OR 5+ years of equivalent hands-on experience
Proven experience in vulnerability management,security engineering, or penetration testing
Strong knowledge of IT infrastructure,networking, and cloud environments (AWS preferred)
Familiarity with security automation, scripting (Python, PowerShell, Bash), and infrastructure-as-code principles
Excellent analytical, problem-solving, and communication skills
Background check and unannounced drug testing required.
This position is onsite in Washington, DC, with occasional travel (up to 25%) for client meetings and work assignments.
Preferred:
Professional certifications such as CISSP, CISM, OSCP, CEH,Security+, or AWS Security Specialty
Experience with compliance frameworks (FedRAMP, NIST 800-53, CMMC)
Background in DevSecOps practices, continuous monitoring, and automation
EOE STATEMENT:
We are an equal opportunity employer. All qualified applicants will be considered without discrimination based on race, color, religion, sex, national origin, age, disability, or protected veteran status. Employment offers will be contingent on passing a pre-employment drug screen.
#J-18808-Ljbffr
$103k-139k yearly est. 5d ago
Senior Security Engineer
Emergencymd
Manager, network & security job in Washington, DC
Evolver Federal is seeking a Senior Security Engineer to fulfill a requirement for a potential government client. The Senior Security Engineer is responsible for designing, implementing, and maintaining advanced security solutions to protect federal systems and data. This role prioritizes continuous monitoring, FISMA compliance, and OIG audit readiness while engineering secure architectures, integrating cybersecurity technologies, and ensuring adherence to federal standards such as NIST 800-series, RMF, and TIC 3.0. The Senior Security Engineer will work closely with SOC teams, architects, and program managers to deliver robust security capabilities across cloud (AWS GovCloud, Azure Government), on-premises, and hybrid environments. This position requires deep technical expertise, hands-on experience with security tools, and the ability to lead engineering efforts for mission‑critical systems in highly regulated environments.
Responsibilities
Design and implement security solutions for enterprise and federal environments, ensuring compliance with RMF and NIST guidelines.
Engineer secure configurations for SIEM, SOAR, EDR, and vulnerability management platforms.
Support Tier 2/3 SOC analysts by developing advanced correlation rules for Splunk and optimizing detection workflows.
Support SOC operations by integrating advanced detection and response capabilities.
Conduct security assessments, penetration testing, and risk analysis for critical systems.
Implement continuous monitoring and automated compliance reporting to meet Department of Labor and federal requirements.
Develop and maintain security engineering documentation, including system security plans and architecture diagrams.
Collaborate with architects and program managers to align security engineering with strategic objectives.
Lead efforts to integrate security into DevSecOps pipelines and CI/CD workflows.
Provide technical expertise during incident response and forensic investigations.
Evaluate emerging technologies and recommend enhancements to improve security posture.
Define and track measurable outcomes such as MTTR reduction, SLA adherence, compliance score improvements, and false positive reduction to meet performance‑based contract KPIs.
Coordinate with federal stakeholders (CISO, ISSOs, AO) and provide audit support for ATO processes.
Ensure adherence to performance‑based contract requirements and federal cybersecurity mandates.
Basic Qualifications
Bachelor's Degree in Computer Science, Information Management (IM), Information Technology, Engineering, or equivalent with 6 years of technical experience, or 4 years' experience in IT Solutions at senior management
Certified Information Systems Security Professional (CISSP) mandatory with Information Systems Security Engineering Professional (ISSEP) concentration
Project Management Institute (PMI) Project Management Professional (PMP) (Highly Recommended)
Information Technology Infrastructure Library (ITIL) 4 Foundation
10 years of successful enterprise experience in an IT or technology-related field, with the last 5 years, on large government technical contract/BPAs
US Citizen with the ability to pass a comprehensive government background check
Preferred Qualifications
Master's degree in cybersecurity, IT, or a related technical field
Experience supporting SOC operations in federal or regulated environments
Familiarity with RMF, NIST 800-series, OMB A-130, and TIC 3.0
Proven leadership in cross‑functional teams and performance‑based contracts
Strong communication skills, including executive briefings and incident reporting
Hands‑on experience with SIEM (Splunk, Elastic), SOAR (Cortex XSOAR), and EDR (CrowdStrike, Microsoft Defender).
Expertise in cloud security engineering (AWS, Azure, GCP) and container security (Kubernetes, Docker).
Familiarity with Zero Trust Architecture principles and implementation strategies.
Familiarity Continuous Diagnostics and Mitigation (CDM).
Experience with PKI, encryption standards, and securenetwork design.
Knowledge of automation tools for security orchestration and compliance reporting.
Ability to lead technical teams and mentor junior engineers in cybersecurity best practices.
Experience integrating security controls into large-scale federal systems and mission‑critical applications.
Understanding of advanced threat detection techniques and AI‑driven security solutions.
Evolver Federal is an equal opportunity employer and welcomes all job seekers. It is the policy of Evolver Federal not to discriminate based on race, color, ancestry, religion, gender, age, national origin, gender identity or expression, sexual orientation, genetic factors, pregnancy, physical or mental disability, military/veteran status, or any other factor protected by law.
Actual salary will depend on factors such as skills, qualifications, experience, market and work location. Evolver Federal offers competitive benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies.
#J-18808-Ljbffr
$98k-136k yearly est. 3d ago
Senior Cloud & Security Software Engineer
Tla LLC
Manager, network & security job in Washington, DC
A technology firm is seeking a Software Engineer to design, develop, and integrate secure computing environments supporting critical mission objectives. The role requires experience in full-stack development, AWS services, and Infrastructure-as-Code tools. Ideal candidates will collaborate with cross-functional teams and possess strong scripting skills. Preferred certifications include AWS Certified Solutions Architect. This position is based in Washington, D.C.
#J-18808-Ljbffr
A leading AI research company in San Francisco is hiring a Security Engineer, specializing in application security. Responsibilities include conducting security assessments, developing security tools, and collaborating with development teams to integrate security best practices throughout the software development lifecycle. The ideal candidate has extensive experience in cybersecurity and strong programming skills. This role offers a hybrid work model with relocation assistance.
#J-18808-Ljbffr
$125k-175k yearly est. 5d ago
Senior Systems Security Engineer
Nava 4.0
Manager, network & security job in Washington, DC
Be Challenged and Make a Difference
In a world of technology, people make the difference. We believe if we invest in great people, then great things will happen. At AnaVation, we provide unmatched value to our customers and employees through innovative solutions and an engaging culture.
Description of Task to be Performed:
AnaVation is looking for a Sr. Systems Security Engineer to assist the customer with engineering and administration tasks. The ideal candidate will be comfortable engaging with client leadership on a regular basis and interacting with senior level team members.
Responsibilities
Perform hands-on engineering, administration, and securing of multiple operating systems (e.g., Windows, RHEL, Unix variants), and applying DISA STIGs across diverse vendor technologies, including virtualization platforms (VMWare, Hyper-V), cloud environments (AWS, Azure, Google Cloud), and enterprise applications.
Perform system administration tasks to include audit and log management, availability monitoring and remediation, account management and access reviews, and configuration update scheduling and performance.
Contribute to the design and development of secure system architectures, ensuring security is integrated through system and network lifecycles.
Evaluate, implement, and document security architecture solutions, aligning with compliance requirements and organizational mission needs.
Ensure technical compliance with applicable security frameworks, standards, and regulations (e.g., DISA SITGs, NIST 800-53, RMF).
Conducting, configuring, and managing vulnerability scans.
Conducting vulnerability remediations, patching, and system hardening.
Collaborate with ISSOs, Assessors, System Owners, and other stakeholders to implement security controls.
Support security assessments, audits, and accreditation/authorization (ATO) activities.
Document security configurations, engineering solutions, and compliance evidence.
Troubleshoot and resolve security-related technical issues in a timely manner.
Understanding and advising the client regarding critical application data and vulnerability points, coordinating with industry partners to advise the government regarding those security vulnerabilities, and providing recommendations and advice on incident response and recovery plans.
Providing Incident Response (IR) activities including triage, investigation, interviewing, resolving, and reporting on events.
Promoting information security awareness across the program, ensuring security controls and processes are implemented.
Presenting vulnerability analysis to system owners and leadership.
Required Qualifications
5-10 years of experience in information system engineering and configuration management.
5 years of experience in control implementation and secure system engineering or design.
Excellent communication skills.
Hands on experience with:
Security monitoring and evaluation, including audits, assessments, and risk management
SIEM tools (e.g., Splunk)
Vulnerability Scanning tools (e.g., Tenable, Nessus)
EDR tools (e.g., Crowdstrike)
Web App Scanning tools (e.g., Burpsuite, Acunetix)
Active Directory
SANs
VMWare
Networking Devices
Expertise in batch, bash, and/or PowerShell scripting
Able to deliver and present security compliance to a wide range of audiences (i.e., system owners, division leadership).
Experience configuring and operating enterprise storage across networks (SAN)
Server visualization - design solutions and configuration (VMWare, VSphere, Hyper-V, etc)
Experience with:
Linux (RHEL 7/8), Windows Operating Systems, and Oracle/SQL Databases
Agile Methodologies
GRC Tools (e.g., CSAM)
Strong desire to learn, grow and be highly motivated.
Certifications: OS specific certifications,Security +
Personnel assigned to this task shall possess a blend of strong technical skills (networking, operating systems,security tools, programming, encryption) and essential soft skills (problem-solving, critical thinking, communication, collaboration) to design, implement, and maintain an information system's security control implementation.
Desired Qualifications
Knowledgeable on different cloud providers: AWS, Azure, Oracle, GCP
Understanding of servers and security tools
Education: Bachelor's degree in Engineering, Computer Science, or Information Systems
Certifications: CompTIA Server+, Cloud certifications (AWS, Azure, Google), Network+, CCNA, RHCSA, Azure (AZ-104, AZ-204, AZ-500, AZ-305), AWS Solutions Architect
Benefits
Generous cost sharing for medical insurance for the employee and dependents
100% company paid dental insurance for employees and dependents
100% company paid long-term and short-term disability insurance
100% company paid vision insurance for employees and dependents
401k plan with generous match and 100% immediate vesting
Competitive Pay
Generous paid leave and holiday package
Tuition and training reimbursement
Life and AD&D Insurance
About AnaVation
AnaVation is the leader in solving the most complex technical challenges for collection and processing in the U.S. Federal Intelligence Community. We are a US owned company headquartered in Chantilly,Virginia. We deliver groundbreaking research with advanced software and systems engineering that provides an information advantage to contribute to the mission and operational success of our customers. We offer complex challenges, a top-notch work environment, and a world-class, collaborative team.
If you want to grow your career and make a difference while doing it, AnaVation is the perfect fit for you!
AnaVation is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law.
#J-18808-Ljbffr
$74k-97k yearly est. 3d ago
Qualys Security Engineer- Active Secret Clearance Required
VETS, Inc.
Manager, network & security job in Washington, DC
Staffing Pros, a division of VETS Inc., is recruiting for a full-time Qualys Security Engineer onsite in Washington, DC or Beltsville, MD. This position requires an Active Secret Clearance.
The Senior Qualys Security Engineer will support our customer's enterprise vulnerability management initiatives. This role involves maintaining and optimizing Qualys toolsets, performing vulnerability assessments, and working collaboratively across technical teams to strengthen organizational cybersecurity posture.
This position is based on-site at either the Washington, DC or Beltsville, MD office, with occasional travel between the two locations.
What you'll do:
Oversee day-to-day management of the Qualys platform including agents, scanners, and connectors.
Optimize scan configurations, authentication methods, and template deployments.
Review and interpret scan results to generate actionable intelligence for technical and non-technical audiences.
Partner with infrastructure, development, and SOC teams to validate findings and drive remediation efforts.
Automate tasks using Qualys APIs and custom scripts to support reporting and data integration.
Maintain an up-to-date asset inventory through discovery and classification workflows.
Minimize false positives through tuning and validation.
Conduct policy compliance assessments in support of regulatory frameworks.
Provide guidance and mentorship to junior analysts in vulnerability management best practices.
Required Qualifications
5+ years of hands-on expertise with Qualys.
Must be able to commute to Beltsville, MD or Washington, DC for full-time onsite work.
Secret clearance with the ability to obtain a Top Secret clearance is required.
Proficiency in scripting (Python, PowerShell, or Bash).
Familiarity with network protocols, OS security (Windows/Linux), and web application vulnerabilities.
Understanding of compliance standards and frameworks (e.g., NIST 800-53, CIS Controls, ISO 27001.)
Qualys Vulnerability Management & Policy Compliance.
Qualys Web Application Scanning.
Automation using Qualys APIs.
Network architecture and protocol knowledge.
Database and OS-level security.
Vulnerability lifecycle and remediation strategies.
Excellent written and verbal communication.
Strong problem-solving and analytical mindset.
Ability to operate independently or as part of a multi-disciplinary team.
Solid documentation and reporting practices.
Experience engaging with cross-functional stakeholders.
US Citizenship is required.
Preferred Qualifications
Professional certifications: CISSP, CEH, GIAC, or equivalent.
Exposure to other scanning tools (e.g., Tenable, Rapid7).
Familiarity with public cloud security models (AWS, Azure, GCP).
Experience with configuration management tools and CI/CD pipelines.
Background in system administration,network engineering, or DevSecOps.
EEO Statement Staffing Pros a division of VETS-inc is an Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities.
The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor's legal duty to furnish information.
$84k-117k yearly est. 41d ago
Senior Network Architect - Mission-Critical NAS
Peraton 3.2
Manager, network & security job in Washington, DC
A leading technology solutions provider in Washington, D.C. is seeking a Network Architect to design and implement modern IP-based network architectures for critical aviation projects. The ideal candidate will have proven experience in network engineering, maintain security standards, and provide oversight on subcontractor activities. This role offers a chance to shape the future of air traffic management and contribute to the safety of U.S. airspace operations.
#J-18808-Ljbffr
$84k-118k yearly est. 3d ago
Principal Cloud Security Engineer
Zealotech People
Manager, network & security job in Washington, DC
Clearance: Active Secret
Employment Type: Full-Time
We are seeking a Principal Cloud Security Engineer to lead the design, automation, and enforcement of security across large-scale federal cloud environments. This role focuses on cloud security architecture, DevSecOps automation, and secure platform enablement in a multi-cloud ecosystem.
The ideal candidate is highly technical, self-directed, and comfortable operating as the senior security authority for cloud platforms. You will define secure patterns, implement guardrails at scale, and embed security directly into infrastructure and CI/CD pipelines.
Key Responsibilities:
Cloud Security Architecture:
Design and guide secure architectures across AWS, Azure, and GCP, including GovCloud and restricted environments
Define and enforce security baselines aligned with NIST 800-53, FedRAMP, and CIS Benchmarks
Lead threat modeling, architecture reviews, and secure design guidance for cloud workloads
DevSecOps & Automation:
Build and maintain Infrastructure as Code using Terraform (preferred) and cloud-native tooling
Integrate automated security controls into CI/CD pipelines (SAST, DAST, IaC scanning, container scanning)
Implement policy-as-code guardrails using tools such as AWS SCPs, Azure Policy, and cloud-native governance services
Develop automated remediation and enforcement workflows to reduce manual security effort
Governance, Compliance & Visibility:
Embed compliance controls directly into cloud infrastructure and pipelines to support ATO efforts
Partner with compliance teams and auditors on evidence collection and continuous monitoring
Implement centralized logging, monitoring, and incident response across cloud environments
Technical Leadership:
Serve as the senior cloud security SME for engineers, architects, and stakeholders
Mentor engineers on secure cloud development and DevSecOps practices
Translate complex security concepts to both technical and non-technical audiences
Required Qualifications:
Active Secret clearance
8+ years in cybersecurity or cloud engineering, including 5+ years focused on cloud security
Deep hands-on experience securing AWS, Azure, or GCP (experience in at least two preferred)
Strong Infrastructure as Code experience (Terraform strongly preferred)
Experience integrating security into CI/CD pipelines (GitHub Actions, GitLab, or similar)
Proficiency in Python, Go, PowerShell, or Bash
Strong understanding of IAM,networking, encryption, key management, and cloud-native security services
Ability to operate independently and define security priorities without daily direction
Preferred Qualifications:
Experience securing GovCloud, DoD IL5/IL6, or other regulated cloud environments
Kubernetes and container security experience
Zero Trust architecture implementation experience
ServiceNow integrations for security workflows
Cloud security certifications (AWS Security Specialty, Azure Security Engineer, etc.)
What Makes This a True Principal Role:
Highly hands-on and deeply technical
Owns security outcomes rather than executing predefined tasks
Heavy DevSecOps and IaC focus
Large-scale, multi-cloud environment
Architecture and influence matter as much as implementation