
Security Engineer
Posted Jul 28

Posted Jul 28
This is a fully remote position, open to applicants in Virginia.
• The chosen candidate will be tasked with working on multiple products and must be capable of developing and presenting secure solutions and guidance to both technical teams and leadership.
• Additionally, the candidate will be responsible for assessing risks and providing advice on security standards, best practices, and solutions.
• Various tools will be employed to identify vulnerabilities, with the security engineer documenting these vulnerabilities and collaborating with developers to rectify them.
• The security engineer will also be required to facilitate the path to production for new applications, ensuring that all documentation and necessary steps are completed and approved to maintain a highly secure production application and environment.
• Conduct Static Application Security Testing (SAST) to uncover potential vulnerabilities in application code and infrastructure.
• Execute Dynamic Application Security Testing (DAST).
• Develop and update threat models for FISMA systems.
• Lead and assist in security incident response efforts.
• Contribute to the documentation of System Security Plans and Contingency Plans for related projects.
• Ensure that security systems are current and create documentation and strategies for all security-related information, including incident response and disaster recovery plans.
• Review policies and procedures for compliance with relevant standards and identify areas for improvement to facilitate remediation.
• Engage with senior management, including the ISSO.
• Utilize security assessment tools such as Nessus, Snyk, AWS GuardDuty, and AWS Inspector.
• Demonstrate a solid understanding of cryptography to secure web applications and data at rest.
• Collaborate with development teams to review and amend code written in higher-level programming languages and scripts.
• Partner with DevOps teams to securely harden Linux-based machines and cloud infrastructure.
• Bachelor’s Degree.
• Over 5 years of professional security engineering experience.
• The candidate must be able to obtain and maintain a Public Trust.
• The candidate must reside in the U.S., be authorized to work in the U.S., and all work must be performed in the U.S.
• The candidate must have lived in the U.S. for three (3) full years within the last five (5) years.
• Hands-on experience that includes:
• NIST 800‑53 security controls.
• System hardening and implementation of DoD STIGs.
• Leading incident response activities.
• Data management and applied cryptography.
• Cloud security and infrastructure (AWS, Azure, and/or GCP).
• Awareness of OWASP Top Ten and CWE Top 25.
• Proficiency in Linux command line usage (e.g., bash, sh, zsh).
• Scripting experience in Python, Perl, or similar languages.
• Strong engineering background.
• Application architecture experience.
• Federal Government contracting work experience.
• One or more of the following certifications is preferred:
• OSCP/OSCE/OWSE.
• CISSP.
• GPEN.
• GXPN.
• Security +.
• CEH.
• Reasonable Accommodations are available.
• Equal Employment Opportunity Policy.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.