
Staff Security Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Design and implement controls that prioritize security by design, along with policy-as-code and identity federation throughout the platform.
• Develop automation for audit evidence to facilitate continuous compliance and lessen the manual workload associated with audits.
• Oversee threat modeling, code scanning, dependency controls, and efforts for vulnerability remediation.
• Ensure that technical controls and evidence collection are in alignment with regulatory, privacy, and federal audit standards, including NIST SP 800-53 and FedRAMP.
• Create and implement controls for identity, access, encryption, and data protection within production systems.
• Mitigate security risks through automation, monitoring, and preventive controls integrated directly into delivery workflows.
• Function as an engineering partner who facilitates fixes and empowers teams to operate swiftly and securely.
• Collaborate with ISSOs/ISSEs and the Platform Enablement team on ATO and ongoing monitoring activities.
• Carry out other pertinent duties as qualified and trained.
• A Bachelor’s degree along with a minimum of 8 years of relevant experience, or an equivalent mix of education and experience.
• Proven leadership in establishing secure engineering practices, including threat modeling, code scanning, dependency controls, and vulnerability remediation.
• Experience in aligning technical controls and evidence collection with regulatory, privacy, and audit standards.
• Demonstrated ability to design and implement controls for identity, access, encryption, and data protection in production systems.
• Hands-on experience in reducing security risks via automation, monitoring, and preventive controls integrated into delivery workflows.
• Experience in supporting FISMA Moderate or higher ATO processes for federal systems.
• Ability to obtain and maintain a Tier 4 High Risk Public Trust clearance.
• Familiarity with policy-as-code tools, Terraform security modules, and CI/CD-integrated security scanning tools (e.g., Snyk, CodeQL) is a plus.
• Experience with identity federation (OIDC/SAML) in federal settings is a bonus.
• Previous experience supporting federal financial-data systems is advantageous.
• Must be legally authorized to work in the United States.
• Bixal does not offer visa sponsorship.
• Flexible working hours.
• 401K plan with matching incentives.
• Parental leave.
• Comprehensive medical, dental, and vision benefits.
• Flexible Spending Account.
• Company-provided short-term disability and life insurance.
• Commuter benefits.
• Paid Time Off (PTO).
• 11 paid holidays.
• Reasonable accommodations available for participation in the application or interview process, performance of essential job functions, and access to other employment benefits and privileges.
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.