nCybersecurity Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+25 more
Job description
The CDC National Healthcare Safety Network (NHSN) is seeking a Cybersecurity Engineer to support the modernization of one of the nationâs largest public health surveillance platforms. This role will serve as the programâs primary cybersecurity engineering resource, embedding security throughout the software development lifecycle while supporting NHSNâs migration to modern cloud-native technologies, including Microsoft Azure, Databricks, and AI-assisted software engineering.
Requirements
- Bachelorâs degree in Computer Science, Cybersecurity, Software Engineering, Information Technology, or a related discipline. \n
- Eight (8) or more years of experience in cybersecurity engineering, application security, cloud security, DevSecOps, or secure software engineering. \n
- Experience implementing security controls within Microsoft Azure cloud environments. \n
- Experience supporting secure software development using Java, C#, Python, or other modern programming languages. \n
- Experience with Azure DevOps, Git, CI/CD pipelines, and modern software engineering practices. \n
- Experience securing cloud-native applications, REST APIs, containers, or distributed systems. \n
- Experience performing vulnerability assessments, application security testing, and remediation activities. \n
- Working knowledge of authentication, authorization, encryption, identity management, and API security. \n
- Strong communication and collaboration skills with cross-functional engineering teams. \n, * Experience with Azure Kubernetes Service (AKS), Azure Container Apps, Azure SQL, Azure Storage, Azure Key Vault, Microsoft Defender, and Azure Monitor. \n
- Experience securing Azure Databricks, Delta Lake, Azure Data Factory, or enterprise data platforms. \n
- Experience implementing DevSecOps practices and automated security testing. \n
- Experience supporting healthcare, public health, or other regulated data environments. \n
- Experience with FHIR, HL7, healthcare APIs, or secure healthcare data exchange. \n
- Familiarity with NIST Cybersecurity Framework (CSF), NIST SP 800-53, FISMA, FedRAMP, Zero Trust, and secure cloud engineering principles. \n
- Security certifications such as Security+, CISSP, CCSP, Microsoft Certified: Azure Security Engineer Associate, GIAC, or equivalent. \n, * Strong hands-on engineering and problem-solving skills. \n
- A practical approach to implementing cybersecurity within modern software development environments. \n
- Experience working collaboratively with software developers, cloud engineers, and data engineers. \n
- A passion for automation, DevSecOps, and cloud-native engineering. \n
- The ability to balance security, performance, scalability, and maintainability. \n
- Strong analytical, communication, and collaboration skills. \n
- A commitment to continuously improving secure engineering practices. \n
Benefits & conditions
n Working closely with software engineers, cloud engineers, data engineers, solution architects, and technical leadership, the Cybersecurity Engineer will implement secure engineering practices across applications, APIs, cloud infrastructure, data platforms, and DevSecOps pipelines. This position focuses on hands-on engineering, application security, cloud implementation, and data protection while working closely with CDCâs Office of the Chief Information Officer (OCIO), Cybersecurity Program Office (CSPO), Office of Managed Hosting Services (OMHS), and Microsoft Azure enterprise security services to ensure the NHSN modernization effort aligns with \n \n CDCâs enterprise cybersecurity strategy, architecture, policies, standards, and operational processes. \n \n The ideal candidate combines strong software engineering skills with practical cybersecurity expertise and enjoys building secure, scalable, cloud-native solutions that support CDCâs public health mission. \n \n \nKey Responsibilities \n \n \nSecure Software Engineering \n \n \n
- Integrate cybersecurity throughout the Software Development Lifecycle (SDLC). \n
- Implement secure coding practices, application hardening, and secure design principles across NHSN applications. \n
- Perform application security reviews, vulnerability analysis, and remediation activities. \n
- Support secure implementation of authentication, authorization, API security, encryption, and secrets management. \n
- Partner with software engineers to resolve security findings and improve application resiliency. \n
\n \nCloud Security Engineering \n \n \n
- Implement security controls within NHSNâs Microsoft Azure environment. \n
- Support secure deployment and configuration of Azure App Services, Azure Container Apps, Azure Kubernetes Service (AKS), Azure SQL, Azure Storage, and related Azure services. \n
- Assist with cloud resource hardening, identity integration, logging, monitoring, and secure configuration management. \n
- Collaborate with cloud engineering teams to implement Zero Trust principles and secure Infrastructure-as-Code (IaC) practices. \n
\n \nData Platform Security \n \n \n
- Implement security controls supporting NHSNâs migration from SAS to Databricks. \n
- Secure Azure Databricks workspaces, Delta Lake storage, Azure SQL, and enterprise data pipelines. \n
- Support secure ingestion, transformation, storage, and processing of sensitive public health data. \n
- Implement encryption, access controls, auditing, and monitoring to protect NHSN data assets. \n
\n \nDevSecOps \n \n \n
- Integrate automated security testing into Azure DevOps CI/CD pipelines. \n
- Implement source code scanning, dependency analysis, container image scanning, Infrastructure-as-Code validation, and security automation. \n
- Support continuous vulnerability management and remediation throughout the software delivery lifecycle. \n
- Promote secure engineering practices across development teams. \n
\n \nApplication & Integration Security \n \n \n
- Support secure integration with CDC enterprise services, including Secure Access Management Services (SAMS). \n
- Implement secure authentication and authorization for NHSN applications, APIs, and cloud services. \n
- Support secure transmission and ingestion of healthcare data through NHSNLink, FHIR-based interfaces, and other enterprise integration services. \n
- Coordinate and execute penetration testing, security validation, and remediation of application and infrastructure vulnerabilities. \n
\n \nCollaboration & Compliance \n \n \n
- Work closely with CDCâs enterprise cybersecurity organizations to ensure NHSN solutions comply with enterprise security policies, standards, and compliance requirements. \n
- Support implementation of security controls required for CDC cloud environments and application deployments. \n
- Participate in architecture reviews, security assessments, and technical planning activities as needed. \n
- Assist engineering teams in evaluating and securely implementing emerging technologies, including AI-assisted software development and automation. \n, Beware of fake employment opportunities using Leidosâ name. Leidos will never ask you to provide payment-related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system - never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at LeidosCareersFraud@leidos.com. \n \n If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission. \n \n \nCommitment to Non-Discrimination \n \n All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws. \n \n #Remoteâ, âhiringOrganizationâ: {â@typeâ: âOrganizationâ, ânameâ: âLeidosâ, âlogoâ: âhttps://jobs.military.com/attachments/employer/0/962/152/273.svgâ}, âjobLocationâ: {âaddressâ: {âaddressCountryâ: âUnited Statesâ, âstreetAddressâ: âNot specifiedâ, â@typeâ: âPostalAddressâ, âpostalCodeâ: â30330â, âaddressLocalityâ: âAtlantaâ, âaddressRegionâ: âGeorgia - GAâ}, â@typeâ: âPlaceâ}, âindustryâ: âOther Services (except Public Administration)â, âidentifierâ: {â@typeâ: âPropertyValueâ, ânameâ: âLeidosâ, âvalueâ: âR-00187720â}, âbaseSalaryâ: {â@typeâ: âMonetaryAmountâ, âcurrencyâ: âUSDâ, âvalueâ: {âminValueâ: â107900â, â@typeâ: âQuantitativeValueâ, âmaxValueâ: â195050â, âvalueâ: â107900â, âunitTextâ
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on jobs.military.comGood distractions
Talks and stories from around this role â technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What Are The Top Skills Required For Azure Developers?
Whatâs the Difference between a Junior, Mid, and Senior Developer?
What is Software Engineering?
The Most Popular IT Jobs on the Market