> Markdown version of [/jobs/ext/1429088-security-engineer-lead](https://www.wearedevelopers.com/jobs/ext/1429088-security-engineer-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer Lead - **Company:** TSTC, INC. - **Location:** Colorado Springs, CO, United States (Remote available) - **Experience:** Expert - **Salary:** $155,000.0 - $170,000.0 - **Contract:** Temporary contract - **Skills:** Burp Suite, Configuration Management, Cyber Security, Microsoft Office, Diagnostic Tools, IAd (Apple'S Advertising Platform), Cyberark, Virtual Environment, Information Technology, Plan of Action and Milestones - **Published:** July 24, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=14a31f1831ad7a1a ## About the Role TSTC is looking for a security engineer lead with depth of knowledge in the nuances of government security engineering requirements and policies. We need someone who is self-motivated, able to work in a geographically dispersed team of highly technical security personnel, and who loves problem solving. The ideal candidate combines hand's on security engineering with the ability to translate that and help manage tasks for more junior level staff and is discussing complex topics with senior leadership., * Bachelor's Degree and 15 years of related security engineering experience * Must have a CISSP or a CISM * Provide subject matter expertise to the security requirements allocation and security architecture processes ## Description * Provide expert technical guidance in translating National Institute for Standards and Technology (NIST), and government agency cybersecurity standards, policies, and procedures into actionable tasks including: + Reviewing and analyzing all evidence used to verify security vulnerabilities have been sufficiently addressed and/or system artifacts such as those used in the Assessment & Authorization (A&A) process, i.e. Security Plan (SP), Contingency Plan (CP), Contingency Plan Test (CPT), Incident Response Plan, and Configuration Management Plan (CMP), as some, but not all examples + Reviewing draft documents and providing feedback on allocation of security and privacy requirements (e.g. technical review board (TRB), review of security policies, risk assessments, contingency plans, Plan of Action & Milestone (POA&M) reports) + Determining the security impact of new technologies or policies (e.g., Continuous Diagnostics & Mitigation (CDM) technologies, anomaly-based tools, virtual environments, etc.) on the TSA information security program for TSA review and approval. The review of security impact should be documented through the completion of the Security Impact Analysis (SIA) process as documented by TSA's Information Assurance and Cybersecurity Division (IAD) + Ensuring security requirements are identified, appropriately allocated, and addressed throughout the TSD/SFD mission systems' architectures * Experience with Security scan tools and techniques. Examples include: + Tenable Security Center + Invicti 360 + Trustwave DbProtect + CyberArk Certificate Manager (formerly known as Venafi) + Portswigger Burp Suite Pro * Lead the preparation of responses to federal ad hoc reporting requirements * Lead written reviews or assessments in the form of short briefings, written documents, or presentations (expected average of 5-8 per month) as accomplishment reports of Ad hoc Security Engineering services provided (Deliverable #4) * Help develop alternatives of IT system designs and/or architectures which consider trade-offs between security requirements, functional/operational requirements and cost for TSA review and final approval * Help determine the impact of new or changing applicable NIST, DHS, and TSA cybersecurity standards and policy changes * Lead the impact assessments of new or revised legislation and regulations (examples are OMB Memos and Federal Information Security Modernization Act (FISMA)) for review. Lead and support standard operating procedure documentation and updates * Support weekly security team staff meetings * Review and ensure security compliance deliverables are accurate and correct * Skilled in MS office Suite * Works independently, proactively identifies, and completes task * Excellent verbal and written skills ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Building Security Champions](https://www.wearedevelopers.com/videos/193-building-security-champions) - [ Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [Software Engineer Career: Things You Should Know](https://www.wearedevelopers.com/magazine/143-software-engineer-career-things-you-should-know)