> Markdown version of [/jobs/ext/1470524-security-engineer-public-sector](https://www.wearedevelopers.com/jobs/ext/1470524-security-engineer-public-sector). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer, Public Sector - **Company:** Scale Inc - **Location:** Seattle, WA, United States - **Experience:** Expert - **Salary:** $218,400.0 - $342,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cloud Computing, Cyber Security, Digital Forensics, Forensics Tools (Digital Forensics Software), Intrusion Detection and Prevention, Python (Programming Language), Node.Js, Cloud Services, Runbook, Security Information and Event Management, TypeScript, Data Logging, Google Cloud, Malware, Kubernetes, Cybercrime, Production Code, Software Version Control, Security Orchestration, Automation & Response, Vulnerability Analysis - **Published:** July 28, 2026 - **Apply:** https://www.dice.com/job-detail/4dd44c6a-502e-4764-8caf-ea8842a54cb0 ## About the Role * At least an active Top Secret clearance. This is a requirement and candidates will not be considered who do not hold at least a Top Secret clearance. Ideally, you'd have: * Proficiency in NodeJS, TypeScript, Python, and/or Kubernetes. * 5+ years of experience in Detection Engineering, Incident Response, or Security Operations, with a strong emphasis on building and shipping security tooling and automation. * Proficiency in at least one programming language (e.g., Python, Go) and comfort writing production-grade code - not just scripts. * Hands-on experience designing or improving detection pipelines, SIEM content, and alerting workflows in cloud-native environments. * Practical experience with SIEM, EDR, and SOAR tools, with a preference for candidates who have built integrations or extended these platforms programmatically. * Strong understanding of modern cyber threats, common attack techniques, and adversary TTPs. * Familiarity with digital forensics tools and malware analysis techniques. * Experience with cloud-native environments (e.g., AWS, Google Cloud Platform, Azure) and the security telemetry those environments generate. * Exposure to threat intelligence platforms and integrating intel into detection and investigation workflows. * Strong communication skills, with the ability to translate complex security findings into clear business impact. * Relevant security certifications (e.g., GCIH, GCFA, GCIA, CISSP, GDSA) are a plus. ## Description We are seeking a highly technical Security Engineer to join our Public Sector Infrastructure & Security team as a security generalist. As a generalist you will ensure the security and integrity of our products and platform designing and shipping high-precision detections across cloud services and enterprise SaaS. You won't just investigate incidents, you'll build the systems that detect, contain, and prevent them. Your ability to write production-quality code is just as important as your ability to triage an alert. You will structure investigations, analyze root causes, and clearly communicate the significance of security incidents, their impact, and recommended remediation steps - but you'll also turn those findings into durable engineering improvements: better detections, tighter schemas, and smarter automation. You will: * Engineer, test, and deploy detection logic across cloud and enterprise environments, treating detections as software with version control, peer review, and measurable performance. * Build and maintain incident response automation, runbooks, and tooling that reduce containment timelines without sacrificing developer velocity. * Mature telemetry pipelines through improved schema design, normalization, enrichment, and quality checks that reduce false positives and increase signal fidelity. * Perform digital incident investigations to identify and contain potential security breaches. * Conduct digital forensics and malware analysis to understand attack vectors and adversary methodologies. * Integrate alerting with messaging and ticketing systems to enable fast, traceable response workflows. * Partner cross-functionally with IT, security, and engineering teams to harden identity and access patterns, close logging and forensics gaps, and implement maintainable guardrails that scale with the organization. * Utilize threat intelligence platforms to improve hunting, detection, and response workflows. * Clearly explain the significance and impact of incidents, providing actionable recommendations to both technical and non-technical stakeholders. ## Related Videos - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [Stop using Node.js like in 2020! What changed and what you can do today with Node.js](https://www.wearedevelopers.com/videos/100011-stop-using-node-js-like-in-2020-what-changed-and-what-you-can-do-today-with-node-js) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) - [Bridging AI and Nomad: a Go-based MCP Server for Cluster Control](https://www.wearedevelopers.com/videos/2063-bridging-ai-and-nomad-a-go-based-mcp-server-for-cluster-control) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)