Lead Security Engineer

iWorks Corporation
United States
11 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
$135,000.0 - $170,000.0
Working hours
Regular working hours

Tech stack

Kubernetes Security Amazon Web Services Microsoft Azure Cloud Computing Cloud Computing Security Cyber Security Information Systems Data Systems Intrusion Detection and Prevention Information Systems Security Architecture Professional Secure Coding Security Software
+16 more
Security Information and Event Management Software Engineering Software Vulnerability Management Software Security Cloudformation Gitlab-ci Information Technology Terraform Stream Processing Oracle Cloud Infrastructure Devsecops Docker Jenkins Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

This role provides both technical and management leadership across enterprise security initiatives, ensuring secure modernization of applications, data systems, and cloud infrastructure. The position plays a critical role in embedding security into DevSecOps pipelines and supporting secure, scalable, near real-time data processing and analytics., 1. Provide technical and management leadership across major security and modernization initiatives supporting DTAM objectives

  1. Define and execute project goals, plans, and methods aligned with federal cloud modernization efforts
  2. Direct security engineering activities across application development, integration, and operations environments
  3. Ensure delivery of secure systems through DevSecOps practices and enterprise security governance
  4. Lead implementation of application security controls, policies, and frameworks
  5. Oversee security architecture standards, design reviews, and technical trade-off analyses
  6. Support vulnerability management, security testing, audits, and authorization activities
  7. Guide integration of security tooling into CI/CD pipelines and cloud-native environments
  8. Manage staffing, delivery methods, and financial oversight for assigned security workstreams
  9. Engage with client stakeholders and senior leadership through briefings, negotiations, and technical consultations
  10. Supervise and mentor security engineering staff as assigned

Requirements

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or related field (or equivalent experience)
  • 15+ years of experience in cybersecurity and/or security engineering role
  • Demonstrated experience leading technical and management efforts on large-scale IT or federal programs
  • Proven ability to define goals, plans, and execution strategies for complex security initiatives
  • Experience interfacing with senior government or enterprise stakeholders

Cybersecurity Frameworks & Compliance

  • NIST Risk Management Framework (RMF)
  • NIST 800-53 security controls
  • FedRAMP security requirements
  • Security Authorization processes
  • SSPs and POA&Ms
  • Vulnerability management programs

Application & Software Security

  • Secure Software Development Lifecycle (SSDLC)
  • Application security architecture
  • Secure coding practices
  • SAST/DAST/SCA tools
  • Dependency and vulnerability scanning
  • SBOM processes
  • API security

DevSecOps Security

  • Security integration into CI/CD pipelines
  • GitLab CI/CD security practices
  • Jenkins security integrations
  • Azure DevOps security controls
  • Automated security testing

Cloud & Container Security

  • AWS GovCloud, Azure Government, OCI Government, or GCP
  • Cloud security architecture
  • Kubernetes security
  • Docker/container security
  • Infrastructure-as-Code security reviews
  • Terraform and CloudFormation security considerations

Security Operations

  • SIEM platforms
  • Security monitoring
  • Threat detection
  • Security analytics
  • Continuous monitoring practices

Preferred Certifications:

  • Certified Information Systems Security Professional (CISSP)
  • Certified Cloud Security Professional (CCSP)
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Auditor (CISA)

Please Note: We maintain an on-camera policy for all virtual company meetings to foster engagement and collaboration. Reasonable exceptions may be granted with prior approval from Human Resources and/or the applicable manager or client.

Benefits & conditions

We offer exceptional comprehensive benefits (Medical, Dental, Vision, Life and Disability); 401(k); Health and Wellness Benefits; and Paid Sick Time, Vacation Time, and Holiday Time. Employees are eligible for bonuses throughout the year as part of our incentive program for innovation and business development. All employees are also considered for an annual raise, commensurate with performance and company commitment., Salary Range: -$135K - $170K commensurate with the candidate’s skills, experience, location, and qualifications.

About the company

iWorks Corporation, founded in 2005, is a leading provider of information technology and professional services to the federal government. We are a recognized leader in personnel security and vetting solutions, Agile, DevOps, DevSecOps, data analytics, and cloud solutions. Our continuous process improvement approach, combined with our business and technology expertise, results in innovative solutions., iWorks is committed to maintaining a safe and productive work environment for all employees and ensuring the security and well-being of our clients. As part of our standard hiring process, we may conduct background checks and drug screenings on potential candidates to assess their suitability for employment.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · WWC 2025

1:02 min

Applying an ETL methodology to infrastructure configuration management

Axel Barbier · WWC 2023

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · WWC Europe 2026

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

Videos

See all

Related articles

See all