> Markdown version of [/jobs/ext/1819780-lead-security-engineer](https://www.wearedevelopers.com/jobs/ext/1819780-lead-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Security Engineer - **Company:** iWorks Corporation - **Location:** United States - **Experience:** Expert - **Salary:** $135,000.0 - $170,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Information Systems, Data Systems, Intrusion Detection and Prevention, Information Systems Security Architecture Professional, Secure Coding, Security Software, Security Information and Event Management, Software Engineering, Software Vulnerability Management, Software Security, Cloudformation, Gitlab-ci, Information Technology, Terraform, Stream Processing, Oracle Cloud Infrastructure, Devsecops, Docker, Jenkins, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** July 31, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9068713/lead-security-engineer ## About the Role * Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or related field (or equivalent experience) * 15+ years of experience in cybersecurity and/or security engineering role * Demonstrated experience leading technical and management efforts on large-scale IT or federal programs * Proven ability to define goals, plans, and execution strategies for complex security initiatives * Experience interfacing with senior government or enterprise stakeholders Cybersecurity Frameworks & Compliance * NIST Risk Management Framework (RMF) * NIST 800-53 security controls * FedRAMP security requirements * Security Authorization processes * SSPs and POA&Ms * Vulnerability management programs Application & Software Security * Secure Software Development Lifecycle (SSDLC) * Application security architecture * Secure coding practices * SAST/DAST/SCA tools * Dependency and vulnerability scanning * SBOM processes * API security DevSecOps Security * Security integration into CI/CD pipelines * GitLab CI/CD security practices * Jenkins security integrations * Azure DevOps security controls * Automated security testing Cloud & Container Security * AWS GovCloud, Azure Government, OCI Government, or GCP * Cloud security architecture * Kubernetes security * Docker/container security * Infrastructure-as-Code security reviews * Terraform and CloudFormation security considerations Security Operations * SIEM platforms * Security monitoring * Threat detection * Security analytics * Continuous monitoring practices Preferred Certifications: * Certified Information Systems Security Professional (CISSP) * Certified Cloud Security Professional (CCSP) * Certified Information Security Manager (CISM) * Certified Information Systems Auditor (CISA) Please Note: We maintain an on-camera policy for all virtual company meetings to foster engagement and collaboration. Reasonable exceptions may be granted with prior approval from Human Resources and/or the applicable manager or client. ## Description This role provides both technical and management leadership across enterprise security initiatives, ensuring secure modernization of applications, data systems, and cloud infrastructure. The position plays a critical role in embedding security into DevSecOps pipelines and supporting secure, scalable, near real-time data processing and analytics., 1. Provide technical and management leadership across major security and modernization initiatives supporting DTAM objectives 2. Define and execute project goals, plans, and methods aligned with federal cloud modernization efforts 3. Direct security engineering activities across application development, integration, and operations environments 4. Ensure delivery of secure systems through DevSecOps practices and enterprise security governance 5. Lead implementation of application security controls, policies, and frameworks 6. Oversee security architecture standards, design reviews, and technical trade-off analyses 7. Support vulnerability management, security testing, audits, and authorization activities 8. Guide integration of security tooling into CI/CD pipelines and cloud-native environments 9. Manage staffing, delivery methods, and financial oversight for assigned security workstreams 10. Engage with client stakeholders and senior leadership through briefings, negotiations, and technical consultations 11. Supervise and mentor security engineering staff as assigned ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [The Road to MLOps: How Verivox Transitioned to AWS](https://www.wearedevelopers.com/videos/1050-the-road-to-mlops-how-verivox-transitioned-to-aws) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Enterprise-Cloud-Native - Fast-Paced Development & Deployment in a Highly Secure Banking Environment](https://www.wearedevelopers.com/videos/671-enterprise-cloud-native-fast-paced-development-deployment-in-a-highly-secure-banking-environment) - [Implementing Feature Environments with AWS and Terraform](https://www.wearedevelopers.com/videos/531-implementing-feature-environments-with-aws-and-terraform) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)