> Markdown version of [/jobs/ext/2005983-security-engineer-fedramp](https://www.wearedevelopers.com/jobs/ext/2005983-security-engineer-fedramp). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer (FedRAMP) - **Company:** Veeam Software Corporation - **Location:** San Jose, CA, United States - **Experience:** Expert - **Salary:** $237,800.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Audit Trail, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, Configuration Management, Data Security, Software Design Patterns, Github, Network Segmentation, PCI Data Security Standards, Software Vulnerability Management, Cloud Platform System, Infrastructure Automation Frameworks, Nessus, CIS Benchmarks, Veeam, Terraform, Vulnerability Analysis - **Published:** August 9, 2026 - **Apply:** https://www.dice.com/job-detail/4fa916be-1a6d-4739-b821-b6bcd1010cdb ## About the Role * 8+ years in security engineering, with hands-on experience securing cloud environments (strong preference for experience in Azure and/or AWS) * Experience delivering cloud products to meet regulated compliance requirements such as government (FedRAMP, CMMC, IL2/IL4/IL5, sovereign cloud), financial services (PCI-DSS), and/or healthcare (HIPAA, HITRUST) * Ability to translate specific compliance controls into concrete architecture and operational decisions (e.g., how an audit logging requirement drives log retention design, or how boundary protection requirements shape network segmentation) * Working knowledge of NIST 800-53, including continuous monitoring, vulnerability management, and configuration management standards * Experience hardening infrastructure to secure baselines such as STIGs or CIS benchmarks * Strong understanding of cloud security fundamentals in identity, network boundaries, encryption, and vulnerability remediation domains * Ability to learn large, complex platforms quickly with limited guidance: Being comfortable building understanding from code, docs, and architecture artifacts * A collaborative, hands-on approach to partnering across engineering, product, security, compliance, and SRE * Deep partner mindset: Ability to take a hands-on approach to enable engineering teams rather than serving as gatekeepers * AI as a force multiplier: AI tools are woven into how we work, and we build security at AI-speed using these tools. We want engineers who treat AI as a force multiplier, not an afterthought Bonus Skills * Experience designing and working with controls to satisfy requirements across multiple compliance frameworks * Hands-on experience with vulnerability scanning tools (e.g. Wiz, Nessus) * Experience with IaC tools (e.g. Terraform) * Experience using GitHub for configuration management and change control * Exposure to supply chain security standards and secure-by-design practices * Relevant certifications (e.g., CISSP, CCSP, or cloud provider security certs) ## Description We're looking for a Senior Security Engineer to support the development and growth of Veeam Data Cloud (VDC), our cloud-native SaaS platform. This role owns hands-on security engineering for VDC's regulated environments, starting with our FedRAMP boundary but extending to the broader set of regulated customer needs we will take on as our platform grows. VDC delivers high-trust, secure data protection services on Microsoft Azure and AWS for customers in regulated industries. You'll partner closely with product, platform engineering, and SRE to embed compliant, secure-by-design patterns into everything we ship - designing controls that satisfy NIST 800-53 today but will adapt to other frameworks as we expand. This is a role with room to shape how security engineering scales across VDC's regulated footprint: you will own the domain end to end, work independently on complex, ambiguous problems, and set baselines, review practices, and remediation standards to keep VDC compliant and secure at scale. Security clearance is not required, but there is a slight chance it maybe requested in the future What You'll Do * Champion secure design patterns that enable compliance-driven engineering across VDC's Cloud environments, including VDC-wide standards such as supply chain security * Support the design and onboarding of new workloads into regulated environments from a security compliance perspective * Partner with VDC Engineering to harden shared infrastructure (e.g. VMs, containers, and operating systems) against secure baselines such as STIGs and CIS benchmarks * Oversee and support vulnerability scanning alongside the Platform team, providing remediation guidance and tracking fixes against SLAs * Support configuration management change control and configuration baseline compliance with Platform Engineering and SRE * Review significant architecture changes across our regulated environments and provide security input on approvals * Build reusable, framework-agnostic guardrails and evidence so security controls scale across FedRAMP, sovereign cloud, and emerging regulatory requirements * Review application and platform code and identify security deficiencies * Align commercial, government, and other product roadmaps so controls and standards carry cleanly across environments and frameworks * Participate in an on-call rotation shared across the Security Engineering team to respond, triage, and resolve alerts to closing ## Related Videos - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [CI/CD with Github Actions](https://www.wearedevelopers.com/videos/856-ci-cd-with-github-actions) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)