> Markdown version of [/jobs/ext/2203134-mid-security-information-assurance-engineer](https://www.wearedevelopers.com/jobs/ext/2203134-mid-security-information-assurance-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Mid Security Information Assurance Engineer - **Company:** Caci Inc - **Location:** Denver, CO, United States - **Experience:** Experienced - **Salary:** $63,300.0 - $129,700.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Cloud Computing, Cyber Security, Geospatial Intelligence, Secure Coding, Cloud Platform System, Kubernetes, Information Technology, Nessus, Devsecops, Vulnerability Analysis - **Published:** August 23, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9024628/mid-security-information-assurance-engineer ## About the Role * TS/SCI Security Clearance with ability to obtain Polygraph * Bachelor's degree in Cybersecurity, Computer Science, or a related technical discipline (equivalent experience accepted). * 4+ years of security engineering or information assurance experience. * Experience implementing NIST RMF controls on DoD or IC systems. * Hands-on experience with STIG hardening, ACAS/Nessus, and security remediation. * DoD 8570/8140 IAT Level II certification (Security+ CE or equivalent). * Ability to work on-site at a Government facility. Desired: * Experience securing Kubernetes, containers, or cloud environments (AWS/C2S). * Experience integrating security scanning into CI/CD pipelines. * Prior experience supporting NGA or the Intelligence Community. ## Description * Serve as a security engineer embedded with an Agile program delivering GEOINT capabilities to the National Geospatial-Intelligence Agency (NGA). * Work on-site at a Government facility, side by side with mission stakeholders and system owners. * Engineer security into modern, cloud-native systems rather than bolting it on after the fact. * Play a direct role in achieving and maintaining system authorizations for mission-critical capabilities., * Design and implement security controls across applications, platforms, and infrastructure in accordance with RMF and NGA standards. * Integrate security tooling and automated compliance checks into CI/CD pipelines (DevSecOps). * Perform system hardening, vulnerability assessment, and remediation across development and production environments. * Support security assessment and authorization activities in coordination with Government ISSMs and assessors. * Analyze findings, develop mitigation strategies, and maintain POA&Ms through closure. * Advise development teams on secure design, secure coding, and security architecture decisions. * Document security engineering artifacts supporting ATO and continuous monitoring. ## Related Videos - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [Dev Digest 162: AI careers, MCP, AWS best practices & floppy sweaters](https://www.wearedevelopers.com/magazine/571-dev-digest-162-ai-careers-mcp-aws-best-practices-floppy-sweaters)