> Markdown version of [/jobs/ext/2253429-lead-security-engineer](https://www.wearedevelopers.com/jobs/ext/2253429-lead-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Security Engineer - **Company:** Bart & Associates - **Location:** Suitland-Silver Hill, MD, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Testing (Software), Application Programming Interfaces (APIs), Applications Architecture, Software System Penetration Testing, Systems Engineering, User Authentication, Automation of Tests, Cloud Computing, Cloud Computing Security, Configuration Management, Cyber Security, Information Systems, Continuous Delivery, Continuous Integration, Data Validation, Data Security, Internet Security, Information Systems Security Architecture Professional, Systems Development Life Cycle, Zero Trust Network Access, Security Software, Security Information and Event Management, Software Engineering, Software Vulnerability Management, Data Logging, Enterprise Software Applications, Delivery Pipeline, Software Security, Multi-Cloud, Information Technology, Code Inspection, Devsecops, Cisco, Plan of Action and Milestones, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** August 26, 2026 - **Apply:** https://www.careerbuilder.com/job-details/lead-security-engineer-suitland-md--04d5275c-45c5-4e72-831d-deced0912309 ## About the Role * Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field * 15+ years of relevant IT/cybersecurity experience, providing technical and management leadership on major tasks or technology assignments (SME level), * Demonstrated expertise integrating security into a DevSecOps SDLC, including CI/CD security gates and automated security testing * Hands-on experience implementing Zero Trust Architecture and applying NIST SP 800-53 controls and the NIST Cybersecurity Framework * Proven experience leading vulnerability assessments, penetration testing, and threat modeling for enterprise applications * Experience supporting the ATO lifecycle and managing POA&Ms, security artifacts, and evidence collection Certifications Required: * Certified Information Systems Security Professional (CISSP) * Certified Cloud Security Professional (CCSP) Desired: * Certified Information Security Manager (CISM) * Certified Information Systems Auditor (CISA) Desired Skills * Experience generating Software Bill of Materials (SBOMs) and implementing software supply-chain security controls * Familiarity with SIEM deployment, container/image hardening, and secure baseline configuration * Experience in large-scale, multi-cloud federal environments and FedRAMP processes * Strong analytical, problem-solving, written, and verbal communication skills, including the ability to brief senior Government stakeholders, Analysis Skills, Application Programming Interface (API), Applications Security, Architectural Analysis, Authentication, Bill of Materials (BOM), CCSP - Cisco Certified Security Professional, CISA - Certified Information Systems Auditor, CISM - Certified Information Security Manager, CISSP - Certified Information Systems Security Professional, Cloud Computing, Communication Skills, Computer Science, Computer Security, Configuration Management, Continuous Deployment/Delivery, Continuous Integration, Cryptography, EEO Regulations, Employee Assistance Plan, Enterprise Applications, Entrepreneurship, Financial Management, Financial Planning, Funding, Government, Homeland Security, ISA Standards, Incident Response, Information Technology & Information Systems, Information/Data Security (InfoSec), Internet Security, Leadership, Legal, Maintain Compliance, Mentoring, Metrics, Penetration Testing, Presentation/Verbal Skills, Privacy Impact Assessment (PIA), Problem Solving Skills, Reporting Dashboards, Security Analysis, Security Attacks, Security Clearance, Security Information and Event Management (SIEM), Security Monitoring, Seminars, Social Security Administration, Software Development, Software Development Lifecycle (SDLC), Software Engineering, Software Testing, Systems Engineering, Team Building, Team Player, Technical Leadership, Test Automation, Test Plan/Schedule, Threat Modeling, U.S. National Institute of Standards and Technology (NIST), United States Customs, United States Navy (USN), Writing Skills ## Description We are seeking a Subject Matter Expert (SME)-level Lead Security Engineer to lead application security across a large-scale, cloud-native federal modernization program supporting the U.S. Census Bureau's Decennial Transformation and Application Modernization (DTAM) effort. This role provides technical and management leadership on major security tasks, embedding security into every phase of the System Development Life Cycle (SDLC) using a DevSecOps methodology. The ideal candidate will architect and enforce Zero Trust principles, drive Authorization to Operate (ATO) activities, and direct application security testing, threat modeling, and vulnerability remediation across a System of Systems (SoS). This position interfaces with senior Government stakeholders and the Office of Information Security (OIS), and decision-making and domain knowledge may have a critical impact on overall program implementation. May supervise others., * Lead the design and implementation of application security solutions, frameworks, and processes across all phases of the SDLC, in compliance with U.S. Census Bureau (USCB) and Office of Information Security (OIS) policies * Implement Zero Trust (ZT) principles for applications, workloads, and data, aligned with EO 14028, OMB M-22-09, and NIST SP 800-207 (Zero Trust Architecture) * Integrate security into DevSecOpsCI/CD pipelines, establishing security gates, automated code inspection, and supply-chain controls including Software Bill of Materials (SBOM) generation * Direct Static and Dynamic Application Security Testing (SAST/DAST), vulnerability assessments, and penetration testing to identify, triage, and remediate security weaknesses * Lead threat modeling exercises to analyze application architecture, identify attack vectors, and document mitigation strategies throughout design, development, testing, and deployment * Support the Authorization to Operate (ATO) process, including security control assessment, artifact and evidence collection, Privacy Threshold Analysis/Privacy Impact Assessment support, and Plan of Action and Milestones (POA&M) management * Implement security controls in accordance with the NIST Cybersecurity Framework and NIST SP 800-53, and remediate identified vulnerability and compliance findings * Design and implement secure architecture patterns - secure API design, authentication/authorization, input validation, encryption, secure logging and monitoring (SIEM), and secure error/session/configuration management * Develop and maintain metrics, dashboards, and reporting to track application security posture, threat trends, and remediation progress over time * Support the development and management of Interagency Security Agreements (ISA), security playbooks, and incident response in accordance with current cybersecurity policies * Collaborate with application developers, data engineers, systems engineers, and OIS to identify and mitigate vulnerabilities, and provide expert security consultation to development teams * Assist in FedRAMP certification activities and the assessment/remediation of independent penetration testing results, as applicable, B&A has launched several programs to focus on employee engagement, wellness, and assistance. These include: * The B&A Cares program: 30/60/90-day wellness check ins, personal development, financial management, and stress management seminars, and more * A formal mentorship program * Job shadowing and cross training opportunities * Brand Ambassador program * Employee Assistance Program (EAP) - Access to various support resources to include counseling, legal guidance, financial planning, and more * Monthly teambuilding events * B&A Annual Wellness Challenges: #StepWithB&A, #WalkDuringLunchWithB&A, #VolunteeringWithB&A, #ExerciseDuringLunchWithB&A, and more At B&A, we place significant importance on improving the communities and lives of citizens across the nation through our involvement, technology expertise, and employees. B&A puts an emphasis on charitable efforts in the Northern Virginia area, including Capital Area Food Bank pantry drives, book donations, Hope for Henry Foundation events, and many more. In recognition of all these efforts, B&A has been named a Companies as Responsive Employers (CARE) award recipient by Northern Virginia Family Services and nominated by the Northern Virginia Chamber of Commerce for Outstanding Corporate Citizenship Award. EEO B&A provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran in accordance with applicable federal, state and local laws. B&A complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities. This policy covers conduct occurring at B&A's offices, and other workplaces (including client sites) and all other locations where B&A is providing services, and to all work-related activities. EEO is the Law B&A participates in e-Verify. We provide the Social Security Administration (SSA) and, if necessary, the Department of Homeland Security (DHS) with information from each new employee's I-9 Form to confirm work authorization. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [The Open-source Java SDK for Multi-Cloud Development - Sandeep Pal](https://www.wearedevelopers.com/videos/2113-the-open-source-java-sdk-for-multi-cloud-development-sandeep-pal) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)