> Markdown version of [/jobs/ext/2613216-information-security-engineer-principal](https://www.wearedevelopers.com/jobs/ext/2613216-information-security-engineer-principal). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Engineer - Principal - **Company:** ASRC Federal Holding Company - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Cloud Computing Security, Cyber Security, Continuous Integration, Zero Trust Network Access, SC Clearance, Information Technology, Tenable Nessus, Nessus, Devsecops, Vulnerability Analysis - **Published:** August 18, 2026 - **Apply:** https://dejobs.org/x/x/42C3C1B4D02B4915BF3F2FF0BD0390EC/job/ ## About the Role * 8-10+ years of cybersecurity or security engineering experience * Active DoD Secret clearance or higher. Candidates without a minimum of a Secret clearance will not be considered. * Expertise with Kubernetes security, container scanning tools, and image hardening * Bachelor's Degree in Computer Science, or other Engineering, or Technical discipline with an Information Security or Cyber Security Concentration, Advanced Degree with concentration in Information Security or Cyber Security are all preferred or 4+ additional years of equivalent professional work experience). * Familiarity with DoD STIGs, RMF, ACAS, Nessus, OpenSCAP, etc. * Experience supporting secure cloud or platform environments * Security certifications preferred (Security+, CEH, CISSP, CCSK, etc.) ## Description * Conduct container and Kubernetes security assessments * Develop hardened configurations and STIG-aligned baselines * Build and maintain security controls for container registries, images, and pipelines * Perform vulnerability scanning, remediation tracking, and reporting * Support RMF accreditation, continuous monitoring, and security engineering tasks * Collaborate with DevSecOps and infrastructure teams to integrate security into CI/CD * Implement zero-trust security patterns and secure deployment workflows * Manage secrets, certificate rotation, and identity enforcement ## Related Videos - [Kubernetes Security Best Practices](https://www.wearedevelopers.com/videos/1411-kubernetes-security-best-practices) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Kubernetes Security - Challenge and Opportunity](https://www.wearedevelopers.com/videos/412-kubernetes-security-challenge-and-opportunity) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)