> Markdown version of [/jobs/ext/2717401-security-engineer-federal-fieldops](https://www.wearedevelopers.com/jobs/ext/2717401-security-engineer-federal-fieldops). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - Federal (FieldOps) - **Company:** C3.ai, Inc. - **Location:** Tysons, VA, United States - **Experience:** Expert - **Salary:** $134,000.0 - $167,000.0 - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Artificial Intelligence, Software as a Service, Cloud Computing Security, Cyber Security, Linux, Federal Information Processing Standards (FIPS), Python (Programming Language), Security Content Automation Protocol, Software Vulnerability Management, Workflow Management Systems, Scripting, Information Technology, Devsecops, Security Orchestration, Automation & Response, Plan of Action and Milestones - **Published:** September 4, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88233233/1 ## About the Role This role requires US Citizenship or US Permanent Residence. Active security clearance (Secret or higher) is preferred., * Bachelor's degree in Computer Science, Information Security, or a related field * Minimum of 5+ years of experience in information security, DevSecOps, or a related field * Strong understanding of security principles, practices, and technologies * Experience with vulnerability management activities (CVEs, IOCs, etc.) * Experience with Linux and scripting languages such as JavaScript, Shell, and/or Python * Excellent problem-solving skills and attention to detail * Strong communication and collaboration skills * Active DoD 8570 IAT II or above certification (e.g., CISSP or Security+), or ability to obtain * Hands-on experience with SCAP/OpenSCAP tooling and automated STIG scanning/remediation, * Experience with cloud security and securing cloud-based applications * Familiarity with regulatory requirements and industry standards such as NIST 800-53, CMMC, and FedRAMP * Experience with security automation and orchestration tools * Experience with hardened container registries (e.g., Iron Bank, Chainguard), FIPS 140-2/3 validation, and SBOM generation/traceability tooling Candidates must be authorized to work in the United States without the need for current or future company sponsorship. ## Description C3 AI is seekingan experienced Federal Security Engineer to serve as the named technical owner of release-gate evidence, Continuous Monitoring (ConMon) automation, and the security engineeringinterface with our FedRAMP and ATO boundary partner, for our Federal team in Tysons, Virginia. The ideal candidate will ensure Federal deployments meet C3 AI's rigorous security standards and comply with Federal Security Requirements across the full deployment lifecycle., * Own per-release gate evidence across the 8 gates defined in the Federal Release-Gate Standard (image CVE disposition, allowlist, SCAP/STIG, FIPS validation, Federal BOM) - no evidence, no GA * Work with cross-functional teams to build and maintain ConMon automation: generated Bill of Materials (BOM), automated drainable-vs-structural POA&M classification, and a live ConMon metrics feed * Serve as the engineering-level interface with SMX on FedRAMP boundary-register items (image provenance, patch-uplift vs. CA-6, SCAP scope) * Address unique Federal customer security requirements without compromising core solution integrity * Support high-visibility defense and intelligence projects with stringent security requirements * Triage and resolve security vulnerabilities reported by Federal customers * Ensure solutions comply with technical security requirements for domain-specific programs (e.g., STIG, SCAP/OpenSCAP) * Manage hardened container registries (e.g., Iron Bank, Chainguard) for Federal deployments * Work with product, engineering, and compliance teams to upstream controls and resolve issues * Overlay customer-specific controls while maintaining C3 AI's standard security posture * Discover and remediate security vulnerabilities in Federal systems and applications * Collaborate with Information Security, Product, Engineering, and Operations to implement security best practices and ensure compliance with industry standards * Stay up-to-date with the latest security trends, vulnerabilities, and technologies ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)