> Markdown version of [/jobs/ext/2805247-security-engineer](https://www.wearedevelopers.com/jobs/ext/2805247-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** CareerCircle - **Location:** Bethesda, MD, United States (Remote available) - **Experience:** Expert - **Salary:** $131,300.0 - $237,350.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Agile Methodology, Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Systems Engineering, User Authentication, Cloud Computing, Cloud Engineering, Configuration Management, Signals Intelligence, CompTIA Security+, Cyber Security, Information Systems, Continuous Integration, Linux, Digital Forensics, Firmware, Monitoring of Systems, Identity and Access Management, Integrated Development Environments, Networking Hardware, Intrusion Detection and Prevention, Information Systems Security Architecture Professional, JavaScript Libraries, Python (Programming Language), Key Management, Network Security, Network Layer, Network Architecture, Network Protocols, Windows PowerShell, Release Management, Ansible, Red Team (Cyber Security), Reverse Engineering, Secure Coding, Security Information and Event Management, Software Deployment, Software Engineering, SonarQube, Software Vulnerability Management, Network Routing, Scripting, Google Cloud, Enterprise Software Applications, Computer Network Operations, ReactJS, Large Language Models, Cyber Threat Analysis, Firewalls (Computer Science), Infrastructure as Code (IaC), Gitlab, Cloudformation, Containerization, Gitlab-ci, Kubernetes, Information Technology, Production Code, Nessus, Terraform, Oracle Cloud Infrastructure, Splunk, Devsecops, Api Management, Docker, Jenkins, Plan of Action and Milestones, Vulnerability Analysis, Programming Languages - **Published:** September 9, 2026 - **Apply:** https://www.careercircle.com/jobs/all/all/usa/all/all/9a8e40d4-94a4-48d0-8032-a3889b349403 ## About the Role * 8+ years of professional experience in security engineering, secure software development, or infrastructure security. * Experience securing and using agentic tooling for writing and maintaining production code, managing cloud infrastructure, and release management frameworks. * Experience owning security outcomes for a technical product from ideation to production, and influencing engineering teams toward secure design without direct authority. * Experience hardening software deployments, networks, and production infrastructure at scale. * Experience securing software clusters for online/cloud as well as on-prem or air-gapped installations. * Experience with threat modeling, vulnerability management, and secure development practices across first- and third-party code. * Familiarity with NIST RMF, continuous ATO, and control automation., * 15+ years Hands-on experience securing and hardening Linux systems at the OS and network layer * Expertise in at least one scripting language (Python preferred) * Working knowledge of network protocols, cryptographic fundamentals, and key management * Experience with infrastructure-as-code and containerization (Ansible/Terraform, Docker/Kubernetes) * Experience administering or securing a CI/CD system (GitLab CI, Jenkins, or similar), * Experience working in accredited/classified environments, including cross-domain solutions * Offensive security background - penetration testing, red team, or serious CTF experience * Detection engineering or SIEM experience * Experience with embedded, real-time, or otherwise constrained platforms * Exposure to reverse engineering or vulnerability research * Relevant certifications (CISSP, OSCP, GCIH) - useful, not required * Non-human/agent identity and secrets management - short-lived credentials, scoping, and audit for autonomous actors, which is a genuinely different problem than human IAM. * Sandboxing and egress control for code-executing agents. * Familiarity with NIST AI RMF and the fact that continuous-ATO control automation now has to cover AI system controls, not just traditional ones. * Using LLMs to accelerate the compliance grind control narrative drafting, evidence collection, POA&M triage. ## Description CI/CD Gitlab Writing Ansible Tooling On Prem Jenkins Auditing Research Ideation Equities Scripting Terraform Hardening Pipelines Operations Management Automation Kubernetes Market Data AI Security Supply Chain Cryptography Law Enforcement Threat Modeling Production Code Ancient History Containerization Threat Detection Operating Systems Docker (Software) Network Protocols Release Management Workflow Management Penetration Testing Evidence Collection GIAC Certifications Security Engineering Software Engineering Software Development Cloud Infrastructure Artificial Intelligence Development Environment Infrastructure Security Research And Development Internet Of Things (IoT) Vulnerability Management Computer Network Operations Infrastructure as Code (IaC) Python (Programming Language) GIAC Certified Incident Handler Plan Of Action And Milestones (POA&M) Application Programming Interface (API) Offensive Security Certified Professional Security Information And Event Management (SIEM) Certified Information Systems Security Professional, We are looking for a Security Engineer to own the security posture of the environments where we build, test, and deliver advanced AI-cyber capabilities. You will be embedded with software engineers, reverse engineers, and vulnerability researchers, hardening the infrastructure, supply chains and pipelines on while guiding their secure development. The work includes guiding and reviewing build integrity and supply chain review to threat modeling our own tooling. If you have ever looked at a supply chain & development environment and immediately started listing the ways you would secure it, this is the job. You will be the person the team trusts to tell them when something is a real risk and when it is just noise As an AI Security Integration Engineer on our team, you will bridge the gap between traditional security infrastructure and modern programmatic defense. You will guide the secure development and evolution of software vulnerability tooling. Your primary focus will be working with the development team to maintainmaintaining the tool security posture utilizing continuous ATO. review workflows and pipelines by leveraging Python, assessing robust API integrations, maintained exploring AI/LLM orchestration to rapidly scale threat detection and response capabilities. Support ATO and continuous vuln management., CI/CD Splunk Nessus Rapid7 Ansible Auditing Firewall Equities Scripting SonarQube DevSecOps Pipelines Operations Automation Purchasing Upskilling Market Data Coordinating Oracle Cloud Cryptography Investigation Cyber Security Key Management Risk Management Authentications Cloud Computing Ancient History Network Security Security Controls Incident Response CompTIA Security+ Digital Forensics System Monitoring Endpoint Security Cyber Engineering Analytical Method Windows PowerShell AWS CloudFormation Systems Engineering Amazon Web Services Time Off Management Security Engineering Software Development Contingency Planning Signals Intelligence Programming Languages Regulatory Frameworks Vulnerability Scanning Security Configuration Cyber Security Policies Configuration Management Vulnerability Management Certified Ethical Hacker Cyber Security Standards Cybersecurity Compliance Risk Management Framework Authorization (Computing) Cyber Threat Intelligence Cyber Security Assessment IT Security Documentation Agile Software Development Splunk Enterprise Security Google Cloud Platform (GCP) Computer Network Operations Change Management Processes Information Systems Security Customer Information Systems React.js (Javascript Library) Python (Programming Language) Enterprise Application Software Endpoint Detection And Response Troubleshooting (Problem Solving) Host Based Security System (HBSS) Intrusion Detection And Prevention CompTIA Cybersecurity Analyst (CySA+) Plan Of Action And Milestones (POA&M) Security Information And Event Management (SIEM) Certified Information Systems Security Professional Top Secret-Sensitive Compartmented Information (TS/SCI Clearance) +0 Information Systems Security Engineer Leidos Linthicum, MD*On-Site Planning Firewall Firmware Equities Mitigation CNSSI 1253 Market Data Gap Analysis Risk Analysis Risk Management Network Routing Ancient History Computer Science Security Systems Operating Systems Security Policies Network Protocols Information Privacy Networking Hardware Network Engineering Network Architecture Information Assurance Communications Systems Information Systems Security Security Requirements Analysis Certified Information Systems Security Professional Top Secret-Sensitive Compartmented Information (TS/SCI Clearance) +0 Google IT Support Senior Security Engineer Leidos Columbia, MD*On-Site Linux CI/CD Gitlab Writing Ansible Tooling On Prem Jenkins Auditing Research Ideation Equities Scripting Terraform Hardening Pipelines Operations Management Automation Kubernetes Market Data AI Security Supply Chain Cryptography Law Enforcement Threat Modeling Production Code Ancient History Containerization Threat Detection Operating Systems Docker (Software) Network Protocols Release Management Workflow Management Penetration Testing Evidence Collection GIAC Certifications Security Engineering Software Engineering Software Development Cloud Infrastructure Artificial Intelligence Development Environment Infrastructure Security Research And Development Internet Of Things (IoT) Vulnerability Management Computer Network Operations Infrastructure as Code (IaC) Python (Programming Language) GIAC Certified Incident Handler Plan Of Action And Milestones (POA&M) Application Programming Interface (API) Offensive Security Certified Professional Security Information And Event Management (SIEM) Certified Information Systems Security Professional +0 ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)