> Markdown version of [/jobs/ext/3040455-principal-information-security-engineer](https://www.wearedevelopers.com/jobs/ext/3040455-principal-information-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Information Security Engineer - **Company:** Clarity - **Location:** Springfield, MA, United States - **Experience:** Expert - **Salary:** $139,000.0 - $314,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Artificial Intelligence, User Authentication, Cloud Computing, Cloud Computing Security, Cyber Security, Continuous Delivery, Continuous Integration, Data Security, Linux, Identity and Access Management, Internet Security, Key Management, Linux Security Modules, Network Segmentation, Systems Development Life Cycle, Security Software, Software Engineering, Software Vulnerability Management, Data Logging, Data Classification, Software Security, Model Validation, Data Management, Cyber Warfare, Devsecops, Vulnerability Analysis - **Published:** September 23, 2026 - **Apply:** https://www.careerbuilder.com/job-details/sr-principal-information-security-engineer-springfield-va--6c79fc4c-6f7e-4499-a2be-25d88df3bf53 ## About the Role * RMF * cATO/DevSecOps security practices * Security architecture * Threat modeling * Vulnerability management * Security testing * Application security * API security * Container security * Kubernetes security * Cloud security * Identity and access management * Authentication/authorization * Encryption and key management * Logging and security monitoring * Linux security * Network segmentation * Data classification and handling * Secure SDLC * SBOM and software supply-chain security * NIST cybersecurity frameworks * STIGs and/or applicable government security controls * AI/ML security and AI assurance, Artificial Intelligence (AI), Authentication, Cloud Computing, Computer Security, Continuous Deployment/Delivery, Continuous Integration, Cryptography, Cyber Warfare, Documentation, Government, Identity Data Management, Information Warfare (IW), Information/Data Security (InfoSec), Integrated Circuits (ICs), Intelligence Community, Internet Security, Linux Operating System, Model Review, Operations Security (OPSEC), Risk Analysis, Security Architecture, Security Compliance, Security Monitoring, Security Software, Software Development Lifecycle (SDLC), Software Engineering, Test Plan/Schedule, Testing, Threat Modeling, U.S. National Institute of Standards and Technology (NIST), United States Department of Defense (DoD) ## Description The Security/AI Assurance Engineer will ensure that all capabilities developed by the team comply with security requirements, classification boundaries, IC security policies, and applicable RMF/cATO processes. Security will be incorporated throughout architecture, development, testing, deployment, and sustainment rather than treated as a final approval activity. The engineer will conduct security architecture reviews, threat modeling, vulnerability assessment, security testing, AI-specific risk assessment, and compliance documentation. The position will also support the Government''s software approval process and work closely with the platform and software engineers to automate security controls wherever practical. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)