> Markdown version of [/jobs/ext/3122591-lead-security-engineer](https://www.wearedevelopers.com/jobs/ext/3122591-lead-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Security Engineer - **Company:** Sierra Business Solution LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Audit Trail, Cloud Computing, Cloud Computing Security, Cloud Engineering, Cloud Storage, Cyber Security, System Configuration, Identity and Access Management, Information Systems Security Architecture Professional, Python (Programming Language), Software Vulnerability Management, Data Logging, Scripting, Google Cloud, Cloud Platform System, Event Processing Language, Amazon Virtual Private Cloud (VPC), Kubernetes, Information Technology, Tenable Nessus, Nessus, Codebase, CIS Benchmarks, Software Version Control, Devsecops, Qualys, Vulnerability Analysis - **Published:** September 28, 2026 - **Apply:** https://www.dice.com/job-detail/edefa829-3919-40db-a586-f9c66d6f780c ## About the Role Experience: 7+ years in Cloud Security Engineering, DevSecOps, or Infrastructure Security, with proven experience as a LeadSenior Engineer managing FedRAMP (ModerateHigh) security vulnerability implementations. Cloud Platform Expertise: Strong, hands-on background in Google Cloud Platform (Google Cloud Platform), specifically with Cloud Asset Inventory (CAI), Security Command Center (SCC), IAM, Cloud Audit Logs, and Cloud Storage. Scripting & Languages: Advanced proficiency in Common Expression Language (CEL). Working knowledge of Python, Go, or RegoOPA. Vulnerability Tooling: Practical experience configuring and automating vulnerability and container scanning tools in a large-scale cloud environment. Systems & Infrastructure: Experience with Google Cloud infrastructure and container orchestration (KubernetesGKEBorg). Compliance Knowledge: Strong familiarity with automated control evaluation for NIST SP 800-53 Rev 5, CIS Benchmarks, and FedRAMP Continuous Monitoring (ConMon)., Education: Bachelor s or Master s degree in Computer Science, Information Technology, Cybersecurity, or equivalent practical experience. ## Description The Lead Security Engineer is the primary technical lead responsible for the end-to-end engineering and automation of the FedRAMP Key Security Indicator (KSI) initiative. This role bridges the gap between regulatory compliance and hands-on cloud engineering. The Lead Engineer will design automated cloud controls, manage Google Cloud Platform security vulnerability pipelines, and guide a technical team in deploying solutions that ensure continuous monitoring and secure architectures across Google Cloud Platform (Google Cloud Platform)., Technical Leadership & Translation: Lead discovery workshops to deconstruct FedRAMP KSIs and NIST SP 800-53 controls, translating high-level compliance mandates into binary, automatable technical specifications. Vulnerability Management & Pipelines: Oversee and implement VM vulnerability scanning (AutoVM, Tenable, Qualys, Nessus), container image scanning (Artifact Registry Drydock), and staticdynamic analysis tools. Automation & Scripting: Analyze Google Cloud Asset Inventory (CAI) schemas and oversee the authoring and testing of Common Expression Language (CEL) evaluation rules to define precise PassFail criteria for cloud controls. Pipeline & Telemetry Architecture: Design, deploy, and troubleshoot log agents (FluentbitVector) and Cloud Logging sinks to ensure 100% telemetry coverage across container nodes, VMs, and control-plane APIs. Identity & Access Management (IAM): Architect and enforce least-privilege IAM bindings, service accounts, and VPC Service Controls across the Google Cloud Platform environment. Validation & Deployment: Test logic against synthetic resources in sandbox environments to minimize false positives, manage codebase version control (GitPiper), and support progressive deployment rollouts. Cross-Functional Collaboration: Act as the technical bridge for the project, supporting gap analyses and providing engineering evidence to Governance teams and 3PAO assessors. ## Related Videos - [Getting to Know Your Legacy (System) with AI-Driven Software Archeology](https://www.wearedevelopers.com/videos/1437-getting-to-know-your-legacy-system-with-ai-driven-software-archeology) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Why your codebase lies to AI?](https://www.wearedevelopers.com/videos/100281-why-your-codebase-lies-to-ai) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Refactoring in the Age of AI](https://www.wearedevelopers.com/videos/100223-refactoring-in-the-age-of-ai) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)