Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Lead Security Engineer

Bart & Associates




Apply


Description

Lead Security Engineer

At B&A, we foster and embrace a distinct set of values that we live by and instill in all aspects of our organization: dedication, commitment, partnership, trust, and recognition. We have incorporated these values into successful delivery for our customers since 1988. B&A believes in ensuring its employees feel deeply connected to B&A, recognizing successes and hard work, and providing continuous opportunities to learn and grow. Our people are entrepreneurial thinkers that combine mindset, vision, and experience to drive value - not only to us as an organization, but to the clients we support. We promote a collaborative culture with our clients, and with each other, as one team working towards a common vision. We'd love for you to join our team!

Job Summary

We are seeking a Subject Matter Expert (SME)-level Lead Security Engineer to lead application security across a large-scale, cloud-native federal modernization program supporting the U.S. Census Bureau's Decennial Transformation and Application Modernization (DTAM) effort. This role provides technical and management leadership on major security tasks, embedding security into every phase of the System Development Life Cycle (SDLC) using a DevSecOps methodology. The ideal candidate will architect and enforce Zero Trust principles, drive Authorization to Operate (ATO) activities, and direct application security testing, threat modeling, and vulnerability remediation across a System of Systems (SoS). This position interfaces with senior Government stakeholders and the Office of Information Security (OIS), and decision-making and domain knowledge may have a critical impact on overall program implementation. May supervise others.

Responsibilities

  • Lead the design and implementation of application security solutions, frameworks, and processes across all phases of the SDLC, in compliance with U.S. Census Bureau (USCB) and Office of Information Security (OIS) policies
  • Implement Zero Trust (ZT) principles for applications, workloads, and data, aligned with EO 14028, OMB M-22-09, and NIST SP 800-207 (Zero Trust Architecture)
  • Integrate security into DevSecOps CI/CD pipelines , establishing security gates, automated code inspection, and supply-chain controls including Software Bill of Materials (SBOM) generation
  • Direct Static and Dynamic Application Security Testing (SAST/DAST) , vulnerability assessments, and penetration testing to identify, triage, and remediate security weaknesses
  • Lead threat modeling exercises to analyze application architecture, identify attack vectors, and document mitigation strategies throughout design, development, testing, and deployment
  • Support the Authorization to Operate (ATO) process, including security control assessment, artifact and evidence collection, Privacy Threshold Analysis/Privacy Impact Assessment support, and Plan of Action and Milestones (POA&M) management
  • Implement security controls in accordance with the NIST Cybersecurity Framework and NIST SP 800-53 , and remediate identified vulnerability and compliance findings
  • Design and implement secure architecture patterns - secure API design, authentication/authorization, input validation, encryption, secure logging and monitoring (SIEM), and secure error/session/configuration management
  • Develop and maintain metrics, dashboards, and reporting to track application security posture, threat trends, and remediation progress over time
  • Support the development and management of Interagency Security Agreements (ISA) , security playbooks, and incident response in accordance with current cybersecurity policies
  • Collaborate with application developers, data engineers, systems engineers, and OIS to identify and mitigate vulnerabilities, and provide expert security consultation to development teams
  • Assist in FedRAMP certification activities and the assessment/remediation of independent penetration testing results, as applicable

Education and Experience

  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field
  • 15+ years of relevant IT/cybersecurity experience, providing technical and management leadership on major tasks or technology assignments (SME level)

Required Skills

  • Demonstrated expertise integrating security into a DevSecOps SDLC, including CI/CD security gates and automated security testing
  • Hands-on experience implementing Zero Trust Architecture and applying NIST SP 800-53 controls and the NIST Cybersecurity Framework
  • Proven experience leading vulnerability assessments, penetration testing, and threat modeling for enterprise applications
  • Experience supporting the ATO lifecycle and managing POA&Ms, security artifacts, and evidence collection

Certifications

Required:

  • Certified Information Systems Security Professional (CISSP)
  • Certified Cloud Security Professional (CCSP)

Desired:

  • Certified Information Security Manager (CISM)
  • Certified Information Systems Auditor (CISA)

Desired Skills

  • Experience generating Software Bill of Materials (SBOMs) and implementing software supply-chain security controls
  • Familiarity with SIEM deployment, container/image hardening, and secure baseline configuration
  • Experience in large-scale, multi-cloud federal environments and FedRAMP processes
  • Strong analytical, problem-solving, written, and verbal communication skills, including the ability to brief senior Government stakeholders

Security Clearance

  • U.S. Citizenship required

More About B&A:

Notable Clients
B&A has grown to be a company that is trusted by our clients for exceptional service, innovative solutions, and inspired employees. Our service extends through federal, state, and local Government, the private sector, and higher education. Some of our notable clients include Department of Homeland Security, U.S. Customs and Border Protection, U.S. Senate, U.S. Courts, U.S. Census Bureau, U.S. Navy, and more.

Benefits and Programs

B&A is proud to offer three robust individual and family medical plans to full time employees, including a Health Savings Account (HSA) option as well as two tiers of dental coverage, vision, life & AD&D, disability, accident, hospital indemnity, and critical illness insurance. In addition to these benefits, B&A employees enjoy paid time off, B&A sponsored trainings and certifications, pet insurance benefits, commuter transit benefits and a free subscription to a virtual exercise platform (NEOU). B&A's 401(k) plan is available to all employees and includes a company matching contribution.

B&A has launched several programs to focus on employee engagement, wellness, and assistance. These include:

  • The B&A Cares program: 30/60/90-day wellness check ins, personal development, financial management, and stress management seminars, and more
  • A formal mentorship program
  • Job shadowing and cross training opportunities
  • Brand Ambassador program
  • Employee Assistance Program (EAP) - Access to various support resources to include counseling, legal guidance, financial planning, and more
  • Monthly teambuilding events
  • B&A Annual Wellness Challenges: #StepWithB&A, #WalkDuringLunchWithB&A, #VolunteeringWithB&A, #ExerciseDuringLunchWithB&A, and more

At B&A, we place significant importance on improving the communities and lives of citizens across the nation through our involvement, technology expertise, and employees. B&A puts an emphasis on charitable efforts in the Northern Virginia area, including Capital Area Food Bank pantry drives, book donations, Hope for Henry Foundation events, and many more. In recognition of all these efforts, B&A has been named a Companies as Responsive Employers (CARE) award recipient by Northern Virginia Family Services and nominated by the Northern Virginia Chamber of Commerce for Outstanding Corporate Citizenship Award.

EEO

B&A provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran in accordance with applicable federal, state and local laws. B&A complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities. This policy covers conduct occurring at B&A's offices, and other workplaces (including client sites) and all other locations where B&A is providing services, and to all work-related activities.

EEO is the Law

B&A participates in e-Verify. We provide the Social Security Administration (SSA) and, if necessary, the Department of Homeland Security (DHS) with information from each new employee's I-9 Form to confirm work authorization.

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Lead Security Engineer in Suitland, MD vacancy
  •  ...Lead Security Engineer At B&A, we foster and embrace a distinct set of values that we live by and instill in all aspects of our organization: dedication, commitment, partnership, trust, and recognition. We have incorporated these values into successful delivery... 
    Suggested
    Full time
    Work at office
    Local area

    Bart and Associates Inc

    Suitland, MD
    2 days ago
  •  ...Lead Security Engineer This position supports Revolutional's federal customer as part of an application transformation and modernization initiative. This program is driving a large-scale transformation of systems into a data-centric, cloud-native ecosystem capable... 
    Suggested
    For contractors

    Harmonia | Revolutional

    Suitland, MD
    4 days ago
  • $135k - $170k

     ...Title: Lead Security Engineer Location: Remote / Hybrid (On site-visits to the DMV location as required by contract) iWorks Corporation, founded in 2005, is a leading provider of information technology and professional services to the federal government. We are... 
    Suggested
    Full time
    Contract work
    Work at office
    Remote work

    Iworks

    Suitland, MD
    8 days ago
  • $15.36k - $23.04k

     ...Lead Security Engineer (AI) – Product Security USA, Durham; USA, Miami; USA, Palo Alto; USA, Washington DC Nu is one of the largest digital financial platforms in the world, with more than 127 million customers across Brazil, Mexico, and Colombia. Guided by our... 
    Suggested
    Work at office
    Work from home
    Relocation package
    Flexible hours

    Nubank

    Washington DC
    4 days ago
  • $140k - $155k

     ...Lead Security Engineer (Active Top Secret Clearance Required) Washington, D.C. Clear Creek Federal is part of the Seneca Nation Group (SNG) portfolio of companies. SNG is Seneca Holdings' federal government contracting business that meets mission-critical needs... 
    Suggested
    Full time
    Contract work
    Flexible hours

    Seneca Holdings LLC

    Washington DC
    2 days ago
  •  ...Lead Security Engineer Job Description Overview CoStar Group is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces. Included in the S&P 500 Index, CoStar Group is on a mission to digitize the world... 
    Full time
    Work at office
    Work from home
    Monday to Thursday

    CoStar Realty Information, Inc.

    Arlington, VA
    4 days ago
  •  ...Lead, Cryptographic Security Engineer Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments... 
    Full time
    Temporary work
    Part time
    Worldwide
    Flexible hours

    Dynamic Yield

    Arlington, VA
    4 days ago
  •  ...Lead Cyber Security Engineer The Lead Cyber Security Engineer role centers on steering network design, system integration, and application development initiatives to align with stringent security protocols and industry standards. This pivotal position requires a deep... 

    Samprasoft

    Washington DC
    9 hours ago
  • Lead Security Engineer Job Description Overview CoStar Group (NASDAQ: CSGP) is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces. Included in the S&P 500 Index and the NASDAQ 100, CoStar Group is on a... 
    Full time
    Work at office
    Work from home
    Monday to Thursday

    CoStar

    Arlington, VA
    9 hours ago
  • Job Overview CoStar Group (NASDAQ: CSGP) is a leading global provider of commercial and residential real‑estate information, analytics...  ...mission to digitize real‑estate by leading incident response, security tooling, and threat hunting. Responsibilities Serve as the incident... 

    CoStar Group, Inc.

    Arlington, VA
    2 days ago
  • iTech AG in Arlington, Virginia, is seeking an Information Security Engineer to support a federal contract. The role involves ensuring security compliance with federal regulations and guidelines, assessing security impacts, and maintaining security documentation. Candidates... 
    Contract work

    iTech AG

    Arlington, VA
    1 day ago
  • A high-tech company is seeking a Lead Security Engineer to oversee cybersecurity operations within the DC area. The ideal candidate will lead efforts to ensure compliance with federal security standards while managing vulnerabilities and incidents. Qualifications include... 
    Work at office

    TekSynap

    Washington DC
    3 days ago
  • $129.3k - $258.7k

     ...Lead AI Cybersecurity Engineer Abbott is a global healthcare leader that helps people live more fully at all stages of life. Our portfolio of life...  ...AI Cybersecurity Engineer will be responsible for the secure use of AI across Abbott, to include: Securing the AI... 
    Work experience placement
    Worldwide

    Abbott

    Washington DC
    2 days ago
  • A leading provider of real estate information is seeking a Lead Security Engineer in Arlington, VA. The ideal candidate will have over 10 years of experience in Information Security and a strong background in incident response and technical assessments. The role requires... 

    CoStar

    Arlington, VA
    9 hours ago
  • $114.08k - $152.11k

     ...by connecting people, data and applications – quickly, securely, and effortlessly. Together, we are building a culture and...  ...and issue posture and assessment reports This Lead Information Security Engineer position operates in a supportive role implementing security... 
    Temporary work
    Worldwide

    Lumen Inc

    Washington DC
    9 hours ago
  • $135k - $216k

     ...Team Lead / Information Systems Security Engineer Peraton is seeking a Team Lead / Information Systems Security Engineer to support our Federal Strategic Cyber programs. Location: National Capital Region (NCR) In this role, you will: Lead, mentor, and supervise... 
    Contract work
    For contractors
    Work at office
    Shift work

    Peraton

    Washington DC
    1 day ago
  • $140k - $231k

     ...Lead Information Security Engineer Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments... 
    Full time
    Part time
    Work experience placement
    Worldwide
    Flexible hours

    MasterCard

    Arlington, VA
    4 days ago
  • The Ed Wallach Search Group is seeking a seasoned Classified Information Security Lead located in Arlington, VA. The role involves managing and safeguarding classified information, ensuring compliance across government-sponsored research programs. Qualified candidates should... 

    The Ed Wallach Search Group

    Arlington, VA
    4 days ago
  • Tyto Athene is seeking a Lead Field Support Engineer in Washington, DC to provide hands-on support for all OIS systems at various remote healthcare locations. Key responsibilities include troubleshooting system errors, installing configurations and updating documentation... 
    Remote work

    Tyto Athene

    Washington DC
    4 days ago
  •  ...Senior Network Security Engineer Suitland, MD Tria Federal delivers digital services and technology solutions that support the health and safety of veterans, service members and civilians. For two decades, federal agencies have relied on Tria companies to advance... 

    Softrams

    Suitland, MD
    4 days ago
  •  ...Cisco Network Security Engineer At CDW, we make it happen, together. Trust, connection, and commitment are at the heart of how we work together to deliver for our customers. It's why we're coworkers, not just employees. Coworkers who genuinely believe in supporting... 
    Contract work
    Local area

    CDW

    Suitland, MD
    4 days ago
  • $94.4k - $198.2k

     ...Job Title: Information Assurance Security Engineer/Information System Security Engineer Level 2 Job Category: Engineering Time Type: Full time Minimum Clearance Required to Start: TS/SCI Employee Type: Regular Percentage of Travel Required: Up to 10%... 
    Full time
    Contract work
    Work experience placement
    Local area
    Flexible hours

    CACI International

    Suitland, MD
    3 days ago
  •  ...Planning and Analysis, Inc. in Washington, D.C. is seeking a Lead Cyber Systems Engineer to guide defense programs through the systems engineering lifecycle. You will ensure program protection and manage security threats while being a technical lead. Required... 

    Systems Planning and Analysis, Inc.

    Washington DC
    2 days ago
  •  ...business development efforts for upcoming opportunities with the U.S. Department of State's Bureau of Diplomatic Security (DS) - Training - Technical Security Engineering. The Advisor will play a critical role in refining our understanding of the client landscape, validating... 
    Contract work
    Work at office

    DEXIS

    Washington DC
    4 days ago
  • $159.3k - $202.4k

     ...Amazon's Threat Hunting team is looking for a Security Engineer, Threat Hunting who is excited by the idea of searching for and uncovering undetected threat activities at petabyte scale. In this role, you will work alongside other Threat Hunting engineers to proactively... 
    Flexible hours
    Shift work

    Amazon

    Arlington, VA
    3 days ago
  • $237.6k - $297k

     ...Security Engineer, Product Security We are seeking a highly technical Security Engineer to join our Product Security team. This role is...  ...quality data and full-stack technologies that power the world's leading models, and help enterprises and governments build, deploy,... 
    Full time

    Scale AI

    Washington DC
    4 days ago
  • $136k - $184k

     ...At Amazon Healthcare Security, we are on a mission to make healthcare secure and easy. We are developing a patient-centric healthcare...  ...personal, transparent, and convenient. We are looking for a Security Engineer to join our team. As a Security Engineer, your... 
    Temporary work
    Internship
    Flexible hours

    Amazon

    Arlington, VA
    4 days ago
  • $178.4k - $226.7k

     ...Corporate Services Security (CPSS) is the Amazon security team aligned with Finance & Global...  ...work, we provide opportunities for our engineers to pursue projects they are passionate about...  ...technical acumen with an ability to lead by influence and communicate clearly. Technically... 
    Internship
    Flexible hours

    Amazon

    Arlington, VA
    3 days ago
  • $159.3k - $202.4k

     ...Description Amazon Healthcare Security's (HealthSec) AI team is hiring a Security Engineer II to secure GenAI applications and enable secure AI adoption across Amazon Health Services (AHS). You will work at the intersection of AI for Security and Security for AI—securing... 
    Flexible hours

    Amazon

    Arlington, VA
    4 days ago
  •  ...he Information Systems Security Engineer (ISSE) is responsible for engineering, implementing, and maintaining security solutions across information systems and networks. This role collaborates closely with system engineers, architects, cybersecurity analysts, developers... 

    Insight Global

    Suitland, MD
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Lead Security Engineer. Be the first to apply!