Jobs · Virginia

Senior Security Engineer

ECS · Arlington, VA · 3 days ago
$140k–$180k/yrFull-time

ECS is seeking a Senior Security Engineer to work in our Arlington, VA (hybrid) office. We are looking for a talented Senior Security Engineer who is passionate about building, securing, and improving modern technology environments.

About the role

This is a hands-on engineering role, not a compliance-focused ISSO position. The ideal candidate will be comfortable designing and implementing security controls, writing automation and tooling, troubleshooting complex technical issues, and partnering directly with engineering teams to build secure and resilient systems.

Responsibilities

  • Design, build, implement, and maintain security solutions across cloud, application, infrastructure, and containerized environments.
  • Identify vulnerabilities, attack paths, configuration weaknesses, and security gaps, and develop practical engineering solutions to remediate them.
  • Build and maintain security automation, tooling, scripts, and integrations using languages such as Python, Go, PowerShell, or Bash.
  • Engineer security controls for Linux systems, networks, cloud platforms, containers, Kubernetes, applications, and supporting infrastructure.
  • Develop and improve security monitoring, logging, detection, and response capabilities using system, application, network, and cloud telemetry.
  • Implement security into CI/CD pipelines, infrastructure-as-code workflows, and software development processes.
  • Partner with developers, DevOps engineers, cloud engineers, and system administrators to design solutions that are secure, scalable, maintainable, and operationally effective.
  • Perform hands-on security testing, technical assessments, configuration reviews, and troubleshooting of complex systems and applications.
  • Develop security tooling and integrations using APIs, automation frameworks, and native cloud services.
  • Secure microservices, APIs, containers, and distributed application architectures.
  • Harden operating systems, network services, cloud resources, and application platforms using security engineering best practices.
  • Analyze security data and metrics to identify trends, prioritize risk, and drive improvements to the security posture of the environment.
  • Research emerging threats, vulnerabilities, attack techniques, and security technologies and determine how they apply to the environment.
  • Provide technical leadership and mentorship while remaining actively involved in engineering and implementation work.

Requirements

  • Bachelor’s degree in engineering, computer science, cybersecurity, or another technical discipline, or an associate degree with equivalent years of relevant technical experience.
  • At least 8 years of overall technical experience, including significant hands-on experience in several of the following areas:
    • Security Engineering
    • Unix/Linux Administration and Security
    • Network and Infrastructure Security
    • Cloud Engineering and Cloud Security
    • Application or Software Development
    • Security Automation and Scripting
    • Vulnerability Management and System Hardening
    • Container and Kubernetes Security
    • Security Monitoring, Detection, and Incident Response
  • Strong scripting or development experience in at least one language such as Python, Go, PowerShell, Bash, Perl, or similar.
  • Demonstrated ability to independently troubleshoot complex technical and security problems and implement solutions.
  • Ability to work directly with engineering teams and translate security requirements into practical technical controls.
  • Must successfully complete a stringent Background Investigation and obtain the required Government Security Clearance.

Skills

  • Strong understanding of Git and modern software development workflows.
  • Experience developing security tooling or automation using Python, Golang, C#, Java, C++, or similar programming languages.
  • Strong experience with Bash and/or PowerShell.
  • Deep knowledge of Linux security, operating system internals, and core system services, including DNS, SMTP, Syslog, SSH, firewalls, authentication, and system logging.
  • Strong understanding of TCP/IP networking, firewalls, network segmentation, proxies, load balancers, VPNs, and network security controls.
  • Hands-on experience with AWS, Azure, and/or Google Cloud Platform security.
  • Experience securing containers, Kubernetes, Docker, and microservice architectures.
  • Experience implementing security controls within CI/CD pipelines and DevSecOps environments.
  • Experience with infrastructure-as-code technologies such as Terraform, CloudFormation, or equivalent tools.
  • Experience with vulnerability management, system hardening, security testing, and remediation.
  • Experience with security monitoring and detection technologies such as SIEM, EDR, IDS/IPS, cloud-native security tooling, and centralized logging platforms.
  • Familiarity with identity and access management, secrets management, certificates/PKI, encryption, and key management.
  • Understanding of common application and API vulnerabilities and secure development practices.
  • Experience evaluating and responding to security findings using hands-on technical analysis rather than solely relying on compliance documentation.

Pay

Salary Range: $140,000-$180,000

Similar jobs

Senior Security Engineer

CGIPennsylvania, United States· 2 wk ago
Information Technology$57k–$154k/yrapply on cgi.njoyn.com