Cloud Computing • Identity Management • Information Sharing • Application Development • Cybersecurity
December 28, 2024
🇺🇸 United States – Remote
💵 $110k - $130k / year
⏰ Full Time
🟡 Mid-level
🟠 Senior
👮♂️ Security Engineer
Cloud Computing • Identity Management • Information Sharing • Application Development • Cybersecurity
• Provide application security expertise, continuous integration, software delivery, software quality, and systems documentation support to the agency’s digital assets, including the Bureau’s public-facing web site, consumerfinance.gov, as well as internal software tools; • Work with the Application Development Team to discuss and implement security remediations for agency’s web products; • Work closely with the agency’s Cyber Security and Systems Engineering teams to support compliance, secure baseline development, CVE remediation, and the use of best practices in an AWS FISMA moderate environment; • Provide support to the agency’s Application Development Team in configuring and operating continuous integration and delivery (CI/CD) pipelines, incorporating security into build process using tools such as PrismaCloud, and identifying and resolving issues in the build-deploy-operation lifecycle; • Use and apply the findings of robust application security monitoring tools, including assisting in the securing and maintenance of the agency’s website at consumerfinance.gov and internal software tools; • Assist in building a strong technical foundation in build, release, and production using continuous integration tools such as Jenkins; • Engage with various agency personnel to understand requirements in order to develop better software for the Bureau and identify new ways in which the development team can easily solve issues; • Assist the agency’s Application Development team with security focus through participation in daily standup meetings, monitoring, development, and creating issues in the ticket system • Provide training on a variety of security methodologies, best-practices, and tools along with insight into new technologies and solutions that could help the Application Team and the agency at large; • Assist in the development of Use Cases, Requirements Definition Documents, User and Administration Manuals, Detailed Design Specifications, and Training Manuals and Plans
• U.S. citizenship required • Bachelor’s degree in related field • At least 5 years of demonstrated experience in the following: • Configure, operate, maintain, and monitor various application security tools and services • Experience working with vulnerability scanning tools to identify and resolve security vulnerabilities • Expertise in integrating security testing in automated continuous delivery pipelines (Jenkins/Travis/Ansible) • Experience working with a modern web development stack and toolchain • Experience working with open source and community solutions • Experience in FedRamp IaaS/SaaS • Experience with monitoring software dependencies and automating the creation of an SBOM (software bill of materials) • Collaborate, champion, and mentor software development teams and other stakeholders on secure software development, delivery, and operations
Apply NowDecember 27, 2024
Join phia as an Application Security Engineer, securing federal applications and enhancing cybersecurity posture.
December 26, 2024
Join Bonterra as an Information Security Compliance Analyst, handling risk assessments and compliance reporting for social good technology.
December 26, 2024
Join Hexagon US Federal as a Cloud Security Engineer, managing Azure solutions and deployments. Engage in cutting-edge technologies improving operational decisions.
December 25, 2024
Responsible for analyzing and responding to cyber threats as a SOC Analyst for OSIbeyond. Operate security tools, monitor environments, and perform maintenance activities.
December 25, 2024
CNI seeks a Security Administrator II to manage information security for the Indian Health Services. This remote position requires extensive experience in security management and compliance.