Enter a job title or keyword

Security Engineer

Steampunk


Job Location:

McLean, MD - USA

Yearly Salary: USD 100000 - 155000
Posted: 3 October 2026 (4 hours ago)
Application Deadline: 31 December 2026
Vacancies: 1 Vacancy

Job Summary

Overview

Steampunk is searching for a Security Engineer to support a government customer. This role is a strong fit for hands-on engineers including software developers system administrators and technical subject matter experts who want to apply their technical depth to cybersecurity. Your primary responsibility will be to ensure that the security posture documented in each systems security authorization is implemented and maintained at an acceptable level of risk. Success in this role takes initiative organization a customer-service mindset and the flexibility to adapt in a fast-paced fluid environment. Youll communicate clearly and decisively with all levels of the organization solve practical problems and exercise sound judgment with sensitive and confidential information.

As a Security Engineer youll be the technical expert that development and operations teams rely on to resolve vulnerabilities. Your experience building software or running systems is what makes you effective: youll understand what a finding means in the code or configuration separate real risk from noise and recommend fixes that teams can realistically implement. Rather than performing remediation yourself youll typically guide teams through it tracking issues to closure and keeping systems compliant with federal requirements. If you want to keep coding youll find regular opportunities to do so from building tools that automate compliance work to reviewing code (including AI-generated code) for vulnerabilities and validating fixes. Youll also have access to the latest AI models to speed up development and vulnerability responses.

Contributions
  • Review the security architecture of new systems applications and technologies drawing on your development and infrastructure experience to identify and mitigate potential risks
  • Recommend appropriate mitigation measures and advise on design trade-offs weighing potential impact against cost and benefit
  • Monitor and respond to DHS Information Security Vulnerability Management (ISVM) alerts working with system teams to analyze vulnerabilities and drive them to remediation
  • Proactively monitor and update Plans of Action and Milestones (POA&Ms) working with developers and administrators to resolve weaknesses by their scheduled completion dates
  • Evaluate waivers and risk acceptance memos bringing technical judgment to the management of system risk
  • Monitor the gates in the System Lifecycle Management (SLM) process and brief the customer on outstanding issues and risks before concurrence on system readiness
  • Participate in DevSecOps activities for assigned systems helping teams integrate security into their Agile and DevOps processes
  • Proactively ensure security requirements are included throughout the development lifecycle (Waterfall Agile or DevSecOps)
  • Ensure configuration management (CM) processes are followed so that changes do not introduce new security risks
  • Conduct an annual assessment in accordance with the DHS Information Security Performance Plan
  • Review and update security authorization documents as needed and on the required schedule
  • Perform system self-assessments as part of the customers Ongoing Authorization program
  • Provide audit support for assigned systems (financial OMB Circular A-123 FISMA DHS internal and others) before during and after each audit
  • Maintain knowledge of the hardware and software inventory within authorization boundaries
  • Use DHS-mandated enterprise information assurance (IA) compliance tools
Qualifications
  • Ability to obtain a U.S. government Security Clearance
  • No degree and 9 years of relevant experience; OR
    • Bachelors degree and 5 years of relevant experience; OR
    • Masters degree and 3 year of relevant experience
  • Must hold at least one professional certification relevant to the technical services provided
  • Demonstrated knowledge of security concepts practices and procedures that ensure the secure integration and operation of systems
  • Specialized knowledge and experience evaluating system network or infrastructure security controls against FISMA FIPS and NIST requirements
  • Knowledge and experience with vulnerability scanning execution assessment and analysis
  • Knowledge and experience with application security database security and network security
  • Knowledge and experience using Splunk in an enterprise environment
  • Ability to assess and weigh current and evolving security threats in an operational environment
  • Excellent communication and interpersonal skills including the ability to explain technical risk to both engineers and non-technical stakeholders



Preferred

  • Hands-on background in software development system administration or DevOps engineering
  • An information technology certification related to your subject matter expertise such as a security certification (e.g. CISSP CGRC CSSLP CCSP CompTIA Security or SecurityX) a development certification (e.g. Oracle Certified Professional: Java SE Developer AWS Certified Developer Associate) or a systems or cloud certification (e.g. RHCE CKA AWS Certified Security Specialty)
  • Proven experience as an Information Security Engineer including current experience providing security support to DHS
  • In-depth knowledge of federal cybersecurity regulations and standards
  • Experience with scripting and automation (e.g. Python PowerShell or Bash)
  • Strong understanding of security infrastructure risk management and compliance
  • Proficiency in security tools technologies and best practices
  • Extensive specialized knowledge of cloud engineering or application design and development with experience supporting systems hosted in cloud environments
  • Knowledge and experience with operating systems and network engineering (e.g. LAN and WAN)
  • Experience supporting systems and applications in Agile and DevOps environments
About steampunk

Steampunk relies on several factors to determine salary including but not limited to geographic location contractual requirements education knowledge skills competencies and experience. The projected compensation range for this position is $100000 to $155000. The estimate displayed represents a typical annual salary range for this position. Annual salary is just one aspect of Steampunks total compensation package for employees. Learn more about additional Steampunk benefits here.

Identity Statement

As part of the application process you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.

Steampunk is aChange Agentin the Federal contracting industry bringing new thinking to clients in the Homeland Federal Civilian Health and DoD sectors. Through ourHuman-Centered delivery methodology we are fundamentally changing the expectations our Federal clients have for true shared accountability in solving their toughest mission challenges. If you want to learn more about our story visit.

We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race color religion sex national origin disability status protected veteran status or any other characteristic protected by participates in the E-Verify program.


Required Experience:

IC


About Company

Company Logo

Federal government clients at the center of everything we design, develop, and deliver to drive game-changing mission impacts.

View Profile View Profile