Lead Security Engineer B&A
Overview
Subject Matter Expert Lead Security Engineer to lead application security across a large-scale cloud-native federal modernization program supporting the U.S. Census Bureau’s Decennial Transformation and Application Modernization effort. Provide technical and management leadership on major security tasks, embedding security into every phase of the System Development Life Cycle using a DevSecOps methodology. Architect and enforce Zero Trust principles, drive Authorization to Operate activities, and direct application security testing, threat modeling, and vulnerability remediation across a System of Systems. Interface with senior Government stakeholders and the Office of Information Security, making decisions that impact overall program implementation.
What You'll Do12
- 1Lead the design and implementation of application security solutions, frameworks, and processes across all phases of the SDLC, in compliance with U.S. Census Bureau and Office of Information Security policies
- 2Implement Zero Trust principles for applications, workloads, and data, aligned with EO 14028, OMB M-22-09, and NIST SP 800-207
- 3Integrate security into DevSecOps CI/CD pipelines, establishing security gates, automated code inspection, and supply-chain controls including Software Bill of Materials generation
- 4Direct Static and Dynamic Application Security Testing, vulnerability assessments, and penetration testing to identify, triage, and remediate security weaknesses
- 5Lead threat modeling exercises to analyze application architecture, identify attack vectors, and document mitigation strategies throughout design, development, testing, and deployment
- 6Support the Authorization to Operate process, including security control assessment, artifact and evidence collection, Privacy Threshold Analysis support, and Plan of Action and Milestones management
- 7Implement security controls in accordance with the NIST Cybersecurity Framework and NIST SP 800-53, and remediate identified vulnerability and compliance findings
- 8Design and implement secure architecture patterns such as secure API design, authentication/authorization, input validation, encryption, secure logging and monitoring, and secure error/session/configuration management
- 9Develop and maintain metrics, dashboards, and reporting to track application security posture, threat trends, and remediation progress over time
- 10Support the development and management of Interagency Security Agreements, security playbooks, and incident response in accordance with current cybersecurity policies
- 11Collaborate with application developers, data engineers, systems engineers, and OIS to identify and mitigate vulnerabilities, and provide expert security consultation to development teams
- 12Assist in FedRAMP certification activities and the assessment/remediation of independent penetration testing results, as applicable
Requirements10
- 1Bachelor’s degree in Information Technology Computer Science Cybersecurity or related field
- 215+ years of relevant IT/cybersecurity experience, providing technical and management leadership on major tasks or technology assignments at SME level
- 3Demonstrated expertise integrating security into a DevSecOps SDLC, including CI/CD security gates and automated security testing
- 4Hands-on experience implementing Zero Trust Architecture and applying NIST SP 800-53 controls and the NIST Cybersecurity Framework
- 5Proven experience leading vulnerability assessments, penetration testing, and threat modeling for enterprise applications
- 6Experience supporting the ATO lifecycle and managing POA&Ms, security artifacts, and evidence collection
- 7Certifications: CISSP CCSP CISM
- 8Required: U.S. Citizenship
- 9Strong analytical problem-solving written and verbal communication skills, including the ability to brief senior Government stakeholders
- 10Security Clearance: Required
Salary Insight
Salary not disclosed in listing
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.
B&A
VerifiedLead Application Developer B&A
Subject Matter Expert leading design and development of modern applications for U.S. Census Bureau's DTAM effort. Provide technical and management leadership while adhering to USCB technical and security requirements and SDLC frameworks.
B&A
VerifiedLead Application Architect, Multi-Cloud & DevSecOps
Lead application architecture for the U.S. Census Bureau's DTAM program, shaping the structure of mission-critical systems. You define the standards and patterns that guide multi-cloud architectures, ensuring interoperability, security, and Zero Trust alignment. You collaborate with engineering and governance teams, providing technical direction on microservices, serverless, and containerization. Your decisions directly impact the program's success, making this a high-visibility role. This position offers the chance to modernize federal systems at scale, working with AWS, Azure, and Google Cloud.
Xpect Solutions
VerifiedInformation Systems Security Officer - Xpect Solutions
Lead compliance and security operations for government information systems. Navigate the full NIST Risk Management Framework and ensure adherence to NIST 800-53 controls and DHS 4300A requirements. Partner with Government Security Assurance Management teams to protect critical systems and maintain compliance posture.

Innova Solutions, Inc
VerifiedLead Application Security Engineer AI
As a Lead Application Security Engineer, you will own the application security strategy for DCMS in-scope applications, defining tier-based control models that scale across the portfolio. You will evaluate existing AppSec control coverage, establish baseline mappings, and drive remediation of critical gaps. Reporting to the security leadership, you will collaborate with engineering teams to embed security into the SDLC, focusing on cloud-native environments and AI applications. This role offers the chance to shape security posture for a major financial client, with a 12+ month contract and hybrid work in Charlotte, NC.
00100 LEIDOS, INC.
VerifiedCyber Infrastructure Support Lead 50-60 chars
Lead a team to enhance enterprise IT reliability performance and security across Windows and Linux platforms. Drive system improvements while maintaining compliance and mentoring staff. This role offers unique opportunities to shape security architecture and lead impactful initiatives.
Texas Based Unique Industry Niche Technology Services-MSP type firm
VerifiedCloud Security Architect DoD Systems
Design and lead secure cloud architectures for government clients. Own Zero Trust designs and drive enterprise cloud transformation. Shape secure solutions in controlled intelligence environments. Lead cross-functional teams to deliver high impact results.